painless-security / trust-router

Moonshot Trust Router
0 stars 0 forks source link

Default AAA server currently ignored #32

Closed jennifer-richards closed 6 years ago

jennifer-richards commented 6 years ago

I believe a change in behavio(u)r was introduced along with the initial implementaiton of the Dynamic Trust Router protocol. In the past, a request for an IdP realm without a configured AAA server would be sent to the configured default AAA server. Currently, this will result in an error being returned.

To fix this, the old behavio(u)r should be restored.

I'm not certain that the new behavio(u)r is described accurately here, need to verify this as well.

Launchpad Details: #LP1643681 Jennifer Richards - 2016-11-21 20:16:57 +0000

jennifer-richards commented 6 years ago

I have just realised that we used to split this out into a separate file called 'peering.cfg'. Given that this functionality existed in v1.0 (as static peering mechanism), yes, leave it in. If the 'default_servers' list does not exist (it's always been optional, yes?) then it just returns an auth error. :-)

Launchpad Details: #LPC Stefan Paetow - 2017-11-24 16:44:24 +0000

jennifer-richards commented 6 years ago

This was fixed by 1127905b70bcb8e1e779e798b76b995789059ff0