CAS authentication issue

Rene Paquin rpaquin at wlu.ca
Fri Mar 26 20:36:50 UTC 2021


Thank you.  Will do that and see how it goes.  I hope my hair grows back....

Rene

Get Outlook for Android<https://aka.ms/ghei36>

________________________________
From: users <users-bounces at shibboleth.net> on behalf of Hucker, Taylor <taylor.hucker at tamucc.edu>
Sent: Friday, March 26, 2021 4:23:15 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: CAS authentication issue


Took us a few weeks to rule out CAS then our Banner Admin did this:



•  Assumes tomcat is running as user banner

•  •  sudo to root

•  echo -e "banner soft nofile 65536\nbanner hard nofile 65536" > /etc/security/limits.d/99-banner.conf

•  exit root and restart banner user processes







Thanks,

Taylor



--------------------------------

Taylor Hucker
Applications System Administrator
Texas A&M University - Corpus Christi
Taylor.Hucker at tamucc.edu<mailto:Taylor.Hucker at tamucc.edu>





From: users <users-bounces at shibboleth.net> on behalf of Rene Paquin <rpaquin at wlu.ca>
Date: Friday, March 26, 2021 at 2:45 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: CAS authentication issue

Hi Taylor,



Thanks for the response.  Our issue is with Ellucian Banner.  I will look into this.  What did you set the file limit to?



Thanks again,



Rene



From: users <users-bounces at shibboleth.net> On Behalf Of Hucker, Taylor
Sent: March 26, 2021 3:35 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: CAS authentication issue



Rene,



We had a similar issue with an Ellucian application.

Which unexplained IdP reboots seemed to clear items up but wasn’t the cause it was just coincidental it worked.



Our issue was an open file limit on our linux application side (Ellucian banner, not IdP).





Thanks,

Taylor



--------------------------------

Taylor Hucker
Applications System Administrator
Texas A&M University - Corpus Christi
Taylor.Hucker at tamucc.edu<mailto:Taylor.Hucker at tamucc.edu>





From: users <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>> on behalf of Rene Paquin <rpaquin at wlu.ca<mailto:rpaquin at wlu.ca>>
Date: Friday, March 26, 2021 at 1:43 PM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: CAS authentication issue

Since moving to IDP 4.01 we are having some CAS authentication issues. It seems quite random, maybe 2 -3 times a week and a reboot of one or sometimes both IDP servers resolves the issue until it happens again. Here is what is happening



  1.  User browser accesses  CAS application
  2.  Browser is redirected to IDP login page
  3.  User enters credential (browser) authenticated at IDP
  4.  IDP sent a CAS ticket back to the browser, and redirect the browser back to  CAS application
  5.  Browser presents the CAS ticket number to  CAS application
  6.  CAS application server sends ticket validation request to IDP server
  7.  IDP validates the ticket, and return to the  CAS application server a SOAP wrapped SAML response.
  8.  User only sees a blank page in the browser



When it’s working, between step 7 and 8, it should be the  CAS application servers received SOAP message and continue to display the resources to user in the browser.



Any ideas?   This is really puzzling us.



Thanks,



********************************
Rene Paquin - Systems Administrator
Wilfrid Laurier University
Waterloo, Ontario
(519)884-0710 x3795
rpaquin at wlu.ca<mailto:rpaquin at wlu.ca>


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210326/15b3217a/attachment.htm>


More information about the users mailing list