The biggest thing you will need to do is configure some sort of replication for the ticket registry .. pick a flavor (ehcache, memcache, whatever ...).
Also, with casshib you can do per-service on the SAML/shib side as well, since each shib service comes across to CAS separately (if you wish). MFA requirements are just an extra element in servicesregistry.json Regards, Michael Holstein Cleveland State University ________________________________ From: [email protected] <[email protected]> on behalf of Ted Fisher <[email protected]> Sent: Friday, January 15, 2016 3:55 PM To: [email protected] Subject: [cas-user] duo integration with CAS We are facing an urgent push to get duo integrated with our CAS and I'd like to get some feedback as to best approach, caveats, etc. Environment: CAS 3.5.0 on Tomcat 7, 2 RHEL 6 servers behind Cisco ACE load balancer 2 Shibboleth IDPs using CAS as auth handler. Needs / concerns Use duo only on specific services, which sounds like not much of an issue since cas-mfa supports per service and we are using a JSON service registry where we can configure settings for that. Our IDPs would likely then be all or nothing with duo since that is one CAS defined service. Or could we change CAS / Shibboleth integration to allow finer definition of the Shibboleth integrated service(s)? We considered adding duo 2FA to one of our new CAS services as a pilot month ago, but since our CAS is 3.5.0 and the Unicon cas-mfa project needs 3.5.2 we decided to wait. It looks like cas-mfa is the best way to get to duo with CAS, am I correct? We first upgrade our CAS to 3.5.3 and then add cas-mfa, configure and test. Please offer any specific considerations or caveats. Thanks. Ted F. Fisher Server Administrator 323 Hayes Hall Information Technology Services Email: [email protected]<mailto:[email protected]> Phone: 419.372.1626 [Description: BGSU] -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]<mailto:[email protected]>. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
