Shibboleth without Back Channel?

Cantor, Scott cantor.2 at osu.edu
Mon Mar 21 13:33:34 EDT 2016


> There are integrations here that use CAS as a protocol with applications off-
> campus, so my hands are pretty tied here too.

CAS uses port 443 and generally uses commercial TLS (or nothing) as a trust mechanism.

> We had bantered about an idea here that later turned up on the CAS users’
> list again about removing the need for server-side session replication by
> encoding some information in the ticket or through some other mechanism.
> Is that being actively pursued, and if so, where on the general roadmap
> would it sit?

I don't know if it's been filed as a request. Marvin would tell us what is or isn't going to make a release once a timeline is being discussed. If it's not in the issue tracker then it's certainly not being discussed.

-- Scott



More information about the users mailing list