This page contains a sample configuration for a Trust Router connecting to the primary Janet Trust Router, tr.moonshot.ja.net.
To use this configuration, you must make several changes:
- Replace the items in the configuration as appropriate:
your.identity.realm.example.org- Your identity realm, e.g. camford.ac.uk
your.idp.service.realm.example.org- Your IdP host, e.g. moonshot-idp.camford.ac.uk
your.rp-proxy.service.realm.example.org- Your RP proxy host, e.g. moonshot-rp.camford.ac.uk
If you are using a combined IdP and RP proxy service,
your.rp-proxy.service.realm.example.orgwill be the same as
your.idp.service.realm.organd you can delete the unneeded entry.
firstname.lastname@example.org- Your 'username' on the APC, which is stored in the
userelement of the
credentials.xmlfile issued to you by your Trust Router operator.
- In the Moonshot portal, register your Trust Router as a service realm for your organisation, e.g. moonshot-tr.camford.ac.uk
- In the Moonshot portal, change the AAA server name for the IdP realm(s) that connect to your Trust Router to the hostname of your Trust Router, i.e. set the AAA server for
your.identity.realm.example.orgto the host you registered in Step 2.
- Once the changes have been applied, change to the
/etc/trust_router/conf.d/defaultdirectory and run
trustrouteruser. There should be no errors.
For more information about the format of this file, see the Trust Router trusts.cfg format.