CAS gateway mode

YF Lai ccyflai at
Mon Jun 13 14:54:00 UTC 2022

So apparently CAS gateway mode cannot work in this kind of authentication flow configuration.


-----Original Message-----
From: users <users-bounces at> On Behalf Of Cantor, Scott via users
Sent: Monday, 13 June 2022 7:59 pm
To: Shib Users <users at>
Cc: Cantor, Scott <cantor.2 at>
Subject: Re: CAS gateway mode

On 6/10/22, 8:35 PM, "users on behalf of YF Lai" <users-bounces at on behalf of ccyflai at> wrote:

>    Thanks.  We used SAML and DuoOIDC in MFA flow.  The 
> passiveAuthenticationSupported flag in DuoOIDC is not enabled by default.  Will try it out.

Because you can't. There's no way to control what happens on their end. You'd be violating the sematics.

-- Scott

For Consortium Member technical support, see
To unsubscribe from this list send an email to users-unsubscribe at

More information about the users mailing list