<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=utf-8">
</head>
<body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 12px; font-family: Helvetica, sans-serif; ">
<div>
<div>
<div>We have CAS for our primary authentication source. Using directions found on the CAS wiki at
<a href="https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration">https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration</a> we configured Shibboleth to delegate authentication to CAS. Works great for the services we interface with that require
Shibboleth or SAML2, everything in Shibboleth for attribute release is configured exactly as standard Shibboleth documentation dictates but CAS is trusted to handle the authentication.</div>
<div>
<div><br>
</div>
<div>-- </div>
<div>Joel Goguen</div>
<div>Developer / System Administrator</div>
<div>Enterprise Solutions</div>
<div>Information Technology Services</div>
<div>University of New Brunswick</div>
<div>E-mail: joel.goguen@unb.ca</div>
<div>Phone: (506) 453-4872</div>
<div>Fax: (506) 453-3590</div>
</div>
</div>
</div>
<div><br>
</div>
<span id="OLK_SRC_BODY_SECTION">
<div style="font-family:Calibri; font-size:11pt; text-align:left; color:black; BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: #b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<span style="font-weight:bold">From: </span>Mike Flynn <<a href="mailto:shibbolethlynda@yahoo.com">shibbolethlynda@yahoo.com</a>><br>
<span style="font-weight:bold">Reply-To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Date: </span>Wednesday, 27 February 2013 11:33 AM<br>
<span style="font-weight:bold">To: </span>Shibboleth Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>><br>
<span style="font-weight:bold">Subject: </span>Re: Adding Shibboleth to CAS<br>
</div>
<div><br>
</div>
<blockquote id="MAC_OUTLOOK_ATTRIBUTION_BLOCKQUOTE" style="BORDER-LEFT: #b5c4df 5 solid; PADDING:0 0 0 5; MARGIN:0 0 0 5;">
<div>
<div>
<div style="color:#000; background-color:#fff; font-family:arial, helvetica, sans-serif;font-size:12pt">
<div><span>FWIW, I have an academic IdP that runs CAS and connects to my Shib SP via SAML. Works fine.</span></div>
<div><br>
</div>
<div style="font-family: arial, helvetica, sans-serif; font-size: 12pt;">
<div style="font-family: 'times new roman', 'new york', times, serif; font-size: 12pt;">
<div dir="ltr"><font size="2" face="Arial">
<hr size="1">
<b><span style="font-weight:bold;">From:</span></b> "Cantor, Scott" <<a href="mailto:cantor.2@osu.edu">cantor.2@osu.edu</a>><br>
<b><span style="font-weight: bold;">To:</span></b> Shib Users <<a href="mailto:users@shibboleth.net">users@shibboleth.net</a>>
<br>
<b><span style="font-weight: bold;">Sent:</span></b> Tuesday, February 26, 2013 4:22 PM<br>
<b><span style="font-weight: bold;">Subject:</span></b> Re: Adding Shibboleth to CAS<br>
</font></div>
<br>
On 2/26/13 3:59 PM, "Stein, Eric" <<a ymailto="mailto:steine@locustec.com" href="mailto:steine@locustec.com">steine@locustec.com</a>> wrote:<br>
<br>
>Hi,<br>
> My organization is currently using CAS as our SSO application, based<br>
>off of authentication information in a database. We'd like to support a<br>
>client who has their own SSO solution and wants to connect to our<br>
>CAS-protected applications using SAML 2.0. We are not interested in<br>
>moving away from CAS or our database authentication store.<br>
<br>
Shibboleth is not one product, and it isn't really that clear which part<br>
you're evaluating. At the end of the day, you can bridge the systems in<br>
either direction, with some significant impact on what's involved.<br>
<br>
Shibboleth isn't necessarily the best option for bridging but there are<br>
various options like:<br>
<br>
- protect a CAS login server with a Shibboleth SP, and point your customer<br>
at that SP as the integration point<br>
<br>
- protect the application with a Shibboleth SP, and then protect a<br>
Shibboleth IdP with CAS as Mike described or in other ways<br>
<br>
- possibly look at the new SP feature for plugging in external<br>
authentication so that you can deploy the SP and support CAS at the same<br>
time at the application end<br>
<br>
> Is this<br>
>something that Shibboleth can support? I know there's a plug-in for CAS.<br>
>I just want to make sure we can leverage Shibboleth without making us<br>
>migrate our user/password info from the database to Shibboleth.<br>
<br>
Neither Shibboleth nor CAS store user data inside themselves, that part is<br>
outside both.<br>
<br>
-- Scott<br>
<br>
<br>
--<br>
To unsubscribe from this list send an email to <a ymailto="mailto:users-unsubscribe@shibboleth.net" href="mailto:users-unsubscribe@shibboleth.net">
users-unsubscribe@shibboleth.net</a><br>
<br>
<br>
</div>
</div>
</div>
</div>
</div>
</blockquote>
</span>
</body>
</html>