Same issue. Worked fine in 5.0.6, and the docs suggest that the same is available in 5.1.0/5.1.1, sadly doesn't work the same. Similarly, the additional support for different kinds of security (Basic authentication, LDAP, etc) should be just that, additional support if desired, not a requirement.
If anyone figures this out, please share. Thanks. On Monday, June 26, 2017 at 4:29:20 PM UTC-4, crdaudt wrote: > > I have set up a test instance of a CAS 5.1.0 server running under tomcat > with a fairly minimal configuration. I would like to enable the /status > from my workstation's IP address (or better yet, two or three ranges of IP > addresses). I am not able to make sense of the documentation for how to > accomplish this ( > https://apereo.github.io/cas/5.1.x/installation/Monitoring-Statistics.html, > https://apereo.github.io/cas/5.1.x/installation/Configuring-Monitoring.html, > and > https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html). > > When I attempt to visit https://<CAS_URL>/cas/status, I am directed to an > error pages that states "YOU DID NOT SAY THE MAGIC WORD!" and "We are > sorry. You do not have permission to view this page". > > Here is what I have so far: > ----------BEGIN cas.properties----------- > cas.server.name: https://my.test.cas.server > cas.server.prefix: https://my.test.cas.server/cas > cas.host.name: my.test.cas.server > logging.config: file:/etc/cas/config/log4j2.xml > ###cas.authn.accept.users=casuser::Mellon > cas.authn.accept.users= > #ldap stuff: > cas.authn.ldap[0].type=AUTHENTICATED > cas.authn.ldap[0].ldapUrl=ldaps://my.ldap.server:636/ > cas.authn.ldap[0].useSsl=true > cas.authn.ldap[0].useStartTls=false > > cas.authn.ldap[0].trustCertificates=file:/etc/cas/certificates_to_trust/i_trust_this_ca.cer > cas.authn.ldap[0].connectTimeout=5000 > cas.authn.ldap[0].principalAttributeID=sAMAccountName > > cas.authn.ldap[0].principalAttributeList=sAMAccountName,displayName,mail,memberOf,description:UDC_IDENTIFIER > cas.authn.ldap[0].baseDn=dc=xxx,dc=yyy,dc=edu > cas.authn.ldap[0].bindDn=cn=ldap,cn=Users,dc=xxx,dc=yyy,dc=edu > cas.authn.ldap[0].bindCredential=XXXXXXXXXX > cas.authn.ldap[0].userFilter=sAMAccountName={user} > cas.authn.ldap[0].subtreeSearch=true > cas.authn.ldap[0].minPoolSize=3 > cas.authn.ldap[0].maxPoolSize=10 > cas.authn.ldap[0].validateOnCheckout=true > cas.authn.ldap[0].validatePeriodically=true > cas.authn.ldap[0].validatePeriod=600 > cas.authn.ldap[0].failFast=true > cas.authn.ldap[0].idleTime=500 > cas.authn.ldap[0].prunePeriod=600 > cas.authn.ldap[0].blockWaitTime=5000 > ## attempting to grant /status privilege to the workstation with the > following IP address > cas.adminPagesSecurity.ip=10\.11\.12\.13 > ----------END cas.properties----------- > > For deploying CAS with maven overlay, I used the following for pom.xml: > > ----------BEGIN pom.xml----------- > <?xml version="1.0" encoding="UTF-8"?> > <project xmlns="http://maven.apache.org/POM/4.0.0" > xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" > xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 > http://maven.apache.org/xsd/maven-4.0.0.xsd "> > <modelVersion>4.0.0</modelVersion> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-overlay</artifactId> > <packaging>war</packaging> > <version>1.0</version> > > <build> > <plugins> > <plugin> > <groupId>com.rimerosolutions.maven.plugins</groupId> > <artifactId>wrapper-maven-plugin</artifactId> > <version>0.0.4</version> > <configuration> > <verifyDownload>true</verifyDownload> > <checksumAlgorithm>MD5</checksumAlgorithm> > </configuration> > </plugin> > <plugin> > <groupId>org.springframework.boot</groupId> > <artifactId>spring-boot-maven-plugin</artifactId> > <version>${springboot.version}</version> > <configuration> > > <mainClass>org.springframework.boot.loader.WarLauncher</mainClass> > <addResources>true</addResources> > </configuration> > </plugin> > <plugin> > <groupId>org.apache.maven.plugins</groupId> > <artifactId>maven-war-plugin</artifactId> > <version>2.6</version> > <configuration> > <warName>cas</warName> > <failOnMissingWebXml>false</failOnMissingWebXml> > <recompressZippedFiles>false</recompressZippedFiles> > <archive> > <compress>false</compress> > > <manifestFile>${project.build.directory}/war/work/org.apereo.cas/cas-server-webapp/META-INF/MANIFEST.MF > </manifestFile> > </archive> > <overlays> > <overlay> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-webapp</artifactId> > </overlay> > </overlays> > </configuration> > </plugin> > <plugin> > <groupId>org.apache.maven.plugins</groupId> > <artifactId>maven-compiler-plugin</artifactId> > <version>3.3</version> > </plugin> > </plugins> > <finalName>cas</finalName> > </build> > > <dependencies> > <dependency> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-webapp</artifactId> > <version>${cas.version}</version> > <type>war</type> > <scope>runtime</scope> > </dependency> > <dependency> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-support-ldap</artifactId> > <version>${cas.version}</version> > </dependency> > <dependency> > <groupId>org.ldaptive</groupId> > <artifactId>ldaptive-unboundid</artifactId> > <version>1.0</version> > </dependency> > </dependencies> > > <properties> > <cas.version>5.1.0</cas.version> > <springboot.version>1.5.3.RELEASE</springboot.version> > <maven.compiler.source>1.8</maven.compiler.source> > <maven.compiler.target>1.8</maven.compiler.target> > <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> > </properties> > > <repositories> > <repository> > <id>sonatype-releases</id> > <url>http://oss.sonatype.org/content/repositories/releases/ > </url> > <snapshots> > <enabled>false</enabled> > </snapshots> > <releases> > <enabled>true</enabled> > </releases> > </repository> > <repository> > <id>sonatype-snapshots</id> > <url>https://oss.sonatype.org/content/repositories/snapshots/ > </url> > <snapshots> > <enabled>true</enabled> > </snapshots> > <releases> > <enabled>false</enabled> > </releases> > </repository> > <repository> > <id>shibboleth-releases</id> > <url> > https://build.shibboleth.net/nexus/content/repositories/releases</url> > </repository> > <repository> > <id>spring-milestones</id> > <url>https://repo.spring.io/milestone</url> > </repository> > </repositories> > > <profiles> > <profile> > <activation> > <activeByDefault>false</activeByDefault> > </activation> > <id>pgp</id> > <build> > <plugins> > <plugin> > <groupId>com.github.s4u.plugins</groupId> > <artifactId>pgpverify-maven-plugin</artifactId> > <version>1.1.0</version> > <executions> > <execution> > <goals> > <goal>check</goal> > </goals> > </execution> > </executions> > <configuration> > <pgpKeyServer>hkp://pool.sks-keyservers.net > </pgpKeyServer> > > <pgpKeysCachePath>${settings.localRepository}/pgpkeys-cache</pgpKeysCachePath> > <scope>test</scope> > <verifyPomFiles>true</verifyPomFiles> > <failNoSignature>false</failNoSignature> > </configuration> > </plugin> > </plugins> > </build> > </profile> > </profiles> > </project> > ----------END pom.xml----------- > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/9a034db2-269e-402a-ab9f-797789558301%40apereo.org.
