<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
<style type="text/css" style="display:none;"><!-- P {margin-top:0;margin-bottom:0;} --></style>
</head>
<body dir="ltr">
<div id="divtagdefaultwrapper" style="font-size:12pt;color:#000000;background-color:#FFFFFF;font-family:Calibri,Arial,Helvetica,sans-serif;">
<p>Jessica,</p>
<p><br>
</p>
<p>I recently setup CAS and Shibboleth together. I used <a href="https://github.com/Unicon/shib-cas-authn3" id="LPlnk549950" title="https://github.com/Unicon/shib-cas-authn3
Cmd+Click or tap to follow the link">https://github.com/Unicon/shib-cas-authn3</a> as
the remote user authentication gateway between CAS and Shibboleth. Unfortunately as Unicon pointed out to me, there is no way to exchange data between CAS and Shibboleth besides PrincipalName. To get the data I needed I query LDAP using the PrincipalName.
Seems counter productive but it works for me.</p>
<div id="LPBorder_GT_14394844311070.47532202675938606" style="margin-top: 20px; margin-bottom: 20px; overflow: auto; width: 100%;">
<table id="LPContainer_14394844311030.5875324860680848" style="border-top-color: rgb(204, 204, 204); border-top-width: 1px; border-top-style: solid; border-bottom-width: 1px; border-bottom-style: solid; border-bottom-color: rgb(204, 204, 204); width: 80%; position: relative; overflow: auto; background-color: rgb(255, 255, 255);">
<tbody>
<tr valign="top">
<td id="ImageCell_14394844311040.21647858945652843" colspan="1" style="width: 140px; position: relative; display: table-cell; padding: 0px;">
<div id="LPImageContainer_14394844311040.23187197069637477" style="margin-top: 12px; height: auto; width: 140px; position: relative; display: table; background-color: rgb(255, 255, 255);">
<a id="LPImageAnchor_14394844311060.4466815406922251" href="https://github.com/Unicon/shib-cas-authn3" target="_blank" style="display: table-cell; text-align: center;"><img aria-label="Preview image with link selected. Double-tap to open the link." width="140" height="140" style="display: inline-block; margin-left: auto; margin-right: auto; max-width: 140px; max-height: 140px; height: 140px; width: 140px; border-width: 0px;" src="https://avatars3.githubusercontent.com/u/835400?v=3&s=400"></a></div>
</td>
<td>
<div id="LPTitle_14394844311060.5334908629301935" style="top: 0px; margin-top: 8px; font-size: 21px; font-family: wf_segoe-ui_semilight, 'Segoe UI Semilight', 'Segoe WP Semilight', 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; color: rgb(51, 51, 51); margin-left: 14px; margin-right: 14px;">
Unicon/shib-cas-authn3 · GitHub</div>
<div id="LPDescription_14394844311060.7273250538855791" style="margin-top: 8px; font-size: 13px; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; color: rgb(102, 102, 102); margin-left: 14px; margin-right: 14px;">
shib-cas-authn3 - Integrates an external CAS Server and Shibboleth IdPv3.</div>
<div id="LPUrlContainer_14394844311070.3749053617939353" style="margin: 8px 14px 10px; height: 18px; text-overflow: ellipsis; overflow: hidden; white-space: nowrap;">
<a id="LPUrlAnchor_14394844311070.5493214468006045" href="https://github.com/Unicon/shib-cas-authn3" target="_blank" style="font-size: 11px; font-family: wf_segoe-ui_normal, 'Segoe UI', 'Segoe WP', Tahoma, Arial, sans-serif; text-decoration: none;">Read more...</a></div>
</td>
</tr>
</tbody>
</table>
</div>
<br>
<p><br>
</p>
<div id="Signature">
<div name="divtagdefaultwrapper" style="font-family:Calibri,Arial,Helvetica,sans-serif; font-size:; margin:0">
<p class="p1"><b><br>
</b></p>
<p class="p1"><b>Brandon Martin</b></p>
<p class="p1">martinb@psd401.net</p>
<p class="p1">Peninsula School District</p>
<p class="p1"><i>Data Integration Analyst</i></p>
<p class="p1"></p>
<p class="p1">Ext: 3712</p>
</div>
</div>
<br>
<br>
<div style="color: rgb(0, 0, 0);">
<hr tabindex="-1" style="display:inline-block; width:98%">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" color="#000000" style="font-size:11pt"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Jessica Coltrin <jcoltrin@pdx.edu><br>
<b>Sent:</b> Thursday, August 13, 2015 9:42 AM<br>
<b>To:</b> users@shibboleth.net<br>
<b>Subject:</b> Setting up IdP3 to release set of attributes only to CAS users</font>
<div> </div>
</div>
<div>
<div>We’re setting up IdP3 and want to release a set of attributes to only users that login via CAS. Has anyone done this? What configuration did you use?</div>
<div><br>
</div>
<div>Thanks,</div>
<div>Jessica</div>
<br>
<div>-- <br>
<b>Jessica Coltrin</b><br>
Manager, Identity and Access Management<br>
Computing Infrastructure Services<br>
Office of Information Technology<br>
Portland State University<br>
503-725-9599<br>
<a href="mailto:jcoltrin@pdx.edu">jcoltrin@pdx.edu</a><br>
<a href="http://www.pdx.edu/oit">www.pdx.edu/oit</a> </div>
<br>
</div>
</div>
</div>
</body>
</html>