Important: Please assure that you have set a new password for your WLAN/VPN account in your selfservice tool, after February, 1st 2008. If you didn´t set a new password or if your are not sure, please set a new password!
Please install at least the Telekom Toplevel Certificate on your mobile device. (Example: On Nokia mobile phones, use the Nokia Suite and transfer the file rootcert.cer to the device. Then execute this file on the device.)
Choose "System->Settings" at the menu.
Now choose "Connection" -> "Accesspoints"
There you have to choose "Options->New Accespoint->Default settings"
Then you have to choose an name for the connection, do not confound it with the SSID. Example "Eduroam". Choose "Wireless LAN" as data carrier and then use the name search if your are in the range of eduroam or enter "eduroam" manually. The network status should be "public" and the WLAN network mode should be "Infrastructure". Choose WPA/WPA2 as security mode.
In the wireless LAN security settings, set the WPA mode to "EAP" and the TKIP encryption to "Allow". Now change the EAP plug-in settings and deactivate all services except EAP-TTLS.
Now you have to configure EAP-TTLS as followed: Set "User certificate" to "Not defined". In the menu item "CA certificate" choose the certificate of the Deutsche Telekom installed in step 0. Set "Used user name" to "Benutzerkonfiguriert". As user name enter your user ID. Set "used realm" to "Benutzerkonfiguriert" and enter "rwth-aachen.de" as realm/area.
Now you have to switch to the menu sub item EAP and deactivate all services except "MsChapV2". Then you have to configure the MsChapV2 service. As user name enter your user ID followed by "@rwth-aachen.de", set the password request to "No" and then enter your WLAN/VPN password (changeable via selfservice tool)