<html><head></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><br><div><div>On Feb 27, 2013, at 9:42 AM, Joel Goguen wrote:</div><br class="Apple-interchange-newline"><blockquote type="cite">

<meta http-equiv="Content-Type" content="text/html; charset=utf-8">

<div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; color: rgb(0, 0, 0); font-size: 12px; font-family: Helvetica, sans-serif; ">
<div>
<div>
<div>We have CAS for our primary authentication source. Using directions found on the CAS wiki at
<a href="https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration">https://wiki.jasig.org/display/CASUM/Shibboleth-CAS+Integration</a>&nbsp;we configured Shibboleth to delegate authentication to CAS. Works great for the services we interface with that require
 Shibboleth or SAML2, everything in Shibboleth for attribute release is configured exactly as standard Shibboleth documentation dictates but CAS is trusted to handle the authentication.</div></div></div></div></blockquote><div><br></div>There is one key exception to following "standard Shib documentation" recommendations (well, more an exception to the default settings) that it is worth highlighting. And that is giving strong consideration to *not* using the PreviousSession handler in the Shib IdP, so that session management goes back to the CAS Server, and you don't need to log the user out of both the IdP and the CAS server to disable neew SSO sessions being created without a new authentication event.&nbsp;</div><div><br></div><div>One, of course, wants to give careful thought to session management times no matter what, but one complicates the picture a bit more when you have one WebSSO system "underneath" another. Minimizing the use of sessions in the Shib IdP, and leaving that to CAS on the actual "SSO part", can make it easier to understand and manage what is happening vis-a-vis SSO sessions.</div><div><br></div><div apple-content-edited="true"><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-align: -webkit-auto; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px; font-size: medium; "><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space; "><div><br>--<br>Michael A. Grady<br>Senior IAM Consultant, Unicon, Inc.</div></div></span></div></span></span>
</div>
<br></body></html>