CAS Integration Module for Shibboleth IdP

Marvin Addison marvin.addison at gmail.com
Tue Mar 26 13:02:51 EDT 2013


> I know I'm a bit late on this one, but why implement CAS in Shib when
> you can already authenticate Shib against CAS?

I attempted to address that point in my initial post, but I don't mind
saying a few words more. We're quite familiar with Shib-CAS
integration; in fact we wrote the documentation for making CAS the
authentication provider for Shib based on the architecture of the
integration path we use at Virginia Tech:

https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration

There are even better ways to accomplish this now [1], but it amounts
to the same thing in terms of system components: two large, complex
applications with numerous system dependencies. I hope it's self
evident that it would be preferable to consolidate engineering effort
and support resources in a single system that provided the
functionality of both Shib and CAS.

Beyond the potential efficiency gains, it looks like a fun and
challenging project that could be beneficial to us as well as the
larger IDM community. I'm optimistic there's value in the work; even
if the effort is a failure, the value would be evidence that it's
better to run both systems.

M

[1] https://github.com/Unicon/shib-cas-authenticator


More information about the dev mailing list