<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=us-ascii">
<style type="text/css" style="display:none;"> P {margin-top:0;margin-bottom:0;} </style>
</head>
<body dir="ltr">
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Mark,</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Is it possible that these tickets are in fact expired?</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Ticket life is short(ish), say 10s (though I am not sure what the default is) [1].</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
<br>
</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
Ray</div>
<div style="font-family: Aptos, Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica, sans-serif; font-size: 12pt; color: rgb(0, 0, 0);" class="elementToProof">
[1] <a href="https://shibboleth.net/api/java-identity-provider/5.1.6/net/shibboleth/idp/cas/config/ValidateConfiguration.html">
https://shibboleth.net/api/java-identity-provider/5.1.6/net/shibboleth/idp/cas/config/ValidateConfiguration.html</a> DEFAULT_TICKET_VALIDITY_PERIOD</div>
<div id="appendonsend"></div>
<hr style="display:inline-block;width:98%" tabindex="-1">
<div id="divRplyFwdMsg" dir="ltr"><font face="Calibri, sans-serif" style="font-size:11pt" color="#000000"><b>From:</b> users <users-bounces@shibboleth.net> on behalf of Mark Y. Goh via users <users@shibboleth.net><br>
<b>Sent:</b> September 18, 2025 13:47<br>
<b>To:</b> users@shibboleth.net <users@shibboleth.net><br>
<b>Cc:</b> Mark Y. Goh <mgoh@cca.edu><br>
<b>Subject:</b> CAS issues with 5.1.6</font>
<div> </div>
</div>
<div>
<div dir="ltr">
<div>Hi -</div>
<div>I ran into a problem with 5.1.6 - where certain CAS tickets are rejected, we have not been able to figure out why some tickets are accepted and some are not. I assume this behavior is related to CVE-2025-41242 [1] as it does not seem to occur with 5.1.4. </div>
<div><br>
</div>
<div>Three of our CAS apps were affected: koha, webcheckout, and homegrown django apps using CAS-NG. </div>
<div><br>
</div>
<div>this is an example of an error i see for a rejected ticket from our an inhouse python app:</div>
<div>2025-09-18T16:53:40.621203635Z||https://<OUR_APP>/login/?next=%2F|ST-<CAS_TICKET>|||||||||||TicketExpired|INVALID_TICKET|||python-requests/2.27.1<br>
<br>
</div>
<div>Has anyone else run into this issue? Is this a problem on the cas sp side?</div>
<div><br>
</div>
<div>mark</div>
<div>[1] <a href="https://shibboleth.net/community/advisories/secadv_20250826.txt" originalsrc="https://shibboleth.net/community/advisories/secadv_20250826.txt">https://shibboleth.net/community/advisories/secadv_20250826.txt</a></div>
<span class="x_gmail_signature_prefix">-- </span><br>
<div dir="ltr" class="x_gmail_signature" data-smartmail="gmail_signature">
<div dir="ltr">
<pre cols="72"><font face="arial, helvetica, sans-serif">Mark Y. Goh (he/him), Site Reliability Engineer, California College of the Arts, <a href="mailto:mgoh@cca.edu" target="_blank">mgoh@cca.edu</a></font><span></span><br></pre>
</div>
</div>
</div>
</div>
</body>
</html>