Hi Trenton, I did check out the linked document prior to posting the question. I am not convinced one can declare CAS "supports" SAML based on the linked document. I believe the document merely indicates that CAS has a /samlValidate URI that can be used to obtain a SAML 1.1 ticket validation response. We are looking for CAS to issue some sort of SAML tokens as part of the CAS sign in, and a solution similar to proxy granting tickets and proxy tickets in CAS.
Thanks, Mitch On 2016-03-07, at 1:43 PM, Trenton D. Adams <[email protected]> wrote: > Yes, CAS supports SAML. > > https://wiki.jasig.org/display/CASUM/SAML+1.1 > > Trenton D. Adams > Senior Systems Analyst/Web Software Developer > Navy Penguins at your service! > Athabasca University > (780) 675-6195 > :wq! > > ----- "Mitch Chang" <[email protected]> wrote: > > From: "Mitch Chang" <[email protected]> > > To: "CAS Community" <[email protected]> > > Sent: Monday, March 7, 2016 1:17:57 PM GMT -07:00 US/Canada Mountain > > Subject: [cas-user] SAML support in CAS > > > > Hi, > we are exploring solutions to a request in hand for CAS. We are running CAS > 3.5.3. > > > > So far we believe one potential solution is to use Proxy Granting Ticket and > Proxy Ticket in CAS, but the client would like to know whether there is a > potential CAS SAML solution. Here is a description of the request: > > > > There are 2 services involved: One is a CASified service, Dashboard, and the > other, API Gateway, is not CASified (and the client does not want it to be > CASified). Dashboard needs to access API Gateway on behalf of the user. > Naturally, using PGT and PT seems to be a decent solution and the workflow > shall be similar to the following: > > > > Dashboard obtains a service ticket when a user signs in through CAS. > Dashboard obtains a PGTID upon validating the service ticket. > Dashboard obtains a PT for API Gateway using the PGTID. > Dashboard passes the PT to API Gateway to request an access token. > API Gateway validates the PT with CAS to obtain a CAS response that > contains some user information (user id for instance). > API Gateway then returns an access token to Dashboard. > Dashboard uses the access token to access API Gateway on behalf of the > user. > > > > However, since API Gateway already knows how to handle SAML tokens, and the > client prefers not having to write custom code in Dashboard to handle the > pgtUrl for storing PGTIOU and PGTID, we are looking to see whether there is a > similar solution by using the SAML support in CAS. I suppose Dashboard would > obtain a SAML token from CAS when a user signs in, passes the SAML token to > API Gateway, which then verifies the authenticity of the SAML token. Once the > SAML token has been verified, API Gateway then returns an access token to > Dashboard. Dashboard uses the access token to access API Gateway on behalf of > the user. > > > > I have checked out a number of discussion threads and online documents, > including https://wiki.jasig.org/display/CASUM/SAML+1.1 and > https://wiki.jasig.org/display/CASUM/SAML+Support+in+CAS+4 but I still cannot > conclude for sure the SAML support in CAS is sufficient or not. Does anyone > have any insights or have done something similar? > > > > Thanks, > Mitch > > > > -- > > You received this message because you are subscribed to the Google Groups > > "CAS Community" group. > > To unsubscribe from this group and stop receiving emails from it, send an > > email to [email protected]. > > Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. > > > > This communication is intended for the use of the recipient to whom it is > addressed, and may contain confidential, personal, and or privileged > information. Please contact us immediately if you are not the intended > recipient of this communication, and do not copy, distribute, or take action > relying on it. Any communications received in error, or subsequent reply, > should be deleted or destroyed. > > -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
