- Nothing in CAS “requires” https. As such, there is no MUST. There is a very very strong SHOULD. Everything if not all is by default configured to assume https. You can turn all that off to use http only, or a combination. You should not do that.
- We recommend you use https for everything. That includes the CAS deployment, and all applications registered with CAS, and every callback URL and serviceId and logout URL and everything else. - Clients that initiate authentication with HTTP remain to be in HTTP as long as CAS allows HTTP access for that client. Same goes for HTTPS. You cannot change URL protocol in between. From: [email protected] [mailto:[email protected]] On Behalf Of Jonathan Labin Sent: Tuesday, January 26, 2016 12:59 PM To: CAS Community <[email protected]> Subject: [cas-user] Documentation Recommends https Could someone please help me understand the recommendation in the documentation to use Secure Transport <http://jasig.github.io/cas/4.1.x/planning/Security-Guide.html#secure-transport-https> ? During development, I've just used https for everything but I'd like to have a better understanding of which configuration items really require it. The page specifically states that "all CAS urls must use HTTPS" and to me this means all of the applications should configure their clients with https urls to endpoints such as loginURL, serverUrlPrefix, ... What about the URL provided as a service redirect argument to the /logout endpoint? I might guess this is O.K. to be http. The documentation also sates https should be used "when the generated service ticket is sent back to the application on the 'service' url" What is the practical implication of this? Does it mean that all serviceId values for registered services must begin with https? Does this also mean that the client callbackUrl must also be https? If these must all be https, does this mean that the application will always return from authentication in https? If the client was in http before authentication started, is there any way that they can end up in http after authentication? Thanks -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected] <mailto:[email protected]> . Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
