CAS service Parameter with shib-cas-authenticator
Michael A Grady
mgrady at unicon.net
Wed Dec 11 11:42:03 EST 2013
> On Dec 11, 2013, at 9:24 AM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>> On 12/11/13, 12:57 AM, "Abba Yadav" <APY at usp.org> wrote:
>>
>> We have an integrated Shibboleth and CAS installation using
>> shib-cas-authenticator. Is it possible to retrieve within CAS the
>> original service URL that is protected by Shibboleth?
>
> No, SAML does not communicate that information by design. What you get is
> an entityID. What you get in CAS is outside of my view, but you will never
> get the URL.
And that entityID for the requesting service is *not* communicated back to CAS today when using the shib-cas-authenticator. Unicon is planning to produce a new version of that within the next few months that "enriches" the communication between the Shibboleth Identity Provider and the CAS Server. So that the CAS Server does know the service (entityID) that sent the user to the Identity Provider, and the requested authentication context, and so that the Identity Provider gets back more info about the authentication that is done by the CAS Server.
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://shibboleth.net/pipermail/users/attachments/20131211/5b0e6b1b/attachment.html
More information about the users
mailing list