The eduroam service has been operated by REANNZ for over a decade and the associated services were built up over time. REANNZ had been an early adopter of DjNRO, the software that runs the eduroam member portal to gather location data and publish a location map, and has become a significant contributor to the project.
Seeing the value of correctly configuring eduroam on end-user devices, both in terms of user experience and security, we had been actively championing CAT within our membership
We also saw the need to demonstrate to members the value eduroam brings to them (as well as to the whole community), so we started collecting usage data early on and share monthly reports with our members.
To make it easier to extend eduroam to smaller organisations and beyond campus, we had to reconsider how eduroam is operated by participating organisations. While eduroam was traditionally deployed with institutions being responsible for deploying and operating their own RADIUS servers, this creates a barrier to entry for smaller organisations, as these may not have the skills required. To address this, REANNZ has started offering eduroam as a service, consisting of three components: eduroam Managed SP, eduroam Managed IdP, and eduroam Visitor Access (eVA).
The eduroam Managed SP service makes it easier for small deployments to avoid running a RADIUS server and point their APs directly at the service operated by REANNZ.
The eduroam Managed IdP service addresses the issue that, with the move to cloud-based identity, for many organisations it is no longer feasible to operate an on-premises RADIUS IdP server, as there is no on-premises Identity Management System to use as authentication backend. The service (based on LetsWifi software) instead authenticates users as part of onboarding and issues eduroam configuration profiles with embedded X509 certificates. Part of the service is a RADIUS IdP server that authenticates users by validating the profiles / the X509 certificates. This allows organisations joining eduroam to avoid having to run a RADIUS server and is compatible with modern identity solutions.
The third component of the eduroam as a service portfolio is eduroam Visitor Access (eVA). While eduroam Managed IdP and Hosted SP simplify participation for member organisations, eVA addresses users who do not already have an eduroam identity through a home institution. Developed and maintained by SURF, eVA provides a secure and federated way to manage guest access for campus visitors, conference attendees and other temporary users. The service is a key building block for institutions looking to deliver a unified, eduroam-only wireless experience without maintaining separate guest access solutions.