Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

In case Security Server does not support the required TLS version and/or cipher suite(s), the default configuration can be overridden using the file:

/etc/xroad/conf.d/local.ini

All the configuration stored in /etc/xroad/conf.d/local.ini overrides configuration defined in other configuration files. LocalThe local.ini file is not overwritten during version updates so all the changes remain untouched over different X-Road versions. If you want to return to a default value at a later point, just remove the value from local.ini.

Info

"The xroad-proxy" service must be restarted to make the changes effective.

# Ubuntu
service xroad-proxy restart
 
# RHEL
sudo systemctl restart xroad-proxy

For example, when connecting IIS web server to a Security Server, the following changes to Security Server's configuration must be done using local.ini;

/etc/xroad/conf.d/local.ini

...