Understanding shib-cas-authenticator

Cantor, Scott cantor.2 at osu.edu
Wed Oct 23 17:35:32 EDT 2013


On 10/23/13, 5:09 PM, "Baci" <cbacigal at css.edu> wrote:

>I've been looking to integrate my CAS (3.5.2) and Shibboleth. Unicon's
>shib-cas-authenticator <https://github.com/Unicon/shib-cas-authenticator>
>looks
> pretty cool but as I'm reading the documentation in the software
>requirements section, I'm confused. If I have many services managed by
>CAS, I'd need to deploy Shibb IDP in the servlet container of each server?

No. Services using CAS don¹t involve Shibboleth at all, and an IdP doesn¹t
run with services, it¹s the same as your CAS login server, it¹s a web
authentication/SSO service.

> Is the "web resource protected by CAS (casauth)"
> any "casified" application?

It¹s probably referring to the IdP itself. If you don¹t want the IdP to
handle authentication and want CAS to, then you protect the IdP with CAS.
Same as any use of a separate SSO system to handle authentication for the
IdP.

-‹ Scott




More information about the users mailing list