Delegate idp v4 auth to CAS
Cantor, Scott
cantor.2 at osu.edu
Tue Oct 6 13:29:32 UTC 2020
On 10/6/20, 9:17 AM, "users on behalf of Jehan PROCACCIA" <users-bounces at shibboleth.net on behalf of jehan.procaccia at tem-tsp.eu> wrote:
> 1) I cannot stop running both, we still have many applications that uses CAS and we've learned our users , for many
> years, that for security reasons to trust only one URL/login interface (the CAS one).
If you really think your users notice what the URL is, you would have the first set of users that do I've ever heard of. I know people think they do, but in all the experiments I've seen, that's extremely rare. The UI is entirely up to you obviously, there's no reason the IdP has to look any different.
> 2) Ok I can give it a try, do you confirm this is the correct starting point:
Yes.
> , that one is for making IDP act as a CAS server right ?
Yes.
> could this "hack" still work with IDPv4 ?
That's RemoteUser or RemoteUserInternal. There's nothing new here in V4 except the proxy support.
-- Scott
More information about the users
mailing list