cas protocol metadata provider confusion

Ray Bon rbon at uvic.ca
Fri Aug 29 19:16:27 UTC 2025


I am setting up shibboleth IdP to support cas services.
When setting up metadata, there is an example MetadataProvider entry that uses a MetadataFilter [0].
With this filter I can not view the metadata with mdquery (though the logs say it is being loaded), nor view [correct] output with aacli, nor log in to the cas service ("Metadata resolution failed..." with "net.shibboleth.shared.resolver.ResolverException: No compatible role resolved").
If I remove this filter everything works as [I] expected.

What is the purpose of the MetadataFilter in this example?
Is there some additional configuration that is required when using the filter [that is not in the docs]?


[0] https://shibboleth.atlassian.net/wiki/spaces/IDP5/pages/3199506569/CASServiceSAMLMetadata#CAS-Metadata-Example


--


Ray Bon
Programmer Analyst
Development Services, University Systems
2507218831 | CLE 019 | rbon at uvic.ca<mailto:rbon at uvic.ca>

I acknowledge and respect the Lək̓ʷəŋən (Songhees and Xʷsepsəm/Esquimalt) Peoples on whose territory the university stands, and the Lək̓ʷəŋən and W̱SÁNEĆ Peoples whose historical relationships with the land continue to this day.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20250829/7c7a8f63/attachment.htm>


More information about the users mailing list