* T-Mobile delivers 802.1x; iPass to follow
endif; ?>T-Mobile – the carrier of Starbucks hot spot fame – recently said it has completed its rollout of 802.1x support in its 4,700 U.S. public Wi-Fi service locations.
What exactly does this mean?
For now, T-Mobile seems to be the first U.S. wireless ISP to authenticate user credentials before granting access to its public wireless LANs. Even more importantly to security-conscious users and their IT departments, the 802.1x support in the T-Mobile infrastructure encrypts over-the-air sessions between the user’s client device and the wireless access point with which it associates.
This prevents those sessions from being sniffed by others who might, for example, see what Internet sites users are browsing and draw conclusions. This could happen either in cases where no VPN is used or where VPN split tunneling is in operation. Split tunneling is when a Layer 3 encrypted tunnel is required for corporate network access but not required for direct access to the public Internet.
T-Mobile authenticates user credentials against its own infrastructure to a service set identifier (SSID) set up for 802.1x connections; verifying that a user is, indeed, a subscriber to the T-Mobile hot spot service. For traveling business users, VPN authentication against a corporate database would require a separate log on.
Users must be outfitted with a client that supports Wi-Fi Protected Access (WPA), as well as T-Mobile’s Connection Manager 1.5 software. Users without the requisite technology for 802.1x authentication will associate to a different SSID, just as they would have otherwise, for “open” authentication.
During the second half of next year, iPass, which aggregates network services from partners such as T-Mobile, plans to also offer 802.1x-based WLAN access via the T-Mobile network. In the case of iPass, which has long been in the business of offering remote access services to enterprise users, 802.1x authentication would take place against the corporate RADIUS server, not the T-Mobile or iPass network.
For that to happen, T-Mobile must build a RADIUS proxy that tunnels user authentication information to the iPass network, and “the company is working with us actively on that,” iPass CTO Roy Albert says.
Currently, iPass uses an HTTPS-based protocol in its client software to communicate authentication credentials to the iPass partner carrier’s RADIUS infrastructure, which proxies the information to the iPASS infrastructure. From there, SSL tunnels carry the credentials across the Internet to the enterprise’s AAA (authentication, authorization and accounting) infrastructure, Albert explains.




