<div dir="ltr"><div>Hello,<br><br>We are running IdP v4.1.6 with shib-cas-authenticator v4.0.0. Most, but not all, Shib services go to CAS and there are numerous services that are CAS-only. Shib controls SSO sessions.<br><br>We use a service (Campus Cloud by Ready Education, makers of CampusGroups) as a portal to access third-party services. These services use either our IdP or straight CAS for SSO. The portal service itself uses Shib with shib-cas.<br><br>The desired behavior is a user having a portal session who accesses one of the services from a tile within the portal shouldn't be prompted to auth again even though their SSO session has expired. Services using straight CAS work as desired. The portal extracts a request token that CAS looks for using custom JAVA code. Even though the Shib / CAS SSO session ends after 3 hours, accessing a CAS-only service doesn't require authing again because of the existence of the token. The portal session only ends if a user clicks 'log out'.<br><br>The one shib-cas service we added (Workforce) doesn't work as desired. Shib, of course, isn't aware of the auth token the portal stashes. So, we're left trying to come up with a solution. It's unclear to me how Shib with shib-cas-authenticator handles sessions, plus there's the dependence on the user having a portal session.</div><div><br>Would a fix work that focuses on the Shib session, such as using idp.session.defaultSPlifetime in the RP, or another method that renews the session? If it's possible to make Shib aware of the portal token by configuring the IdP to receive, store, and pass it back through shib-cas, we're open to doing that.<br><br>I appreciate any guidance.<br><br>              Janemarie<br clear="all"><div><br></div><span class="gmail_signature_prefix">-- </span><br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><b><span style="color:rgb(11,83,148)"><span style="background-color:rgb(255,255,255)"><span style="font-family:monospace"><img src="https://ci3.googleusercontent.com/mail-sig/AIorK4zpRbtQKEfumFa024uUvgVX6y-TmDvn0IU1RsgcUZgQdNxzrpusMRfxo-LMo1knzn-fSC7LFRE"><br></span></span></span></b></div><div><font size="2"><span style="color:rgb(11,83,148)"><b><b><span style="font-size:11.5pt;line-height:105%;font-family:"Arial",sans-serif;color:rgb(0,83,159)">Janemarie Duh</span></b></b></span></font></div><div><font color="#888888"><font size="2"><span style="color:rgb(11,83,148)"><span style="font-size:11.5pt;line-height:105%;font-family:"Arial",sans-serif;color:rgb(0,83,159)"><span style="font-size:10pt;line-height:105%;color:rgb(10,10,10)">UD Information Technologies</span></span></span></font></font></div><div><span style="color:rgb(11,83,148)"><i><span style="color:rgb(0,0,0)">Identity and Access Management Specialist</span></i><b><br></b></span></div><div><span style="color:rgb(11,83,148)"><a href="mailto:duhj@udel.edu" target="_blank"><span style="color:rgb(0,0,0)">duhj@udel.edu</span></a><b><br></b></span></div></div></div></div></div>