<html><body>
        <div dir="ltr">
    Just confirming Mike’s prescription: close attention to tomcat rewrite rules* to map existing cas service point urls to the appropriate idp endpoints enabled all of our existing cas-protocol services to rely on the shibboleth idp with zero changes to the cad-based services. * (in combination with DNS change to make cas…. a CNAME for idp…so the shibboleth idp receives requests directed to cas...)</div><div dir="ltr"><br></div><div dir="ltr">David Bantz</div><div dir="ltr">UAlaska IAM<br><br>
    <div class="gmail_quote">
        <div dir="ltr" class="gmail_attr">On 21Jan, 2021 at 09:35:58, Michael Grady <<a href="mailto:mgrady@unicon.net">mgrady@unicon.net</a>> wrote:<br></div>
        <blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><br>Perhaps you had servlet-based rewrite rules in place that allowed you to send to the "classic CAS Server" endpoints, but were then rewritten into the actual Shib IdP CAS endpoints? We've worked with Tomcat's Rewrite Valve/rewrite.config to help folks do that, where for one reason or another they did not want to change all the existing CAS client/app config.<br><br>--<br>Michael A. Grady<br>IAM Architect, Unicon, Inc.<br><br>


        </blockquote>
    </div>
</div>
    
</body></html>