SSO-CAS Login Handler error

Baron Fujimoto baron at hawaii.edu
Mon Oct 19 23:16:21 EDT 2015


Though we are in the process of upgrading to IdPv3, we're still currently
using IdP v2.4.4 and using CAS for AuthN with the RemoteUser login
handler.

We now have an SP that would like to use the forceAuthn parameter, and
this isn't supported by the RemoteUser login handler. I did find the
SSO-CAS login handler documented which purports to do what we want.

<https://wiki.shibboleth.net/confluence/display/SHIB2/SSO-CAS+Login+Handler>

However, I seem to have run into the same error that was described here:

<http://shibboleth.1660669.n2.nabble.com/New-contribution-SSO-CAS-Login-Handler-td7581293.html>

Unfortunately, if the cause was ever determined, it doesn't seem to have
been captured on the list. The last response by Scott suggests the problem
is a missing colon somewhere. Is it safe to say that the problem is
confined to handler.xml? The only changes I've made to the that file were
to edit ProfileHandlerGroup , defined the new LoginHandler as , and
commented out the RemoteUser Login handler, all as directed in the wiki.

I'd be happy to update the documentation if an error in it can be
identified.

Alternatively, is there a preferred approach for IdPv2 so support
forceAuthn? SSO-CAS had the benefit of seeming pretty strightforward.

Aloha,
-baron
-- 
Baron Fujimoto <baron at hawaii.edu> :: UH Information Technology Services
minutas cantorum, minutas balorum, minutas carboratum desendus pantorum


More information about the users mailing list