Delegate idp v4 auth to CAS

Jehan PROCACCIA jehan.procaccia at tem-tsp.eu
Fri Oct 9 13:49:36 UTC 2020


Hello

regarding the UI , it's not that easy to cutomize the IDP default one to look like our current one in CAS, so I guess we should not try to make them simiar but start a new design that we'll teach our user to trust ...
appart from changing logos and messages in  system/messages/messages.properties (https://wiki.shibboleth.net/confluence/display/IDP4/MessagesTranslation)
is there a documentation regarding login page customization ? 
for example I tried to add that 2nd line (url) 
idp.login.needHelp = Need Help?
idp.login.needHelp.url=https://mywiki.domain.fr/help
that needHelp.url doesn't work . is this the right way to reference a link in the login form ? 

Back to https://wiki.shibboleth.net/confluence/display/IDP4/CasProtocolConfiguration (making shib IDP act as a CAS server) => in that case, does all CAS client apps need to publish metadata and appear as confident relying-parties for the IDP to allow SSO ? the "advantage" of a CAS server was that inside the institution there is no need to share metadatas . 

finaly, I read from :
https://github.com/Unicon/shib-cas-authn3/releases/tag/3.3.0

that idp.authn.flows = Shibcas should change to idp.authn.flows = External , then I suppose that it is IDP v4 compliant if it uses External flow !? 

thanks for your precious help to take the good direction toward IDP v4 .

----- Mail original -----
De: "Cantor, Scott" <cantor.2 at osu.edu>
À: "users" <users at shibboleth.net>
Envoyé: Mardi 6 Octobre 2020 15:29:32
Objet: Re: Delegate idp v4 auth to CAS

On 10/6/20, 9:17 AM, "users on behalf of Jehan PROCACCIA" <users-bounces at shibboleth.net on behalf of jehan.procaccia at tem-tsp.eu> wrote:

>    1) I cannot stop running both, we still have many applications that uses CAS and we've learned our users , for many
> years,  that for security reasons to trust only one URL/login interface (the CAS one). 

If you really think your users notice what the URL is, you would have the first set of users that do I've ever heard of. I know people think they do, but in all the experiments I've seen, that's extremely rare. The UI is entirely up to you obviously, there's no reason the IdP has to look any different.

>    2) Ok I can give it a try, do you confirm this is the correct starting point: 

Yes.

> , that one is for making IDP act as a CAS server right ?

Yes.

>    could this "hack" still work with IDPv4 ?  

That's RemoteUser or RemoteUserInternal. There's nothing new here in V4 except the proxy support.

-- Scott


-- 
For Consortium Member technical support, see https://wiki.shibboleth.net/confluence/x/coFAAg
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net


More information about the users mailing list