Really stupid question about IdP v3 CAS support
Karla Borecky
kborecky at smith.edu
Wed Jul 6 13:24:49 EDT 2016
Thank you so much! Yes, I didn't know what to tell them.
They asked for the 'location' of our CAS server, and our email domain
(O_o). Now, if they want email address as their login ID (so to speak), why
would they want the email domain? Unless they want to verify someone's
email exists? Sigh.
We weren't thrilled they chose to go with a service that doesn't support
shib (and assumed we would let them do LDAP). And I don't understand how
such a well-known and long-existing academic service hasn't been configured
to DO saml auth, butl, as the young people say, Whatev-errrr. ;-)
Thanks again to everyone for taking time to write. If anyone is trying to
get shib to work with any of the following, I've managed to do it (by way
of trade):
gartner
banner ssomanager and eis (in cooperation with my colleague on the banner
end)
hiretouch
Best,
Karla B
On Fri, Jul 1, 2016 at 2:38 PM, Walter Forbes Hoehn (wassa) <
wassa at memphis.edu> wrote:
> Depending on what client is being used (and thus what configuration
> options are presented), they will usually either ask for URLs for the login
> and validation endpoints or they will request a base URL (some clients
> refer to this as a “prefix”) from which the two are inferred.
>
> The base URL is: https://$HOST/idp/profile/cas/
>
> Thus, the login URL is: https://$HOST/idp/profile/cas/login
>
> The validation URL varies depending on what style of validation you are
> doing.
>
> -WFH
>
>
> > On Jul 1, 2016, at 1:13 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
> >
> >> Depending on your setup, you will likely need to add an entry to cas-
> >> protocol.xml. If the application doesn’t need any attributes besides the
> >> username, you are done. To send attributes, you’ll also need to edit
> the
> >> standard filter configuration.
> >
> > I think she's asking more about what they will ask from her, and the
> answer is that there is no metadata in CAS and its security model is much
> different. All they will ask is the location of your CAS server. I think
> even the paths/locations of the CAS ticket validation and request endpoints
> are hardwired in the protocol (SAML's are not, we never even considered
> that would fly, shows what making crazy assumptions can buy you).
> >
> > -- Scott
> >
> > --
> > To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
> --
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
--
Karla Borecky
Systems Administrator
ITS
Smith College
Northampton, MA 01063
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20160706/e5344f66/attachment-0001.html>
More information about the users
mailing list