Login jsp idpui for CAS
O'Dowd, Josh
Josh.O'Dowd at mso.umt.edu
Tue Nov 3 11:16:49 EST 2015
> Do you have a test environment where you can configure the standard authn/password flow and repeat your test sequence againt that? If you still see that behavior in a "default" case, then it would be stronger evidence that it's not some custom code causing the problem.
Yes, that is what I intended to do today, as you say, to be sure it isn’t something we have customized. I’ll let you know what I find…
-Josh
From: users [mailto:users-bounces at shibboleth.net] On Behalf Of Marvin Addison
Sent: Tuesday, November 3, 2015 4:59 AM
To: Shib Users <users at shibboleth.net>
Subject: Re: Login jsp idpui for CAS
The following is an excerpt from the idp-process.log in DEBUG, as requested. I restarted our Jetty server, then I did a single SAML2 authentication using our testing SP (WTS-Staging1). I then logged out and browse to our sample CAS protected URL. The login page branding I am presented with is the UIInfo from the WTS-Staging1 SP.
The logs show what I'd expect other than the existence of an RelyingPartyUIContext, which simply doesn't get populated by the CAS protocol flow. While the CAS login flow does set up a SAMLMetadataContext, which is a precondition of SetRPUIInformation, none of the fields are set that are needed to build the RPUICtx in the authn/password flow.
Do you have a test environment where you can configure the standard authn/password flow and repeat your test sequence againt that? If you still see that behavior in a "default" case, then it would be stronger evidence that it's not some custom code causing the problem.
M
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20151103/7f4e8cf8/attachment.html>
More information about the users
mailing list