Group administrators:
Trust Router v1.0 now available
As announced at moonshot-community@jiscmail.ac.uk Trust Router 1.0 was officially released (and tagged in the git repository) this week.
The following features have been added since the beta release:
-
The Trust Router checks COI and APC membership for both the rp_realm and target_realm in the received request.
-
The Trust Router checks the gss_name associated with an incoming connection and ensures that the rp_realm for each request on that connection matches an rp_permitted "accept" filter corresponding to that gss_name.
-
The TIDS running beside the IDP AAA Server now checks the gss_name on the incoming connection and will only accept incoming requests from a local Trust Router using the gss_name provided on the TIDS command line.
-
Improved error handling and reporting.
The above changes mean that a complete and consistent set of Trust Router configuration is now needed in order to get the Trust Router to work properly.
Please try out the new release and let us know at moonshot-community@jiscmail.ac.uk if you have any questions.