CAS/shib integration
Michael A Grady
mgrady at unicon.net
Thu Jan 23 21:26:08 EST 2014
FYI - Unicon has done some work towards an update, a version 2, of the shib-cas-authenticator that will add richer communication between the IdP and the CAS Server. Such as indicating the entityID of the service for which the IdP is handling an authn request, so that the CAS Server could potentially uses sources of information like InCommon metadata to enhance what's shown on the Login page etc. (There are folks who use information stored in the CAS Service registry to do that for CAS-handled services today.) And, hopefully, vice-versa, so that information about how the authentication happened (such as MFA etc.) could get communicated back. (And remove the need for a shared context within Tomcat.) I'm trying to pin down an estimate on when that will be available, and when I do, I'll send that along to you.
On Jan 23, 2014, at 7:28 PM, Paul B. Henson wrote:
>> From: Joel Goguen
>> Sent: Thursday, January 23, 2014 3:47 AM
>>
>> We followed the directions at
>> https://wiki.jasig.org/display/CASUM/Shibboleth-
>> CAS+Integration#Shibboleth-CASIntegration-
>> DesignateCAStheAuthenticationProviderforShibIDP to use CAS as our
>> authenticator. Overall, we found it was faster and easier to set up.
>
> Yes, that's the simpler remote user authentication method. shib-cas-authenticator seems a bit more future proof though, and maintains functionality such as forced authentication you would otherwise lose, which at this point tentatively seems worth the additional complexity of the implementation.
> --
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
Michael A. Grady
Senior IAM Consultant, Unicon, Inc.
More information about the users
mailing list