Shibboleth IDP 3 as CAS Server
Walter Forbes Hoehn (wassa)
wassa at memphis.edu
Thu Jun 11 16:35:41 EDT 2015
Ditto what Marvin said below. You are going to have to check the client end. The only additional information I’ll add is that every time I’ve seen this in the past it has been one of two things:
1) The CAS client was rejecting the CAS server SSL certificate
2) The CAS client was very old and was not parsing the SOAP envelope correctly. This was with the CAS client for Java, so it probably doesn’t apply.
Firewall issues probably don’t come into play all that often, because most folks are running CAS back-channel requests on port 443 along with the /login endpoint.
-Walter
> On Jun 11, 2015, at 3:23 PM, Marvin Addison <marvin.addison at gmail.com> wrote:
>
> 140.211.91.96 - - [11/Jun/2015:12:58:30 -0700] "POST /idp/profile/cas/login;jsessionid=85B70E3AD0AEF47512F7D2D787BEBDCC?execution=e1s1 HTTP/1.1" 302 -
>
> The request to /idp/profile/cas/samlValidate to validate the ticket ought to follow shortly after the credential submission above. I think we need to focus on mod_auth_cas debug output in the Apache error log. What does it say?
More information about the users
mailing list