releasing/mapping attributes for CAS protocol in idp 3.x

Mathis, Bradley bmathis at pima.edu
Fri Dec 15 17:27:56 EST 2017


I'm working in an idp 3.x test environment.  I'm wanting to test out using
the CAS protocol.  We are experimenting with using idp3 and the CAS
protocol feature in to test out the possibility of eliminating our CAS
server altogether.

It appears I have successfully configured the CAS protocol and I'm
configured to use password authentication.   So I can give the idp a URL
with the /idp/profiles/cas/login?service=https://xxxxxxxxx  and I get the
default login page. I'm able to authenticate against my ldap server and
then sent on to the page I requested.

The part I'm not sure about now is:

How do I map/release attributes for CAS specific services?
Do I modify attribute-resolver.xml and attribute-filter.xml like I would
for an SP?
Do I have to have a metadata file?
or it it done somewhere CAS specific e.g. cas-protocol.xml ?

I have been following the information found here
https://wiki.shibboleth.net/confluence/display/IDP30/CasProtocolConfiguration
and
it has helped me get to where I am now.

Your input is appreciated.  Just need a point in the right direction.

Thanks!




Brad Mathis
Principal Systems Analyst
Pima Community College
IT - Technical Services
520.206.4826
bmathis at pima.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20171215/6f6eaaeb/attachment-0001.html>


More information about the users mailing list