IDP 3.3.2 CAS protocol and alternate CAS username difficulty

Cantor, Scott cantor.2 at osu.edu
Fri Apr 13 10:55:29 EDT 2018


> Do you think this is a bug in the implementation or is this local to our setup?

Is it actually a feature to control what's in the SAML NameID in whatever non-SAML thing CAS made up? I think the username customization is for general CAS "proper". Do the docs suggest this is possible?

If the data is passed in the AttributeStatement properly, that may be what its meant to be doing. I say that from a very uninformed look at the code. The non-SAML validation response logic mentions plowing through IdPAttributes and shows it backing off the the principal name in the ticket state, and the SAML case to me seems to just use the ticket state.

-- Scott




More information about the users mailing list