SSO for both CAS and SAML

Peters C.L. C.L.Peters at soton.ac.uk
Wed Mar 8 12:50:07 EST 2017


Ignore that - I've figured out how to do what I want now.

I had missed the shibboleth.authn.Password.SSOBypassFieldName config option in password-authn-config.xml, which was set to it's default of donotcache. Changing that solves the problem.

Clayton
________________________________________
From: users [users-bounces at shibboleth.net] on behalf of Peters C.L. [C.L.Peters at soton.ac.uk]
Sent: 08 March 2017 17:31
To: Shib Users
Subject: RE: SSO for both CAS and SAML

Hi Scott,

To clarify, you're saying that the CAS/SAML implementation won't automatically use a user that's logged in from the other implementation, and that if a user wants to log in to two apps that use the two different protocols, they have to log in twice? Just checking so I can stop chasing something that's not possible.

Clayton
________________________________________
From: users [users-bounces at shibboleth.net] on behalf of Cantor, Scott [cantor.2 at osu.edu]
Sent: 08 March 2017 17:11
To: Shib Users
Subject: Re: SSO for both CAS and SAML

On 3/8/17, 11:17 AM, "users on behalf of Peters C.L." <users-bounces at shibboleth.net on behalf of C.L.Peters at soton.ac.uk> wrote:

> Hmm, I figured that they should use the same session. My idp.properties file is configured such that both
> idp.session.StorageService and idp.cas.StorageService are set to shibboleth.MemcachedStorageService. I can see sessions
> appearing in memcached, so it looks like that's working, but alas still getting prompted.

There's only one session, it just doesn't work the way you're describing.

-- Scott


--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
--
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list