Shibboleth IDP 3 as CAS Server
Jesse Martinich
martinicj at sou.edu
Thu Jun 11 15:36:19 EDT 2015
Thank you. I've had the feeling that I'm missing some pieces. My most
recent config was borrowing from mod_auth_cas examples I found online, in
hopes that I could trigger a meaningful error code.
I took from the CAS protocol configuration documentation (
https://wiki.shibboleth.net/confluence/display/IDP30/CasProtocolConfiguration)
that there were was nothing in the way of relying party config beyond the
defaultRelyingParty bean. It seems that the serviceRegistry takes the place
of metadata configuration for CAS services. I assume there is something
analogous to the attribute-filter for registered CAS services?
As I mentioned in my (long) email, I had "require valid-user" in there as
well, and saw the same symptoms.
Is there somewhere else I could look for documentation?
Jesse
Jesse Martinich | Systems Administrator
Southern Oregon University
martinicj at sou.edu | 541-552-8424
On Jun 11, 2015 12:20 PM, "Cantor, Scott" <cantor.2 at osu.edu> wrote:
>
>
>
>
>
> On 6/11/15, 7:11 PM, "Jesse Martinich" <martinicj at sou.edu> wrote:
> >
> >I would like to release attributes like ePPN, ePPA, first, last, etc and
> >be able to support CAS clients in general.
>
> I don't think that the vanilla config you described would issue
> attributes, and your require rule depends on one, so I would imagine
> that's the problem. I don't know if the docs cover the proto-SAML bits in
> the CAS support, or not, but there's got to be more involved here.
>
> -- Scott
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20150611/34d44211/attachment.html>
More information about the users
mailing list