
for anybody who wants to learn how eduroam works: your university runs an authentication server, that checks your credentials (securely) whenever you log on to eduroam from ANYWHERE. Suppose you’re at NYU for a conference and want to use eduroam. You click eduroam, maybe put in your username and password, and then you’re connected. Under the hood, your login request got intercepted by a RADIUS server that looks at the domain name of your username, and then forwards the request to your school 1/2
the auth server on your school’s network then receives the login/authentication request from the server at NYU along with your encrypted credentials, decrypts and checks your credentials, and then tells the NYU server whether or not you had valid credentials. The really cool part of all of this, is that NYU’s servers never saw your credentials, and yet you’ve successfully connected to the wifi.