mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-10-01 13:54:53 +02:00
* Let users configure the AIA to use with TA certificates. Set 'ta_aia' in the config file. (#409) * Use explicit configuration section for testbed, no longer rely on magic env variables. Note: this will all be revised again if/when the Publication server and TA vs CA code is fully separated in future. Co-authored-by: Ximon Eighteen <3304436+ximon18@users.noreply.github.com>
63 lines
2.2 KiB
Plaintext
63 lines
2.2 KiB
Plaintext
# Example Krill testbed configuration
|
|
#
|
|
# ************************* NOTE: ********************************
|
|
#
|
|
# THIS ONLY MEANT TO BE USED FOR TESTING / TRAINING
|
|
#
|
|
# The testbed setup is very likely to change in future releases!
|
|
# *****************************************************************
|
|
#
|
|
# With the disclaimer out of the way.. you can run Krill in testbed
|
|
# mode. If you do, then it will enable an embedded repository, and
|
|
# setup a trust anchor, and intermediate CA called 'testbed'.
|
|
#
|
|
# Furthermore the UI will expose where users can register their CA
|
|
# as a publisher under the embedded repository, and as a child under
|
|
# the testbed CA - claiming any resources they like to use for test
|
|
# purposes.
|
|
|
|
# To enable the testbed just add the following section to you config,
|
|
# and edit ALL settings - there are no defaults.
|
|
[testbed]
|
|
|
|
# RRDP BASE URI
|
|
#
|
|
# Set the base RRDP uri for the testbed repository server.
|
|
#
|
|
# It is highly recommended to use a proxy in front of Krill.
|
|
#
|
|
# To expose the RRDP files you can actually proxy back to your testbed
|
|
# krill server (https://<yourkrill>/rrdp/), or you can expose the
|
|
# files as they are written to disk ($data_dir/repo/rrdp/)
|
|
#
|
|
# Set the following value to *your* public proxy hostname and path.
|
|
rrdp_base_uri = "https://testbed.example.com/rrdp/"
|
|
|
|
# RSYNC BASE URI
|
|
#
|
|
# Set the base rsync URI (jail) for the testbed repository server.
|
|
#
|
|
# Make sure that you have an rsyncd running and a module which is
|
|
# configured to expose the rsync repository files. By default these
|
|
# files would be saved to: $data/repo/rsync/current/
|
|
rsync_jail = "rsync://testbed.example.com/repo/"
|
|
|
|
# TA AIA
|
|
#
|
|
# Set the rsync location for your testbed trust anchor certificate.
|
|
#
|
|
# You need to configure an rsync server to expose another module for the
|
|
# TA certificate. Don't use the module for the repository as its
|
|
# content will be overwritten.
|
|
#
|
|
# Manually retrieve the TA certificate from krill and copy it
|
|
# over - it won't change again. You can get it at:
|
|
# https://<yourkrill>/ta/ta.cer
|
|
ta_aia = "rsync://testbed.example.com/ta/ta.cer"
|
|
|
|
# TA URI
|
|
#
|
|
# Like above, make the TA certificate available over HTTPS and
|
|
# specify the url here so that it may be included in the TAL.
|
|
ta_uri = "https://testbed.example.com/ta/ta.cer"
|