Eduroam certificate verification
Background
The eduroam wireless network uses WPA2-Enterprise with Protected Extensible Authentication Protocol (PEAP) for client authentication. PEAP requires a server-side public key certificate to create a secure TLS tunnel between the client and the authentication server. Inside this encrypted tunnel, user credentials are safely exchanged and verified. This process ensures that sensitive login information is protected from eavesdropping.
Client devices must trust the security certificate when prompted. Unlike SSL certificates used on the web, a wireless device will not automatically verify the validity of the certificate presented by the Wi-Fi authentication server. It is possible to preconfigure and install a profile containing the certificate, marking it as trusted, but that is outside the scope of this article.
The authentication server certificate is issued by the University's certificate authority (CA) provider, and must be renewed yearly.
Current certificate
Name | Expiry | Serial Number |
---|---|---|
eduroam.uwaterloo.ca | 15 Mar 2025 12:51:00 EDT | 3C:6B:CF:AD:9B:AE:C2:43:54:45:CC:10 |
Certificate Verification
To manually verify the certificate chain on MacOS or Linux, perform the following:
Save each of the following certificates to your local machine, with the listed names and extensions
eduroam.uwaterloo.ca.pem
-----BEGIN CERTIFICATE----- MIIIDDCCBvSgAwIBAgIMPGvPrZuuwkNURcwQMA0GCSqGSIb3DQEBCwUAMFAxCzAJ BgNVBAYTAkJFMRkwFwYDVQQKExBHbG9iYWxTaWduIG52LXNhMSYwJAYDVQQDEx1H bG9iYWxTaWduIFJTQSBPViBTU0wgQ0EgMjAxODAeFw0yNDAyMTIxNjUxMDFaFw0y NTAzMTUxNjUxMDBaMHIxCzAJBgNVBAYTAkNBMRAwDgYDVQQIEwdPbnRhcmlvMREw DwYDVQQHEwhXYXRlcmxvbzEfMB0GA1UEChMWVW5pdmVyc2l0eSBvZiBXYXRlcmxv bzEdMBsGA1UEAxMUZWR1cm9hbS51d2F0ZXJsb28uY2EwggEiMA0GCSqGSIb3DQEB AQUAA4IBDwAwggEKAoIBAQCorSw6H/scgepXv2b+33T1o6m1Yo2+DSojnJs6w/D7 KqnutMC1rB9MV54J8SO9lwiYJ4O34zd0PEAm/m8KbgQrGSqOIHZ9fFESx32FCU8/ oy1rz+5JxeW7+SNsQrMOO5T+vFykZE9eLq66ELiO+Y9NZ3j3lRa3SHNZvMl2TNOQ GhN1OCHL+OzoMzjUJ3XI88EYlf6++GZ2PsGMPcoDkAdyq0Go0vwNfcUMxK2dsUTa gfRlA7MzYBQO+U12OpbN/Qs6ac8yg0CEpfZWEuRqKxJOHTKJ7Mw3JbqVD1qx2bxl I2LdK4qX7kQO6i7vgkFhg5Es0kX4XIG9N6c6nAz0Rc5TAgMBAAGjggTCMIIEvjAO BgNVHQ8BAf8EBAMCBaAwDAYDVR0TAQH/BAIwADCBjgYIKwYBBQUHAQEEgYEwfzBE BggrBgEFBQcwAoY4aHR0cDovL3NlY3VyZS5nbG9iYWxzaWduLmNvbS9jYWNlcnQv Z3Nyc2FvdnNzbGNhMjAxOC5jcnQwNwYIKwYBBQUHMAGGK2h0dHA6Ly9vY3NwLmds b2JhbHNpZ24uY29tL2dzcnNhb3Zzc2xjYTIwMTgwVgYDVR0gBE8wTTBBBgkrBgEE AaAyARQwNDAyBggrBgEFBQcCARYmaHR0cHM6Ly93d3cuZ2xvYmFsc2lnbi5jb20v cmVwb3NpdG9yeS8wCAYGZ4EMAQICMD8GA1UdHwQ4MDYwNKAyoDCGLmh0dHA6Ly9j cmwuZ2xvYmFsc2lnbi5jb20vZ3Nyc2FvdnNzbGNhMjAxOC5jcmwwggGTBgNVHREE ggGKMIIBhoIUZWR1cm9hbS51d2F0ZXJsb28uY2GCE2NuLWFhYS51d2F0ZXJsb28u Y2GCE25zLWFhYS51d2F0ZXJsb28uY2GCE2F1dGgteC51d2F0ZXJsb28uY2GCF2d1 ZXN0LndpZmkudXdhdGVybG9vLmNhgiFucy1pc2UtcHNuLWEucHJpdmF0ZS51d2F0 ZXJsb28uY2GCIW5zLWlzZS1wc24tYi5wcml2YXRlLnV3YXRlcmxvby5jYYIhbnMt aXNlLXBzbi1jLnByaXZhdGUudXdhdGVybG9vLmNhgiFucy1pc2UtcHNuLWQucHJp dmF0ZS51d2F0ZXJsb28uY2GCIW5zLWlzZS1wc24tZS5wcml2YXRlLnV3YXRlcmxv by5jYYIhbnMtaXNlLXBzbi1mLnByaXZhdGUudXdhdGVybG9vLmNhgiFucy1pc2Ut cHNuLWcucHJpdmF0ZS51d2F0ZXJsb28uY2GCIW5zLWlzZS1wc24taC5wcml2YXRl LnV3YXRlcmxvby5jYTAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYD VR0jBBgwFoAU+O9/8s14Z6jeb48kjYjxhwMCs+swHQYDVR0OBBYEFI4JGOhlw9hb rEq/VgxQPIvd339nMIIBfAYKKwYBBAHWeQIEAgSCAWwEggFoAWYAdQCi4wrkRe+9 rZt+OO1HZ3dT14JbhJTXK14bLMS5UKRH5wAAAY2eOsZ+AAAEAwBGMEQCIC+lSNKs G60lBxNU/qkCnd2/8j0IPNAyyJu1noWWL7JDAiAf9TZqDbojz2m263rtmPHLl/gT