Could someone please help me understand the recommendation in the documentation to use Secure Transport <http://jasig.github.io/cas/4.1.x/planning/Security-Guide.html#secure-transport-https> ? During development, I've just used https for everything but I'd like to have a better understanding of which configuration items really require it.
The page specifically states that "all CAS urls must use HTTPS" and to me this means all of the applications should configure their clients with https urls to endpoints such as loginURL, serverUrlPrefix, ... What about the URL provided as a service redirect argument to the /logout endpoint? I might guess this is O.K. to be http. The documentation also sates https should be used "when the generated service ticket is sent back to the application on the 'service' url" What is the practical implication of this? Does it mean that all serviceId values for registered services must begin with https? Does this also mean that the client callbackUrl must also be https? If these must all be https, does this mean that the application will always return from authentication in https? If the client was in http before authentication started, is there any way that they can end up in http after authentication? Thanks -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
