It doesn't work for me.

I'm using maven release 5.1.1
- LDAP login on CAS (https://myserver:8443*/cas/login* : 
*AUTHENTICATION_SUCCESS*
- Acces to the */status* or /status/dashboard : "*YOU DID NOT SAY THE MAGIC 
WORD!.....*"

And i've only this on my cas.log :








*2017-06-27 16:43:06,813 DEBUG 
[org.apereo.cas.util.cipher.BaseStringCipherExecutor] - <Decrypting 
value...>2017-06-27 16:43:06,814 DEBUG 
[org.apereo.cas.web.support.DefaultCasCookieValueManager] - <Decoded cookie 
value is 
[TGT-**********************************************[email protected]@Mozilla/5.0
 
(Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko]>2017-06-27 
16:43:06,814 DEBUG 
[org.apereo.cas.authentication.PseudoPlatformTransactionManager] - 
<Creating new transaction with name 
[org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]:
 
PROPAGATION_REQUIRED,ISOLATION_DEFAULT; 
'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG 
[org.apereo.cas.authentication.PseudoPlatformTransactionManager] - 
<Creating new transaction with name 
[org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]:
 
PROPAGATION_REQUIRED,ISOLATION_DEFAULT; 
'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG 
[org.apereo.cas.authentication.PseudoPlatformTransactionManager] - 
<Initiating transaction commit>2017-06-27 16:43:06,814 DEBUG 
[org.apereo.cas.authentication.PseudoPlatformTransactionManager] - 
<Resuming suspended transaction after completion of inner 
transaction>2017-06-27 16:43:06,815 DEBUG 
[org.apereo.cas.authentication.PseudoPlatformTransactionManager] - 
<Initiating transaction commit>*Here my *cas.properties*

