Most likely the ST just expires during your debugging session. The default expiration time is 10 second. Set it to a higher value for your debugging so it stays valid. The example below sets it to 3 minutes:
st.timeToKillInSeconds=180 This could be the same problem with your REST clients - by the time they perform /serviceValidate the ST had already expired. Cheers, D. > On Jun 1, 2016, at 10:48 AM, Yan Zhou <[email protected]> wrote: > > Hi, > > Running CAS 4.1.7 overlay, the web app works fine with CAS, until someone > says our CAS REST API keeps returning "invalid service ticket" when > /serviceValidate is called. > > I started to see how the CAS /serverValidate implementation works when user > logs in from CAS login page. I have noticed that if I go through the code in > debugger mode step by step, I always end up with "invalid ticket" when ST is > validated. > > The log is below, it does not show any sign of tickets being deleted. And, > if I login to app just like a normal user would (without stepping through in > debugger), everything is fine. > > I am using Hazlecrest as ticket registry. I do not think that is the issue. > > Any suggestion? > > Thx! > Yan > > this is my cas.properties for hazlecrest registry > > hz.cluster.members=localhost > > > this is the log, you can see that the ST is created but then we cannot find > it. > > 2016-06-01 10:40:54,916 INFO [org.jasig.cas.CentralAuthenticationServiceImpl] > - Granted ticket [ST-2-ybVUfMrDALVlxNXZbqm5-localhost.dev.medplus.com] for > service [http://localhost:8084/cas-admin/j_spring_cas_security_check] for > user [y] > 2016-06-01 10:40:57,039 INFO > [org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - Audit > trail record BEGIN > ============================================================= > WHO: y > WHAT: ST-2-ybVUfMrDALVlxNXZbqm5-localhost.dev.medplus.com for > http://localhost:8084/cas-admin/j_spring_cas_security_check > ACTION: SERVICE_TICKET_CREATED > APPLICATION: CAS > WHEN: Wed Jun 01 10:40:57 EDT 2016 > CLIENT IP ADDRESS: 127.0.0.1 > SERVER IP ADDRESS: 127.0.0.1 > ============================================================= > > > 2016-06-01 10:40:57,063 DEBUG > [org.springframework.web.servlet.DispatcherServlet] - Null ModelAndView > returned to DispatcherServlet with name 'cas': assuming HandlerAdapter > completed request handling > 2016-06-01 10:40:57,063 DEBUG > [org.springframework.web.servlet.DispatcherServlet] - Successfully completed > request > 2016-06-01 10:40:57,099 DEBUG > [org.springframework.web.servlet.DispatcherServlet] - DispatcherServlet with > name 'cas' processing GET request for [/cas/serviceValidate] > 2016-06-01 10:40:57,100 DEBUG > [org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping] > - Looking up handler method for path /serviceValidate > 2016-06-01 10:40:57,103 DEBUG > [org.springframework.web.servlet.mvc.method.annotation.RequestMappingHandlerMapping] > - Did not find handler method for [/serviceValidate] > 2016-06-01 10:40:57,104 DEBUG > [org.springframework.web.servlet.handler.SimpleUrlHandlerMapping] - Mapping > [/serviceValidate] to HandlerExecutionChain with handler > [org.jasig.cas.web.ServiceValidateController@3768d58d] and 1 interceptor > 2016-06-01 10:40:57,104 DEBUG > [org.springframework.web.servlet.DispatcherServlet] - Last-Modified value for > [/cas/serviceValidate] is: -1 > 2016-06-01 10:41:13,383 INFO [org.jasig.cas.CentralAuthenticationServiceImpl] > - Service ticket [ST-2-ybVUfMrDALVlxNXZbqm5-localhost.dev.medplus.com] does > not exist. > 2016-06-01 10:41:13,854 INFO > [org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - Audit > trail record BEGIN > ============================================================= > WHO: audit:unknown > WHAT: ST-2-ybVUfMrDALVlxNXZbqm5-localhost.dev.medplus.com > ACTION: SERVICE_TICKET_VALIDATE_FAILED > APPLICATION: CAS > WHEN: Wed Jun 01 10:41:13 EDT 2016 > CLIENT IP ADDRESS: 127.0.0.1 > SERVER IP ADDRESS: 127.0.0.1 > ============================================================= > > -- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] > <mailto:[email protected]>. > To post to this group, send email to [email protected] > <mailto:[email protected]>. > Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/ > <https://groups.google.com/a/apereo.org/group/cas-user/>. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/44fb53af-858b-4a82-8b84-797900389ab2%40apereo.org > > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/44fb53af-858b-4a82-8b84-797900389ab2%40apereo.org?utm_medium=email&utm_source=footer>. > For more options, visit https://groups.google.com/a/apereo.org/d/optout > <https://groups.google.com/a/apereo.org/d/optout>. -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To post to this group, send email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/59834B20-E7BC-475D-B0AF-A24C28E4086D%40unicon.net. For more options, visit https://groups.google.com/a/apereo.org/d/optout.
