<html>
  <head>
    <meta content="text/html; charset=windows-1252"
      http-equiv="Content-Type">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    Thank you. I will examine the other side.<br>
    <br>
    Most of our internal CAS clients do not use sessions and (I think)
    rely on the Ticket Granting Ticket (with an expire time of 30
    minutes) to keep issuing new Service Tickets each time they are hit.<br>
    <br>
    I take it this is not normal.<br>
    <br>
    I'm really attempting to upgrade our setup from CAS v3.4.10 + Shib
    v2.2.1 to just Shib 3.2.1.<br>
    <br>
    Thanks again for your help.<br>
    -Brian<br>
    <br>
    All of our existing CAS clients don't use sessions afaik. We're
    currently using <br>
    <br>
    <div class="moz-cite-prefix">On 02/02/2016 12:24 PM, Marvin Addison
      wrote:<br>
    </div>
    <blockquote
cite="mid:CACOs9MSXR7OFkRO63sGkM-GkOPuPauqOoFd+-C9SZgBR249L3g@mail.gmail.com"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=windows-1252">
      <div dir="ltr">
        <div class="gmail_quote">
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF">However, when I go
              back to the same page that I got into, it sends me back to
              authenticate again and I see:<br>
              <br>
              2016-02-02 11:14:44,670 - DEBUG
              [net.shibboleth.idp.cas.flow.impl.ValidateTicket
              Action:92] - Attempting to validate
              ST-1454440484132NQj5toJoKOBk3ZSRFlAd3cQxm<br>
            </div>
          </blockquote>
          <div>... </div>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF"> 2016-02-02
              11:14:44,671 - INFO
              [net.shibboleth.idp.cas.flow.impl.ValidateTicketAction:117]
              - Successfully validated
              ST-1454440484132-NQj5toJoKOBk3ZSRFlAd3cQxm for <a
                moz-do-not-send="true"
                href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi"
                target="_blank"><a class="moz-txt-link-freetext" href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi">https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi</a></a></div>
          </blockquote>
          <div><br>
          </div>
          <div>At this point the CAS protocol work is effectively done
            and a successful service validation response ought to be
            returned to your application that allows you access.</div>
          <div><br>
          </div>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF"> 2016-02-02
              11:14:45,212 - INFO [Shibboleth-Audit.SSO:241] -
20160202T191445Z||3bc14bcbe2cddd2a5d11079ec2cb352c0fd774e2f5e46729bbf03ba0faef7af0|<a
                moz-do-not-send="true"
                href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi"
                target="_blank"><a class="moz-txt-link-freetext" href="https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi">https://ldap-cgi2.dev.sonoma.edu/portal/index.cgi</a></a>|<a
                moz-do-not-send="true"
                href="https://www.apereo.org/cas/protocol/serviceValidate"
                target="_blank"><a class="moz-txt-link-freetext" href="https://www.apereo.org/cas/protocol/serviceValidate">https://www.apereo.org/cas/protocol/serviceValidate</a></a>||||biggsb|||biggsb|ST-1454440484132-NQj5toJoKOBk3ZSRFlAd3cQxm|<br>
            </div>
          </blockquote>
          <div><br>
          </div>
          <div>Further evidence that all is well from the perspective of
            the IdP.</div>
          <div><br>
          </div>
          <blockquote class="gmail_quote" style="margin:0 0 0
            .8ex;border-left:1px #ccc solid;padding-left:1ex">
            <div text="#000000" bgcolor="#FFFFFF"> (BTW, it's a bit
              weird seeing <a moz-do-not-send="true"
                href="https://www.apereo.org/cas/protocol/serviceValidate"
                target="_blank">"https://www.apereo.org/cas/protocol/serviceValidate"</a>
              in the logs since i have no references to it...)<br>
            </div>
          </blockquote>
          <div><br>
          </div>
          <div>That's just a protocol URI. It's not a URL to anything
            anywhere.</div>
          <div><br>
          </div>
          <div>At this point you ought to look more closely at your
            target application's logs. It sounds like it's (a) not
            establishing an application session and (b) may be
            configured for forced authentication (renew=true), which
            would cause you to log in regardless of an existing IdP
            session.</div>
          <div><br>
          </div>
          <div>M</div>
          <div><br>
          </div>
        </div>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="72">-- 

Brian Biggs
Sonoma State University
</pre>
  </body>
</html>