cas.server.name=https://server.domain.prive.fr:8443 
cas.server.prefix=https://server.domain.prive.fr:8443/cas 
> logging.config: file:/etc/cas/config/log4j2.xml 
> #======================================== 
> # Authentication #======================================== 
> cas.authn.accept.users= #======================================== ## 
> Embedded Tomcat HTTP/AJP ## Enable HTTP/AJP connections for the embedded 
> Tomcat container. #======================================== 
> cas.server.http.enabled=false #======================================== # 
> LDAP : #======================================== 
> cas.authn.ldap[0].type=AUTHENTICATED 
> cas.authn.ldap[0].ldapUrl=ldap://domain.prive.fr 
> cas.authn.ldap[0].useSsl=false 
> cas.authn.ldap[0].baseDn=dc=domain,dc=prive,dc=fr 
> cas.authn.ldap[0].userFilter=sAMAccountName={user} 
> cas.authn.ldap[0].bindDn=CN=BIND 
> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr 
> cas.authn.ldap[0].bindCredential=password 
> cas.authn.attributeRepository.ldap.ldapUrl=Ldap://domain.prive.fr 
> cas.authn.attributeRepository.ldap.minPoolSize=3 
> cas.authn.attributeRepository.ldap.maxPoolSize=10 
> cas.authn.attributeRepository.ldap.validateOnCheckout=false 
> cas.authn.attributeRepository.ldap.validatePeriodically=true 
> cas.acceptableUsagePolicy.ldap.ldapUrl=Ldap://domain.prive.fr 
> cas.acceptableUsagePolicy.ldap.baseDn=dc=domain,dc=prive,dc=fr 
> cas.acceptableUsagePolicy.ldap.userFilter=sAMAccountName={user} 
> cas.acceptableUsagePolicy.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider
>  
> cas.acceptableUsagePolicy.ldap.connectTimeout=5000 
> cas.acceptableUsagePolicy.ldap.minPoolSize=3 
> cas.acceptableUsagePolicy.ldap.maxPoolSize=10 
> cas.acceptableUsagePolicy.ldap.validateOnCheckout=true 
> cas.acceptableUsagePolicy.ldap.validatePeriodically=true 
> cas.acceptableUsagePolicy.ldap.validatePeriod=600 
> cas.acceptableUsagePolicy.ldap.idleTime=500 
> cas.acceptableUsagePolicy.ldap.prunePeriod=600 
> cas.acceptableUsagePolicy.ldap.blockWaitTime=5000 
> cas.acceptableUsagePolicy.ldap.useStartTls=false 
> cas.serviceRegistry.ldap.idAttribute=sAMAccountName 
> cas.serviceRegistry.ldap.ldapUrl=Ldap://domain.prive.fr 
> cas.serviceRegistry.ldap.baseDn=dc=domain,dc=prive,dc=fr 
> cas.serviceRegistry.ldap.bindDn=CN=BIND 
> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr 
> cas.serviceRegistry.ldap.bindCredential=password 
> cas.serviceRegistry.ldap.useSsl=false cas.mgmt.ldapAuthz.rolePrefix=ROLE_ 
> cas.mgmt.ldapAuthz.searchFilter=cn={user} cas.mgmt.ldapAuthz.roleAttribute
> =uugid cas.mgmt.ldapAuthz.ldapUrl=Ldap://domain.prive.fr 
> cas.mgmt.ldapAuthz.baseDn=dc=domain,dc=prive,dc=fr 
> cas.mgmt.ldapAuthz.userFilter=sAMAccountName={user} 
> cas.mgmt.ldapAuthz.bindDn=CN=BIND 
> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr 
> cas.mgmt.ldapAuthz.bindCredential=password cas.mgmt.ldapAuthz.useSsl=false 
> cas.adminPagesSecurity.ldap.type=AUTHENTICATED 
> cas.adminPagesSecurity.ldap.ldapUrl=Ldap://domain.prive.fr 
> cas.adminPagesSecurity.ldap.useSsl=false 
> cas.adminPagesSecurity.ldap.baseDn=dc=domain,dc=prive,dc=fr 
> cas.adminPagesSecurity.ldap.userFilter=sAMAccountName={user} 
> cas.adminPagesSecurity.ldap.bindDn=CN=BIND 
> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr 
> cas.adminPagesSecurity.ldap.bindCredential=password 
> cas.monitor.ldap.ldapUrl=Ldap://domain.prive.fr 
> cas.monitor.ldap.baseDn=dc=domain,dc=prive,dc=fr 
> cas.monitor.ldap.userFilter=sAMAccountName={user} 
> cas.monitor.ldap.bindDn=CN=BIND 
> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr 
> cas.monitor.ldap.bindCredential=password 
> cas.monitor.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider
>  
> cas.monitor.ldap.useSsl=false #======================================== # 
> Management Webapp #======================================== 
> cas.mgmt.adminRoles=ROLE_ADMIN 
> cas.mgmt.userPropertiesFile=file:/etc/cas/config/users.properties 
> #======================================== # Admin Status Endpoints # The 
> following properties describe access controls and settings for the /status 
> endpoint of CAS which provides administrative functionality and oversight 
> into the CAS software. To learn more about this topic, please review this 
> guide. #======================================== 
> cas.monitor.endpoints.enabled=true cas.monitor.endpoints.sensitive=false 
> cas.monitor.endpoints.dashboard.enabled=true 
> cas.monitor.endpoints.dashboard.sensitive=false 
> cas.monitor.endpoints.status.enabled=true 
> cas.monitor.endpoints.status.sensitive=false 
> cas.adminPagesSecurity.users=file:/etc/cas/config/adminusers.properties 
> cas.adminPagesSecurity.adminRoles=ROLE_ADMIN cas.adminPagesSecurity.ip= 
> #======================================== 
> # Service Registry #======================================== 
> cas.serviceRegistry.watcherEnabled=true cas.serviceRegistry.initFromJson=
> true
>

 




