Shibboleth IdP freezing issue
IAM David Bantz
dabantz at alaska.edu
Mon Oct 26 18:17:25 UTC 2020
FWIW, we recently successfully pointed our CAS-protocol-reliant services
(Banner and closely related services) to our existing Shibboleth IdP (they
had relied on separate CAS servers for what I'll call historical reasons),
enabling us to decommission multiple dedicated CAS servers. Configuration
of CAS-protocol-reliant services is somewhat different than either (Apereo)
CAS or the SAML2-protocol-reliant services in Shibboleth, but the switch is
essentially invisible to users while providing them a more valuable SSO
session. In our case, the actual change-over was merely a DNS change for
the CAS service to point to the Shibboleth IdP and required 0 changes to
CAS-reliant services themselves.
On Mon, Oct 26, 2020 at 8:55 AM Cantor, Scott <cantor.2 at osu.edu> wrote:
> On 10/26/20, 12:32 PM, "users on behalf of Feinstein, Moses" <
> users-bounces at shibboleth.net on behalf of moses.feinstein at touro.edu>
> wrote:
>
> > Would you recommend any alternatives to our current setup (We have
> several clients that integrate directly with the
> > CAS protocol)
>
> I'd recommend using the IdP as a CAS server, or dumping the IdP and using
> CAS as the SAML server, but I have no idea why the CAS extension would
> requires server side storage.
>
> -- Scott
>
>
> --
> For Consortium Member technical support, see
> https://wiki.shibboleth.net/confluence/x/coFAAg
> To unsubscribe from this list send an email to
> users-unsubscribe at shibboleth.net
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20201026/217845ef/attachment.htm>
More information about the users
mailing list