IDP 2.4 finding session that should not exist
Cantor, Scott
cantor.2 at osu.edu
Tue Feb 28 19:39:33 EST 2017
On 2/28/17, 5:35 PM, "users on behalf of Ted Fisher" <users-bounces at shibboleth.net on behalf of tffishe at bgsu.edu> wrote:
> Thanks for the feedback Scott. Can I ask for some more clarity. Where the IDP normally hits the authentication engine it
> redirects to /idp/Authn/RemoteUser which then redirects to our CAS server since that is how we have it configured.
No, a CAS client would redirect to the login server only when it needs to, just as a Shibboleth SP does. It has its own session.
> In this case it is not redirecting but somehow knows the user even though the session it had was expired.
No, the IdP session expired, that has nothing to do with the CAS client's session.
> When we have it configured to go to CAS for remote_user how is it getting user info without having gone to CAS?
By leveraging the CAS client's session.
-- Scott
More information about the users
mailing list