CAS authentication issue
Rene Paquin
rpaquin at wlu.ca
Fri Mar 26 20:36:50 UTC 2021
Thank you. Will do that and see how it goes. I hope my hair grows back....
Rene
Get Outlook for Android<https://aka.ms/ghei36>
________________________________
From: users <users-bounces at shibboleth.net> on behalf of Hucker, Taylor <taylor.hucker at tamucc.edu>
Sent: Friday, March 26, 2021 4:23:15 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: CAS authentication issue
Took us a few weeks to rule out CAS then our Banner Admin did this:
• Assumes tomcat is running as user banner
• • sudo to root
• echo -e "banner soft nofile 65536\nbanner hard nofile 65536" > /etc/security/limits.d/99-banner.conf
• exit root and restart banner user processes
Thanks,
Taylor
--------------------------------
Taylor Hucker
Applications System Administrator
Texas A&M University - Corpus Christi
Taylor.Hucker at tamucc.edu<mailto:Taylor.Hucker at tamucc.edu>
From: users <users-bounces at shibboleth.net> on behalf of Rene Paquin <rpaquin at wlu.ca>
Date: Friday, March 26, 2021 at 2:45 PM
To: Shib Users <users at shibboleth.net>
Subject: RE: CAS authentication issue
Hi Taylor,
Thanks for the response. Our issue is with Ellucian Banner. I will look into this. What did you set the file limit to?
Thanks again,
Rene
From: users <users-bounces at shibboleth.net> On Behalf Of Hucker, Taylor
Sent: March 26, 2021 3:35 PM
To: Shib Users <users at shibboleth.net>
Subject: Re: CAS authentication issue
Rene,
We had a similar issue with an Ellucian application.
Which unexplained IdP reboots seemed to clear items up but wasn’t the cause it was just coincidental it worked.
Our issue was an open file limit on our linux application side (Ellucian banner, not IdP).
Thanks,
Taylor
--------------------------------
Taylor Hucker
Applications System Administrator
Texas A&M University - Corpus Christi
Taylor.Hucker at tamucc.edu<mailto:Taylor.Hucker at tamucc.edu>
From: users <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net>> on behalf of Rene Paquin <rpaquin at wlu.ca<mailto:rpaquin at wlu.ca>>
Date: Friday, March 26, 2021 at 1:43 PM
To: Shib Users <users at shibboleth.net<mailto:users at shibboleth.net>>
Subject: CAS authentication issue
Since moving to IDP 4.01 we are having some CAS authentication issues. It seems quite random, maybe 2 -3 times a week and a reboot of one or sometimes both IDP servers resolves the issue until it happens again. Here is what is happening
1. User browser accesses CAS application
2. Browser is redirected to IDP login page
3. User enters credential (browser) authenticated at IDP
4. IDP sent a CAS ticket back to the browser, and redirect the browser back to CAS application
5. Browser presents the CAS ticket number to CAS application
6. CAS application server sends ticket validation request to IDP server
7. IDP validates the ticket, and return to the CAS application server a SOAP wrapped SAML response.
8. User only sees a blank page in the browser
When it’s working, between step 7 and 8, it should be the CAS application servers received SOAP message and continue to display the resources to user in the browser.
Any ideas? This is really puzzling us.
Thanks,
********************************
Rene Paquin - Systems Administrator
Wilfrid Laurier University
Waterloo, Ontario
(519)884-0710 x3795
rpaquin at wlu.ca<mailto:rpaquin at wlu.ca>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20210326/15b3217a/attachment.htm>
More information about the users
mailing list