CAS/shib integration

Joel Goguen joel.goguen at unb.ca
Thu Jan 23 06:47:26 EST 2014


We followed the directions at https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration#Shibboleth-CASIntegration-DesignateCAStheAuthenticationProviderforShibIDP to use CAS as our authenticator. Overall, we found it was faster and easier to set up.

-- 
Joel Goguen
Developer
Enterprise Solutions
Information Technology Services
University of New Brunswick
E-mail: joel.goguen at unb.ca
Phone: (506) 453-4872
Fax: (506) 453-3590

-----Original Message-----
From: users-bounces at shibboleth.net [mailto:users-bounces at shibboleth.net] On Behalf Of Peter Schober
Sent: 2014 January 23 04:47
To: users at shibboleth.net
Subject: Re: CAS/shib integration

* Paul B. Henson <henson at csupomona.edu> [2014-01-22 21:54]:
> I'm tentatively leaning towards implementing Unicon's
> shib-cas-authenticator module, it seems the most technically
> superior choice (modulo the critical security flaw in their initial
> release :) ). Just wondering if anybody looked at that and ended up
> going with the basic remote user method instead, and if so, why?

RemoteUser is quicker and easier to setup (the IDP even defaults to
it, so any setup happens outside Shib). Other than that it's main
drawback seems to be the lack of support for forceAuthn and isPassive
(if those ever become important to your SAML 2.0 SPs).
-peter
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list