Delegate idp v4 auth to CAS

Jehan PROCACCIA jehan.procaccia at tem-tsp.eu
Tue Oct 6 13:17:18 UTC 2020


Hi, 

1) I cannot stop running both, we still have many applications that uses CAS and we've learned our users , for many years,  that for security reasons to trust only one URL/login interface (the CAS one). 
I admit that's the way to go, we'll probably end with a single IDP/SSO (served by shib) , but in the transition I need to keep CAS running and having IDPv4 authenticate users by redirecting them to their only known and confident  login Form that is served by CAS .
2) Ok I can give it a try, do you confirm this is the correct starting point: 
https://wiki.shibboleth.net/confluence/display/IDP4/SAMLAuthnConfiguration
I am confused with https://wiki.shibboleth.net/confluence/display/IDP4/CasProtocolConfiguration, that one is for making IDP act as a CAS server right ? as I want to keep my CAS server login Form, I don't need that ? 
3) back in the days, I used a filter in web.xml , there was a cas client before shib login that filled the RemoteUSer and then the IDP took it as authenticated and proceeded with attribute resolver : 
https://wiki.shibboleth.net/confluence/display/SHIB2/SSO-CAS+Login+Handler
could this "hack" still work with IDPv4 ?  

Thanks .

----- Mail original -----
De: "Cantor, Scott" <cantor.2 at osu.edu>
À: "users" <users at shibboleth.net>
Envoyé: Lundi 5 Octobre 2020 23:43:38
Objet: Re: Delegate idp v4 auth to CAS

On 10/5/20, 12:07 PM, "users on behalf of jehan Procaccia tem-tsp" <users-bounces at shibboleth.net on behalf of jehan.procaccia at tem-tsp.eu> wrote:

>    What is the best practice and associated Doc to delegate idp v4 auth to a CAS server ? 

I don't have anything to say about "best practice", but were I to be asked, as I literally answered last week, my answer would be:

1. Stop running both, pick one, it's long past time.
2. Use the SAML proxy support in V4 to connect to the later CAS releases using SAML.
3. Anything else, about which I have no real comment.

-- Scott


-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list