Ex: Re: idpv5 CAS proxy tickets service identifer

Paul B. Henson henson at cpp.edu
Tue Aug 6 01:46:12 UTC 2024


> From: Cantor, Scott <cantor.2 at osu.edu>
> Sent: Saturday, August 3, 2024 12:29 PM
> 
> I don't know what the issue is/was and don't really have time to learn the
> protocol. If someone drafts text that's suitable, I'll add it to the page (though I
> think it may technically be editable anyway).

How about this?

When validating a CAS proxy ticket via the proxyValidate endpoint, idp v4 identified the proxying service in the resultant <cas:proxies> block by its CAS service URL, which did not match the protocol specification requirement of identifying a proxied service by its proxy callback URL. This issue has been fixed in idp v5, which now properly identifies a proxying service by the proxy callback URL rather than the service URL. Any services accepting a CAS proxy ticket and restricting access based on the identity of the proxying service as described by the <cas:proxies> block should evaluate whether any changes need to be made to their configuration prior to production deployment. Please see IDP-2028 for more details.


More information about the users mailing list