Erik Kendall at IRON — Idaho Regional Optical Network

I teach CTE cybersecurity and programming at Renaissance High School in the West Ada School District. This summer I worked with IRON, the Idaho Regional Optical Network, on a question that sounds simple until you try to answer it: how do Idaho’s K-12 schools get onto eduroam?

**The Project**

Eduroam is the global roaming Wi-Fi service that lets a student or teacher walk onto any participating campus in the world and connect using their home credentials. Idaho’s universities have it. Our K-12 districts do not. Closing that gap requires an organization willing to serve as the state’s eduroam Support Organization, the entity that registers districts into the national federation and supports them afterward. IRON wants to be that organization, and my job was to find out what that actually takes. The goal was a repeatable model rather than a single deployment.

**What I Accomplished**

I spent the first half of the summer interviewing the people who had already done this in Michigan, Oregon, Utah, Nevada, and Washington, along with Internet2, the national operator every state connects through. The most useful conversations were about what had not worked and what they wished they had decided earlier.

That research became the documents IRON needed in order to move: a nine-stage onboarding process running from first contact through ongoing support, a decision framework laying out twenty-three questions the organization has to answer before onboarding anyone, a district-facing deployment guide, and a draft participation agreement.

The second half was outreach to rural districts across southern Idaho. I built a brief for each one, sent personalized introductions, and then followed up by phone. The calls accomplished far more than the emails did, which turned out to be one of the more practical lessons of the summer.

**What It Changed**

The protocols were not new to me. My Cyber 2 course covers 802.1X and enterprise authentication, and Cyber 3 covers RADIUS, federation, and single sign-on. What was new was everything around them: that a district running Google Workspace gets pushed toward FreeRADIUS by an authentication constraint, and that content filtering gets complicated the moment the device on your network belongs to a visitor from another district. None of that is in a textbook chapter.

The bigger surprise was that not one thing slowing this project down was technical. The blockers were funding, ownership, and a signature.

That has changed what I emphasize. When I teach federated authentication this year, the trust relationship will be the whole lesson rather than a footnote: somebody has to operate the server, somebody has to pay for it, and somebody has to sign an agreement promising to keep doing both. My students can draw the authentication path. Fewer of them can say who owns it on day two hundred, and that is the question that decides whether a system ever gets built.

I am also bringing back the unfinished part. I spent a summer on a project that has not shipped, and that is what real technical work looks like far more often than a completed lab does.

Erik Kendall
Renaissance High School, West Ada School District
CTE Cybersecurity and Programming