CAS And Shibboleth SSO

David C Fuhs dfuhs at csuchico.edu
Tue Aug 1 19:19:04 EDT 2017


Message: 1
Date: Tue, 01 Aug 2017 18:40:24 +0000
From: Marvin Addison <marvin.addison at gmail.com>
To: Shib Users <users at shibboleth.net>
Subject: Re: CAS And Shibboleth SSO
Message-ID:
	<CACOs9MQNHfhLj75RwRBcxKsENw5Xddu9bOR8kQ-xsGJzufU9+A at mail.gmail.com>
Content-Type: text/plain; charset="utf-8"

On Tue, Aug 1, 2017 at 1:58 PM David C Fuhs <dfuhs at csuchico.edu> wrote:

> What am I missing?
>

Nothing comes to mind offhand. As Scott said, both protocols share the same authentication state machinery, so it should be working as you expect. Post some logs and I'll take a look.

Marvin
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170801/ad27e1d8/attachment-0001.html>



See the attachment.  It includes entries from idp-process.log, with idp and opensaml categories set to DEBUG.

What the log entries show:

Successful authN to a CAS-protected application (userlookup), 3:16:45 to 3:17:20.

Second successful authN to another CAS-protected application (captainsquiz), 3:17:55.  IdP V3 recognizes the session, does not display a login form asking for my credentials (the expected behavior).

Login to a Shibboleth-protected application (lynda.com), 3:18:25 to 3:18:55.  IdP V3 does not recognize the session, displays the login form again (unexpected behavior).

Thanks.

David Fuhs
Enterprise Applications
California State University, Chico



-------------- next part --------------
A non-text attachment was scrubbed...
Name: idp.logs.080117
Type: application/octet-stream
Size: 30029 bytes
Desc: idp.logs.080117
URL: <http://shibboleth.net/pipermail/users/attachments/20170801/c9d3073f/attachment-0001.obj>


More information about the users mailing list