CAF – How eduroam uses your domain as a Realm

eduroam uses the ‘@realm.ca’ as the way to route the authentication requests.  This realm is also used as a scope for CAF FIM (Federated Identity Management or Federated Single Sign On) and is the domain for which your institution is trusted to manage.

A participant should have only one domain for their identity set in the eduroam ecosystem.

Cases where an institution is transitioning from one domain to another would have both domains available for a period of time, usually a few weeks to allow the users to be migrated without immediate loss of service.

Usage of domains such as ‘student.domain.ca’, ‘staff.domain.ca’ is possible and will be routed to the designated eduroam server(s) of the institution.