Shibbolizing cas server with IdP 3.0
Walter Forbes Hoehn (wassa)
wassa at memphis.edu
Wed Nov 18 15:32:05 EST 2015
Also, I just noticed that this was posted to shib-dev. I’m not the Sergeant at Arms around these parts, but it seems you’d reach a wider and more appropriate audience on the users list.
-WFH
> On Nov 18, 2015, at 2:29 PM, Walter Forbes Hoehn (wassa) <wassa at memphis.edu> wrote:
>
>
>> On Nov 18, 2015, at 2:02 PM, Nanda Kumar <NKK at FISCHERINTERNATIONAL.COM> wrote:
>>
>> Hi,
>> Went through the docs about setting up storages, configuring relying party for cas login and registration in the service registry but unfortunately couldn’t a complete hold of how
>> the following flows would work. Can you give a high level idea how the following flows (can be configured to) work with IdP 3.0:
>
> Beside the point, perhaps, but I think it is worth noting that 3.0 is a few releases out of date and includes a DOS vulnerability. In 3.0 the CAS functionality was in its infancy and there have been MANY fixes/updates since then.
>
>> · IdP using CAS for authentication
>> · CAS using IdP for authentication
>
> I think you are confusing multiple ideas here. I can’t blame you, because google turns up documents showing several different ways that these two systems have been integrated in the past, some of which are still possible today. The wiki documentation to which I think you are referring (IdP3/CasProtocolConfiguration) shows how you can turn on native CAS protocol support within the IdP. If you go this route, you won’t have to proxy authentication from one system to the other, you simply point your CAS clients at the appropriate endpoints in your IdP.
>
> -WFH
> --
> To unsubscribe from this list send an email to dev-unsubscribe at shibboleth.net
More information about the dev
mailing list