Ted Fisher tffishe at bgsu.edu
Thu Aug 7 16:15:18 EDT 2014


Thanks Ben.  

I ended up getting this corrected by adjusting the Tomcat session timeout for the IDP which was affecting the CAS client in the IDP

Ted F. Fisher
Information Technology Services


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ben Branch
Sent: Thursday, August 07, 2014 3:24 PM
To: Shib Users
Subject: RE: 

Ted,

This should give you a very detailed explanation on the CAS Protocol.  Also, Marvin Addison on the CAS users list (along with a few others) are extremely helpful in explaining the finer details of the CAS protocol.

http://www.jasig.org/cas/protocol

Links to the Mailing lists: http://www.jasig.org/cas/mailing-lists


Ben Branch
UNIX/Linux Administrator
University of Central Oklahoma
ITIL Foundation v3, Network+, RHCSA

100 N. University Drive, Box 122
Edmond, OK 73034
D: 405.974.2649 | M: 405.550.6804 | bbranch at uco.edu | www.uco.edu

"I am wiser than this man, for neither of us appears to know anything great and good; but he fancies he knows something, although he knows nothing; whereas I, as I do not know anything, so I do not fancy I do. In this trifling particular, then, I appear to be wiser than he, because I do not fancy I know what I do not know."  - Socrates


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Ted Fisher
Sent: Thursday, August 07, 2014 11:27 AM
To: Shib Users
Subject: RE:

I had already done that and it did still respond to the auth without redirecting to CAS.  So, I guess the implication is that the CAS client is doing more than I had thought.

Thanks.

Ted F. Fisher
Information Technology Services


-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Cantor, Scott
Sent: Thursday, August 07, 2014 12:08 PM
To: Shib Users
Subject: Re:

On 8/7/14, 11:45 AM, "Ted Fisher" <tffishe at bgsu.edu> wrote:

>The point in terms of the IDP though is that your saying that the IDP 
>is not maintaining a session still.  If I have the PreviousSession 
>handler commented I shouldn't see the IDP attempting to keep any sense 
>of an SSO session.  If that is correct then I just have to figure out 
>who or what is doing so.

If you want to prove it to yourself, remove the IdP's session cookie and leave the JSESSIONID cookie.

-- Scott

--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
**Bronze+Blue=Green** The University of Central Oklahoma is Bronze, Blue, and Green! Please print this e-mail only if absolutely necessary!

**CONFIDENTIALITY** -This e-mail (including any attachments) may contain confidential, proprietary and privileged information. Any unauthorized disclosure or use of this information is prohibited.
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list