eduroam Certificate Change 2027
Summary – What do I need to do?
The certificate used for authentication with eduroam will be changed on 18 January 2027. To ensure that your smartphone, tablet, or laptop can continue to connect securely to eduroam afterwards, your device must have an up-to-date eduroam configuration.
Did you set up eduroam again using geteduroam on or after 3 August 2026?
Then you do not need to take any further action. The profile provided since 3 August 2026 already contains the settings required for the upcoming change.
Did you set up eduroam before 3 August 2026, or are you unsure?
Then we recommend setting up eduroam again with geteduroam before 18 January 2027. This will provide your device with the current configuration and prepare it for the certificate change.
You can update your configuration now. There is no need to wait until January.
Setup instructions are available on our WLAN documentation pages.
Important: If you experience problems connecting to eduroam after 18 January, please do not disable server certificate validation and do not accept any unknown certificates. Instead, install the current eduroam configuration.
Recommendation for users
If you configured eduroam before 3 August 2026 or are unsure whether your configuration is up to date, please set up eduroam again with geteduroam before 18 January 2027.
If you set up eduroam on or after 3 August 2026 using the current geteduroam profile, you do not need to take any further action.
For manually configured devices, the responsible administrators should check whether the new certification authority is already included in the eduroam configuration.
For devices managed by the GITZ, preparations for the change will begin in advance.
Why is this change necessary?
For authentication with eduroam, our RADIUS servers use a server certificate. This certificate allows end devices to verify that they are actually communicating with the intended eduroam infrastructure during authentication.
The server certificate currently in use expires in February 2027.
The certificates used until now are based on Deutsche Telekom's T-TeleSec GlobalRoot Class 2. However, no new server certificates are being issued under this root certification authority. We can therefore no longer replace the current certificate with a new certificate using the same chain of trust.
For this reason, we are migrating our eduroam infrastructure to a new certification authority.
Why does this affect the eduroam configuration on my device?
Server certificate validation plays an important role in eduroam security.
A correctly configured eduroam profile defines which certification authorities may be trusted when establishing a connection. This allows the device to verify that it is actually communicating with a trusted authentication server during login.
Unlike with many websites, it is therefore not always sufficient for a new certification authority to already be included in the operating system's general certificate store. The configuration used for eduroam must also include the corresponding certification authority.
Preparations have been under way since 3 August 2026
To make the transition as smooth as possible, we updated the configuration provided via geteduroam on 3 August 2026.
Since then, the profile has included both the previously used Telekom certificate chain and the new DFN eduroam CA.
This allows devices with the current configuration to trust both the existing and the new server certificate during the transition period.
The change is therefore being carried out in two steps:
-
Since 3 August 2026: Distribution of the updated eduroam configuration containing both the old and the new certification authority.
-
18 January 2027: Planned change of the server certificate on the eduroam infrastructure.
Anyone who has reinstalled their eduroam profile using geteduroam since 3 August 2026 is already prepared for the second step.
What will happen on 18 January 2027?
On 18 January 2027, the server certificate on our eduroam infrastructure is scheduled to be changed.
For devices with the current eduroam configuration, this change should happen without the user noticing. The device already knows both certification authorities and can therefore trust the new server certificate.
Devices with an older configuration, however, may no longer be able to connect to eduroam after the change, or they may display a warning regarding the server certificate.
In this case, certificate validation should not be disabled and an unknown certificate should not simply be accepted. Instead, eduroam should be set up again using the current configuration provided by us.
No comments to display
No comments to display