Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Panel
bgColor#fff
  1. There appears to be a problem with the RP realm that you specified.
  2. Check that:
    1. the value of your RP realm is the same as the one you specified when you applied for credentials at JANET
    2. the value of your RP realm is specified in the second parameter of the TIDC command-line
    3. you have not specified your ID Provider realm by accident, if it differs from your RP realm.

 

Problem

I can't seem to be able to connect my service to the trust router infrastructure. It seems to start but then I get the following error when running the TIDC command:

tidc_open_connection: Opening GSS connection to tr1.moonshot.ja.net:12309.gss_connect: Connecting to host 'tr1.moonshot.ja.net' on port 12309
CTRL-EVENT-EAP-STARTED EAP authentication started
:
:
CTRL-EVENT-EAP-SUCCESS EAP authentication completed successfully
tidc_fwd_request: Sending TID request: {"msg_type": "tid_request", "msg_body": {"rp_realm": "my RP realm", "target_realm": "my IdP realm", "community": "apc.moonshot.ja.net", ...}

tidc_fwd_request: Response Received (198 bytes).
{"msg_type": "tid_response", "msg_body": {"result": "error", "err_msg": "No path to AAA Server(s) for realm", "rp_realm": "my RP realm", "comm": "apc.moonshot.ja.net", "target_realm": "my IdP realm"}}
tr_msg_decode_tidresp(): Error! result = error.
Response received! Realm = apc.moonshot.ja.net, Community = apc.moonshot.ja.net.
tidc_resp_handler: Response is an error.

Solution:

Panel
bgColor#fff
  1. There appears to be a problem with the ID Provider realm that you specified.
  2. Check that:
    1. the value you specified on the command-line matches the ID Provider realm you specified in the portal or asked Adam Bishop to register for you in the portal
    2. the ID Provider server name and IP address you specified in the portal or to Adam Bishop are correct for your IdP server, and that they are accessible from anywhere on ports tcp/2083 and tcp/12309
    3. you have not specified your RP realm by accident, if it differs from your ID Provider realm.

 

More to come...