The path is basically to scope the TGC domain to my domain with path set to root. When a user logs in via cas, and is redirected to my app, I can setup a session, using the values of the TGC cookie and on each subsequent request, I can check the value in the current sessions against the TGC cookie value, if they don't match, invalidate the session.
In order to make that work, I need the TGC to be submitted to my application for each request. At the moment my cas server is running on cas.example.com/cas domain, i would like to change the TGC domain to wildcard .example.com with cookie path set to "/" root path. On Thursday, January 14, 2016 at 3:46:36 PM UTC-5, Misagh Moayyed wrote: > > That’s the file. I’d have to know what you changed and why before I can > recommend a path. > > > > *From:* James Naadjie [mailto:[email protected] <javascript:>] > *Sent:* Thursday, January 14, 2016 12:46 PM > *To:* CAS Community <[email protected] <javascript:>> > *Cc:* [email protected] <javascript:> > *Subject:* Re: [cas-user] CAS SLO for Rails and JAVA application > > > > Thanks for the answers and pointing me in the right direction. Follow up > question. > > Would it be possible to change the TGC cookie domain and path? > > I have tried changing the > > ticketGrantingTicketCookieGenerator.xml configuration for the cookie, but > the path doesn't change. > > > > > > On Thursday, January 14, 2016 at 2:17:19 PM UTC-5, Misagh Moayyed wrote: > > Start with this: > > https://jasig.github.io/cas/4.1.x/installation/Logout-Single-Signout.html > > > > Also on the theory/context of SLO: > > https://wiki.shibboleth.net/confluence/display/CONCEPT/SLOIssues > <https://www.google.com/url?q=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FCONCEPT%2FSLOIssues&sa=D&sntz=1&usg=AFQjCNH2KyE6hjQjcqW8mCiVfofWuK9vgA> > > > > 1. SLO is enabled by default in CAS. > > 2. No special config is needed, unless you need it. > > 3. There is no way to get the TGC. > > > > CAS cannot log the user out of all applications magically. It has no > access to those apps. Instead, it sends a special message to those apps > asking them to logout, and this is why your B and C apps don’t log out > because they are either not receiving that request, or not responding to > it. > > > > *From:* [email protected] [mailto:[email protected]] *On Behalf Of *James > Naadjie > *Sent:* Thursday, January 14, 2016 9:36 AM > *To:* CAS Community <[email protected]> > *Subject:* [cas-user] CAS SLO for Rails and JAVA application > > > > I’m not very clear on how Single Log out works with CAS server 4.1 and > hope for a clear and simple explanation to help resolve an issue i’m having > with my client applications. > > Currently SSO works fine with my two applications. > > Users can login to application A,B and C, A and B are Ruby on Rails > applications using ruby-cas client. C is a Java application using acegi > security(Now Spring security) > > When users logout of application A, they are redirected to CAS server > logout view, but are still logged in to application B,C. Same goes for > logging out of B,C. > > > > Is SLO for Cas server 4.1 enabled by default? > > Does SLO require any special configuration to work on CAS server? > > Is there a way to get and store the cas TGT cookie (value of cas cookie)? > > -- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected]. > Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/ > . > > -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
