CAS Encoded Ticket & CAS User

Ryan Rumbaugh rrumbaugh at nebraska.edu
Fri Jan 18 14:27:54 EST 2019


Thanks Marvin.

There is no username information included in the encrypted ticket then?

What is interesting about this I've changed my /etc/hosts file to point to a test IdP so the front-channel is all going to the test server. When I redirect back to the CAS application and it performs /serviceValidate that call would be going to the production IdP which wouldn't have any saved session for me. However, if I use the same canonicalization configuration in the test IdP I'm able to log into the CAS application which baffles my simple mind.

--
Ryan Rumbaugh

On 1/18/19, 1:15 PM, "users on behalf of Marvin Addison" <users-bounces at shibboleth.net on behalf of serac at vt.edu> wrote:

    On Fri, Jan 18, 2019 at 11:35 AM Ryan Rumbaugh <rrumbaugh at nebraska.edu> wrote:
    > <bean parent="CAS.ValidateConfiguration" p:userAttribute="uid" />
    > When making the above change I have verified the <cas:user> is indeed the correct attribute (uid).
    
    That's all that matters in terms of communicating the attribute to use
    as the CAS username in the CAS v2 ticket validation response.
    
    > However, the CAS service I’m testing with displays a message that my ID is not found
    
    Service is an overloaded term, so let me disambiguate. I understand
    service to mean "CAS-enabled application." In that case all that
    matters is what is in the cas:user element of the protocol message
    sent to the application. It sounds as if you have verified the correct
    value in the protocol message, which is all that matters.
    Canonicalization is a distant memory at that point.
    
    M
    -- 
    For Consortium Member technical support, see https://urldefense.proofpoint.com/v2/url?u=https-3A__wiki.shibboleth.net_confluence_x_coFAAg&d=DwIGaQ&c=Cu5g146wZdoqVuKpTNsYHeFX_rg6kWhlkLF8Eft-wwo&r=x_uM7qpgXzh_70B3Dgey5pfdCFAWMhq-IedVFyaAIwg&m=E9zu0R6aYWR4SxX7Gw1pOFiLYK4GHev_ynIsqqlOId8&s=CoVyT8klZ2u-nbx6shIMZ5rxO0AFh7HOmF8x4K9ZEOA&e=
    To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net



More information about the users mailing list