Eduroam
What is Eduroam
EDUROAM (Education Roaming) is an initiative from TERENA which facilitates mobility among european researchers and students by offering wifi connectivity in a series of institutions abroad which have joined the network. In this way, users from Eduroam participating institutions can access the Internet through the wireless networks of all the participating institutions.
The process of a user connecting to the wireless network of the visited institution is similar to connecting to his home wifi network: the username and password used for authentication are the same to his/her home network, the only difference might be the network access method.
The Institut Cartogràfic i Geològic de Catalunya participates in the EDUROAM project offering access to their own users and users coming from other participating institutions, under coordination from CSUC (IT services provider for catalan universities), which constitutes the technical and administrative link between participating institutions in the Eduroam project.
For further information and to know which institutions are associated to Eduroam, visit the following websites:
- Eduroam Spain (https://www.eduroam.es).
- Eduroam (https://www.eduroam.org).
How to connect
To install the EDUROAM network on your operative system, ask for assistance by sending an e-mail to eduroam@icgc.cat.
Connection details:
- ESSID: eduroam.
- Authentication: IEEE 802.1X EAP-PEAP-MSCHAPv2.
- Encryption: WPA2-AES.
Access point locations
All ICGC building has wireless coverage.
Which services are offered through this network
CiscoVPN, DNS, FTP, IMAP, IPSEC, MS-RDP, OPEN-VPN, POP3, PPTP, SMTP, SSL, WEB-BROWSING and SSH.
Support address
The Eduroam support address in the ICGC is eduroam@icgc.cat.
Regulations
General principles
- Collaboration between Eduroam members is based on mutual trust.
- Only users of participating institutions will have access to mobility services via Eduroam.
- Connecting to Eduroam is voluntary for all institutions affiliated with the Scientific Ring.
- Participating institutions may stop offering the service if they consider that it entails a management burden that they cannot assume.
- The smooth operation of the mobility service depends on the rapid and effective resolution of any problems that may arise, thanks to the collaboration and responsible attitude of all participating institutions.
- Participating institutions must define their own mobility regulations and make them public for both their users and visiting users.
Obligations of the ICGC
- The ICGC will publish on its website a list of participating institutions, as well as a link to the website of each one where technical information can be found on the access methods it offers and the connection procedures.
- The ICGC will keep a record of all authentication sessions redirected through the central RADIUS server, and will store it for a minimum period of 6 months so that it is possible to track users for both security and system sizing reasons.
- The ICGC will keep these mobility regulations updated and published, and will inform the participating institutions of any changes made to them.
- The ICGC will provide the institution that requests it with the information it has registered regarding access to a network of its own, in the event of an attempt to abuse the resources or services of the network, in accordance with these regulations, with the institution's use regulations or with the Anella Científica use policy.
- If these regulations or the Anella Científica use policy are not respected, the ICGC may interrupt or modify the service for a specific user or for an entire domain, and will notify the home institution of the affected user or users of the situation.
User obligations
- The user is obliged to respect the regulations of his or her home institution and the institution visited, the mobility regulations and the Anella Científica use policy. In the event that the regulations defined therein may have different interpretations, the most restrictive ones will be applied.
- The user is responsible for preserving his or her access credentials (username and password) and for the acts that he or she may carry out, or any third party who uses his or her credentials.
- The user must immediately inform the network administrators of their home institution if they become aware that there has been illegal access to the network with their credentials or when they suspect that there may be a risk of this happening.
Obligations of the institution when acting as a home institution
- The home institution is responsible for informing and training its users to respect the usage policies of the visited institutions to which they have access.
- The home institution is obliged to provide support to its users, and will inform its users that for any technical questions about the mobility service they should contact the contact provided by the institution itself, ideally a support phone number. Only if the home institution determines that the problem corresponds to the visited institution, will it redirect the question to the contact provided by the visited institution.
- The home institution is responsible for administering and storing the credentials of its users (username and password, certificates, etc.)
- The home institution must have an authentication server that accepts and processes the credentials of its users when they are on the move.
- The originating institution will keep a record of all authentication sessions maintained with the central RADIUS server, and will store it for a minimum period of 6 months so that it is possible to track users for both security and system sizing reasons.
- If these regulations or the Scientific Ring usage policy are not respected, the originating institution may interrupt or modify the service for a specific user.
- The originating institution will inform the ICGC of any security incident or fraudulent activity detected in which the mobility service is involved, in order to solve it together.
Obligations of the institution when acting as a visited institution
- The visited institution will publish on its website technical information about the access methods it offers and the connection procedures, as well as a link to the ICGC website where the service is described.
- The visited institution must cooperate with the visiting user's home institution.
- The visited institution will inform visiting users about the security levels applied in the transmission of their credentials.
- The visited institution must have an authentication server that securely processes and redirects the credentials of visiting users.
- The visited institution will keep a record of all authentication sessions maintained with the central RADIUS server, and will store it for a minimum period of 6 months so that it is possible to track users for both security and system sizing reasons.
- The visited institution will keep a record of network access sessions.
- The visited institution will inform the ICGC about any security incident or fraudulent activity that is detected in which the mobility service is involved, in order to solve it together.
- The visited institution reserves the right, without prior notice, to interrupt or modify the mobility service for a specific user or for an entire domain, in the event that these rules or the Anella Científica use policy are not respected.