<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="serac@vt.edu" id="email_serac@vt.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=serac%40vt.edu" style="color:#326ca6;">Marvin S Addison</a>
edited a comment on <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-643'>IDP-643</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/IDP-643'><strong>Impossible to Configure CAS Proxy Trust</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>First, I'm not using SAML metadata in any way in the CAS protocol. It's simply a poor fit for any of the protocol configuration concerns. I'll try to explain the core characteristics of CAS proxy trust configuration briefly.</p>
<p>The CAS protocol proxy feature works by validating the certificate of a remote peer. The IdP makes a connection to an endpoint URL under the control of the client over HTTPS and examines the presented certificate as an authentication step. Trust is a key consideration of the certificate's validity. There's actually very little guidance in the protocol about how to implement trust; I believe the assumption is that it works like a browser: host name verification and PKIX trust model. That's what I'm trying to provide by using a configuration like the following.</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
<bean class=<span class="code-quote">"org.opensaml.security.x509.impl.PKIXX509CredentialTrustEngine"</span>>
<constructor-arg name=<span class="code-quote">"resolver"</span>>
<bean class=<span class="code-quote">"org.opensaml.security.x509.impl.StaticPKIXValidationInformationResolver"</span> c:names=<span class="code-quote">"#{<span class="code-keyword">null</span>}"</span>>
<constructor-arg name=<span class="code-quote">"info"</span>>
<bean class=<span class="code-quote">"org.opensaml.security.x509.impl.BasicPKIXValidationInformation"</span> c:crls=<span class="code-quote">"#{<span class="code-keyword">null</span>}"</span> c:depth=<span class="code-quote">"5"</span>>
<constructor-arg name=<span class="code-quote">"anchors"</span>>
<list>
<bean class=<span class="code-quote">"net.shibboleth.ext.spring.factory.X509CertificateFactoryBean"</span>
p:resource=<span class="code-quote">"%{idp.home}/credentials/vtgsca.pem"</span> />
<bean class=<span class="code-quote">"net.shibboleth.ext.spring.factory.X509CertificateFactoryBean"</span>
p:resource=<span class="code-quote">"%{idp.home}/credentials/vtgqsca.pem"</span> />
</list>
</constructor-arg>
</bean>
</constructor-arg>
</bean>
</constructor-arg>
</bean>
</pre>
</div></div>
<p>I've found the TrustEngine API fairly daunting and I'm still learning. In particular, the criteria-based trust evaluation seemed mysterious, and I elided that API point in my first attempt. However, in light of this issue I believe that trust criteria are a key consideration. Implementation plan follows.</p>
<p>I intend to extract the hostname from the HTTPS connection and inject it as a custom HostNameCriterion that is understood by a custom HTTPSConnectionInformationResolver component that understands how to pull the hostname from the custom criteria and add it to the set of trusted names passed to BasicX509CredentialNameEvaluator#evaluate(Credential, Set<String>). That would solve the null/empty set error I'm running into now. On the requirement for PKIX trust, HTTPSConnectionInformationResolver would also need to accept trust anchors for the PKIX trust calculation. In terms of configuration, HTTPSConnectionInformationResolver would take the place of StaticPKIXValidationInformationResolver above, and I believe that will provide the functionality I need.</p>
<p>Please let me know if you see any problems in the planned impl.</p></div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->