Controlling the order of lookup for CAS client metadata/registry

Jeff Chapin jeff.chapin at uni.edu
Mon Feb 20 16:56:27 UTC 2023


We have a set of hosts that run Shibboleth, but do so mainly to provide
LDAP lookup and CAS functionality for a subset of our users. These hosts do
*not* do any SAML authentication, only CAS authentication.

Every time a CAS login is performed, we get a message in idp-warn.log
stating (correctly) that "Metadata resolution failed" -- we do not *HAVE*
SAML metadata for these services at this time.

On
https://shibboleth.atlassian.net/wiki/spaces/IDP4/pages/1265631627/CasProtocolConfiguration#Define-Relying-Party-Metadata
it states that this is the default, expected behavior, but the behavior can
be changed so that it looks in the cas registry first (or even better for
us, *only*), but I am unable to figure out *how* this is done.

I naively tried to control this via commenting out parts of our
default-relying party (we had to add beans to enable CAS, so I wondered if
the order matters), but even with all the Shibboleth and SAML beans
commented out, leaving only CAS ones, I was still getting the error.

Can anyone point me in the right direction?

-- 

Jeff Chapin,

Panther eSports Adviser
Systems/Applications Administrator
ITS-IS, University of Northern Iowa
Phone: 319-273-3162 Email: Jeff.Chapin at uni.edu
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20230220/73223593/attachment.htm>


More information about the users mailing list