<div dir="ltr"><div class="gmail_quote"><div dir="ltr">On Mon, Mar 12, 2018 at 4:51 PM Andrew Morgan <<a href="mailto:morgan@orst.edu">morgan@orst.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">It appears that Shibboleth v3.3.1 does not generate Service Tickets that<br>
are compliant with the CAS Protocol specification....<br><a href="https://apereo.github.io/cas/development/protocol/CAS-Protocol-Specification.html#37-ticket-and-ticket-granting-cookie-character-set" rel="noreferrer" target="_blank">https://apereo.github.io/cas/development/protocol/CAS-Protocol-Specification.html#37-ticket-and-ticket-granting-cookie-character-set</a></blockquote><div><br></div><div>The IdP CAS protocol support targets the v2 specification [1] that puts no restrictions on ticket entity character sets.</div><div><br></div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">This issue was also identified in<br>
<a href="https://github.com/apereo/mod_auth_cas/issues/134" rel="noreferrer" target="_blank">https://github.com/apereo/mod_auth_cas/issues/134</a></blockquote><div><br></div><div>Did you try Dave's patch? I'm pretty sure the issue is "fixed" but we're waiting for some positive feedback before merging his patch. Your feedback would be helpful to moving it along.</div><div><br></div><div>Personally, I'm not too keen on trying to make the EncodingTicketService compatible with such a restrictive character set as defined in the v3 protocol spec. I suppose we don't _have_ to use a baseN encoding scheme, but it's a justifiable choice that is non-compliant due to the '=' padding character.</div><div><br></div><div>M</div><div><br></div><div>[1] <a href="https://apereo.github.io/cas/5.2.x/protocol/CAS-Protocol-V2-Specification.html">https://apereo.github.io/cas/5.2.x/protocol/CAS-Protocol-V2-Specification.html</a><a href="mailto:users-unsubscribe@shibboleth.net" target="_blank"></a><br>
</div><div><br></div></div></div>