eduroam

A digital sign reminds students to update their devices by Oct. 13 to maintain eduroam Wi-Fi access near the Digital Union Prototyping Studio in Enarson Classroom Building Oct. 8. Credit: Hana Alghamdi | Lantern Reporter

Students, faculty and staff who’ve connected their phones and other personal devices to Ohio State’s eduroam Wi-Fi network will have to go through several steps to “re-onboard” to the service by Oct. 13, or risk losing access.

The university is making the change as the technology industry moves toward shorter lifespans for digital security certificates, which devices use to verify that a network can be trusted, according to Ryan Holland, senior director of Enterprise Networks and Infrastructure at Ohio State. Eduroam is the university’s secure Wi-Fi network, according to Ohio State’s Office of Technology and Digital Innovation website.

“Ohio State is adopting a new certificate model designed to minimize future disruptions,” Holland said in an email. “Re-onboarding your device will allow it to recognize the new certificate and continue connecting securely with fewer updates going forward.”

Holland said Oct. 13 was selected because it falls immediately before autumn break, when the university expects campus activity and eduroam usage to begin decreasing as students complete exams and leave campus.

The timing also allows the university to spread support needs across the days leading into and during the break, Holland said.

Students can re-onboard their personal devices by visiting Ohio State’s eduroam webpage and selecting the instructional guide that matches their device, according to Technology and Digital Innovation.

Holland said students and employees must complete the process for each personal device they regularly use on eduroam.

Those who do not re-onboard by Oct. 13 can reconnect afterward, but the process will require additional steps and may require assistance from the university’s IT Service Desk, Holland said.

Holland said students who do not re-onboard can use WiFi@OSU or cellular data to access the internet.

Zhiqiang Lin, faculty director of Ohio State’s Institute for Cybersecurity and Digital Trust, said digital certificates use two types of keys to help verify identity.

Lin said the first is a public key, which devices can access to verify digital signatures, and second is a private key, which is kept by the certificate holder and used to create those signatures.?

“It makes your connection more secure, and it is not so easy to crack your traffic,” Lin said.

Tim Callan is the chief compliance officer at Sectigo, a Scottsdale, Arizona-based cybersecurity company specializing in digital certificates.

Callan said shorter certificate lifespans can improve security by reducing the amount of time a certificate could be misused if someone gains unauthorized access to it.

“There is a reason behind these security requirements,” Callan said. “These are in response to legitimate threats that really exist.”

Callan said when a device cannot verify a certificate, refusing the connection is an intentional security measure designed to prevent potentially unsafe connections.

Ashley Krebs, a third-year in strategic communication, said she had concerns about the alternatives available to students who have not re-onboarded.

“There’s a lot of expensive things outside of just tuition,” Krebs said. “So that worries me that some students might not know that they’re using all their cellular data, and if that’s costing them money, is it a part of their plan?”

Koree Alvarez, a third-year in marketing, said the timing of the re-onboarding requirement concerns her because, as a commuter, she spends several hours studying in the library and relies on campus Wi-Fi to access course materials and participate in class.

“I’m completely shocked because this is midterm season,” Alvarez said. “That’s so detrimental for so many students.”