The path is basically to scope the TGC domain to my domain with path set to 
root. When a user logs in via cas, and is redirected to my app, I can setup 
a session, using the values of the TGC cookie and on each subsequent 
request, I can check the value in the current sessions against the TGC 
cookie value, if they don't match, invalidate the session. 

In order to make that work, I need the TGC to be submitted to my 
application for each request. At the moment my cas server is running on 
cas.example.com/cas domain, i would like to change the TGC domain to 
wildcard .example.com with cookie path set to "/" root path.



On Thursday, January 14, 2016 at 3:46:36 PM UTC-5, Misagh Moayyed wrote:
>
> That’s the file. I’d have to know what you changed and why before I can 
> recommend a path.
>
>  
>
> *From:* James Naadjie [mailto:[email protected] <javascript:>] 
> *Sent:* Thursday, January 14, 2016 12:46 PM
> *To:* CAS Community <[email protected] <javascript:>>
> *Cc:* [email protected] <javascript:>
> *Subject:* Re: [cas-user] CAS SLO for Rails and JAVA application
>
>  
>
> Thanks for the answers and pointing me in the right direction. Follow up 
> question.
>
> Would it be possible to change the TGC cookie domain and path?
>
> I have tried changing the  
>
> ticketGrantingTicketCookieGenerator.xml configuration for the cookie, but 
> the path doesn't change.
>
>  
>
>
>
> On Thursday, January 14, 2016 at 2:17:19 PM UTC-5, Misagh Moayyed wrote:
>
> Start with this:
>
> https://jasig.github.io/cas/4.1.x/installation/Logout-Single-Signout.html 
>
>  
>
> Also on the theory/context of SLO:
>
> https://wiki.shibboleth.net/confluence/display/CONCEPT/SLOIssues 
> <https://www.google.com/url?q=https%3A%2F%2Fwiki.shibboleth.net%2Fconfluence%2Fdisplay%2FCONCEPT%2FSLOIssues&sa=D&sntz=1&usg=AFQjCNH2KyE6hjQjcqW8mCiVfofWuK9vgA>
>
>  
>
> 1.       SLO is enabled by default in CAS.
>
> 2.       No special config is needed, unless you need it. 
>
> 3.       There is no way to get the TGC. 
>
>  
>
> CAS cannot log the user out of all applications magically. It has no 
> access to those apps. Instead, it sends a special message to those apps 
> asking them to logout, and this is why your B and C apps don’t log out 
> because they are either not receiving that request, or not responding to 
> it. 
>
>  
>
> *From:* [email protected] [mailto:[email protected]] *On Behalf Of *James 
> Naadjie
> *Sent:* Thursday, January 14, 2016 9:36 AM
> *To:* CAS Community <[email protected]>
> *Subject:* [cas-user] CAS SLO for Rails and JAVA application
>
>  
>
> I’m not very clear on how Single Log out works with CAS server 4.1 and 
> hope for a clear and simple explanation to help resolve an issue i’m having 
> with my client applications. 
>
> Currently SSO works fine with my two applications. 
>
> Users can login to application A,B and C, A and B are Ruby on Rails 
> applications using ruby-cas client. C is a Java application using acegi 
> security(Now Spring security)
>
> When users logout of application A, they are redirected to CAS server 
> logout view, but are still logged in to application B,C. Same goes for 
> logging out of B,C. 
>
>  
>
> Is SLO for Cas server 4.1 enabled by default?
>
> Does SLO require any special configuration to work on CAS server?
>
> Is there a way to get and store the cas TGT cookie (value of cas cookie)? 
>
> -- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected].
> Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/
> .
>
>

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to