Files
NLnetLabs-krill/defaults/krill-testbed.conf
T
23be0b5ef7 Make testbed fully configurable through config section
* Let users configure the AIA to use with TA certificates. Set 'ta_aia' in the config file. (#409)
* Use explicit configuration section for testbed, no longer rely on magic env variables.

Note: this will all be revised again if/when the Publication server and TA vs CA code is fully separated in future.

Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
2021-03-22 16:53:41 +01:00

63 lines
2.2 KiB
Plaintext

# Example Krill testbed configuration
#
# ************************* NOTE: ********************************
#
# THIS ONLY MEANT TO BE USED FOR TESTING / TRAINING
#
# The testbed setup is very likely to change in future releases!
# *****************************************************************
#
# With the disclaimer out of the way.. you can run Krill in testbed
# mode. If you do, then it will enable an embedded repository, and
# setup a trust anchor, and intermediate CA called 'testbed'.
#
# Furthermore the UI will expose where users can register their CA
# as a publisher under the embedded repository, and as a child under
# the testbed CA - claiming any resources they like to use for test
# purposes.
# To enable the testbed just add the following section to you config,
# and edit ALL settings - there are no defaults.
[testbed]
# RRDP BASE URI
#
# Set the base RRDP uri for the testbed repository server.
#
# It is highly recommended to use a proxy in front of Krill.
#
# To expose the RRDP files you can actually proxy back to your testbed
# krill server (https://<yourkrill>/rrdp/), or you can expose the
# files as they are written to disk ($data_dir/repo/rrdp/)
#
# Set the following value to *your* public proxy hostname and path.
rrdp_base_uri = "https://testbed.example.com/rrdp/"
# RSYNC BASE URI
#
# Set the base rsync URI (jail) for the testbed repository server.
#
# Make sure that you have an rsyncd running and a module which is
# configured to expose the rsync repository files. By default these
# files would be saved to: $data/repo/rsync/current/
rsync_jail = "rsync://testbed.example.com/repo/"
# TA AIA
#
# Set the rsync location for your testbed trust anchor certificate.
#
# You need to configure an rsync server to expose another module for the
# TA certificate. Don't use the module for the repository as its
# content will be overwritten.
#
# Manually retrieve the TA certificate from krill and copy it
# over - it won't change again. You can get it at:
# https://<yourkrill>/ta/ta.cer
ta_aia = "rsync://testbed.example.com/ta/ta.cer"
# TA URI
#
# Like above, make the TA certificate available over HTTPS and
# specify the url here so that it may be included in the TAL.
ta_uri = "https://testbed.example.com/ta/ta.cer"