<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Mon, Mar 14, 2016 at 2:59 PM Joel Levin <<a href="mailto:joel.aaron.levin@gmail.com">joel.aaron.levin@gmail.com</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div><div>Can CAS clients leverage SAML 1.1.with Shibboleth 3.X (if the CAS protocols are not viable for them, and they cannot migrate to SAML2)?<br></div></div></div></blockquote><div><br></div><div>The history of SAML support in CAS clients is quite confusing. It started out as a way to implement attribute release with an eye to full protocol compliance, but little beyond the attribute release got implemented. There's no CAS client that supports SAML signature validation, and I have no idea whether there are additional limitations that would break them.</div><div><br></div><div>The good news is that the CAS protocol support in v3 does support the "CAS-flavored SAML 1.1" support found in many clients. We use that copiously at my home institution.</div><div><br></div><div>M</div><div><br></div></div></div>