Le lundi 26 juin 2017 22:29:21 UTC+2, crdaudt a écrit :
>
> I have set up a test instance of a CAS 5.1.0 server running under tomcat 
> with a fairly minimal configuration.  I would like to enable the /status 
> from my workstation's IP address (or better yet, two or three ranges of IP 
> addresses).  I am not able to make sense of the documentation for how to 
> accomplish this (
> https://apereo.github.io/cas/5.1.x/installation/Monitoring-Statistics.html, 
> https://apereo.github.io/cas/5.1.x/installation/Configuring-Monitoring.html, 
> and 
> https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html).
>   
> When I attempt to visit https://<CAS_URL>/cas/status, I am directed to an 
> error pages that states "YOU DID NOT SAY THE MAGIC WORD!" and "We are 
> sorry. You do not have permission to view this page".
>
> Here is what I have so far:
> ----------BEGIN cas.properties-----------
> cas.server.name: https://my.test.cas.server
> cas.server.prefix: https://my.test.cas.server/cas
> cas.host.name: my.test.cas.server
> logging.config: file:/etc/cas/config/log4j2.xml
> ###cas.authn.accept.users=casuser::Mellon
> cas.authn.accept.users=
> #ldap stuff:
> cas.authn.ldap[0].type=AUTHENTICATED
> cas.authn.ldap[0].ldapUrl=ldaps://my.ldap.server:636/
> cas.authn.ldap[0].useSsl=true
> cas.authn.ldap[0].useStartTls=false
>
> cas.authn.ldap[0].trustCertificates=file:/etc/cas/certificates_to_trust/i_trust_this_ca.cer
> cas.authn.ldap[0].connectTimeout=5000
> cas.authn.ldap[0].principalAttributeID=sAMAccountName
>
> cas.authn.ldap[0].principalAttributeList=sAMAccountName,displayName,mail,memberOf,description:UDC_IDENTIFIER
> cas.authn.ldap[0].baseDn=dc=xxx,dc=yyy,dc=edu
> cas.authn.ldap[0].bindDn=cn=ldap,cn=Users,dc=xxx,dc=yyy,dc=edu
> cas.authn.ldap[0].bindCredential=XXXXXXXXXX
> cas.authn.ldap[0].userFilter=sAMAccountName={user}
> cas.authn.ldap[0].subtreeSearch=true
> cas.authn.ldap[0].minPoolSize=3
> cas.authn.ldap[0].maxPoolSize=10
> cas.authn.ldap[0].validateOnCheckout=true
> cas.authn.ldap[0].validatePeriodically=true
> cas.authn.ldap[0].validatePeriod=600
> cas.authn.ldap[0].failFast=true
> cas.authn.ldap[0].idleTime=500
> cas.authn.ldap[0].prunePeriod=600
> cas.authn.ldap[0].blockWaitTime=5000
> ## attempting to grant /status privilege to the workstation with the 
> following IP address
> cas.adminPagesSecurity.ip=10\.11\.12\.13
> ----------END cas.properties-----------
>
> For deploying CAS with maven overlay, I used the following for pom.xml:
>
> ----------BEGIN pom.xml-----------
> <?xml version="1.0" encoding="UTF-8"?>
> <project xmlns="http://maven.apache.org/POM/4.0.0";
>          xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance";
>          xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 
> http://maven.apache.org/xsd/maven-4.0.0.xsd ">
>     <modelVersion>4.0.0</modelVersion>
>     <groupId>org.apereo.cas</groupId>
>     <artifactId>cas-overlay</artifactId>
>     <packaging>war</packaging>
>     <version>1.0</version>
>
>     <build>
>         <plugins>
>             <plugin>
>                 <groupId>com.rimerosolutions.maven.plugins</groupId>
>                 <artifactId>wrapper-maven-plugin</artifactId>
>                 <version>0.0.4</version>
>                 <configuration>
>                     <verifyDownload>true</verifyDownload>
>                     <checksumAlgorithm>MD5</checksumAlgorithm>
>                 </configuration>
>             </plugin>
>             <plugin>
>                 <groupId>org.springframework.boot</groupId>
>                 <artifactId>spring-boot-maven-plugin</artifactId>
>                 <version>${springboot.version}</version>
>                 <configuration>
>                     
> <mainClass>org.springframework.boot.loader.WarLauncher</mainClass>
>                     <addResources>true</addResources>
>                 </configuration>
>             </plugin>
>             <plugin>
>                 <groupId>org.apache.maven.plugins</groupId>
>                 <artifactId>maven-war-plugin</artifactId>
>                 <version>2.6</version>
>                 <configuration>
>                     <warName>cas</warName>
>                     <failOnMissingWebXml>false</failOnMissingWebXml>
>                     <recompressZippedFiles>false</recompressZippedFiles>
>                     <archive>
>                         <compress>false</compress>
>                         
> <manifestFile>${project.build.directory}/war/work/org.apereo.cas/cas-server-webapp/META-INF/MANIFEST.MF
>                         </manifestFile>
>                     </archive>
>                     <overlays>
>                         <overlay>
>                             <groupId>org.apereo.cas</groupId>
>                             <artifactId>cas-server-webapp</artifactId>
>                         </overlay>
>                     </overlays>
>                 </configuration>
>             </plugin>
>             <plugin>
>                 <groupId>org.apache.maven.plugins</groupId>
>                 <artifactId>maven-compiler-plugin</artifactId>
>                 <version>3.3</version>
>             </plugin>
>         </plugins>
>         <finalName>cas</finalName>
>     </build>
>
>     <dependencies>
>         <dependency>
>             <groupId>org.apereo.cas</groupId>
>             <artifactId>cas-server-webapp</artifactId>
>             <version>${cas.version}</version>
>             <type>war</type>
>             <scope>runtime</scope>
>         </dependency>
>         <dependency>
>             <groupId>org.apereo.cas</groupId>
>             <artifactId>cas-server-support-ldap</artifactId>
>             <version>${cas.version}</version>
>         </dependency>
>         <dependency>
>             <groupId>org.ldaptive</groupId>
>             <artifactId>ldaptive-unboundid</artifactId>
>             <version>1.0</version>
>         </dependency>
>     </dependencies>
>
>     <properties>
>         <cas.version>5.1.0</cas.version>
>         <springboot.version>1.5.3.RELEASE</springboot.version>
>         <maven.compiler.source>1.8</maven.compiler.source>
>         <maven.compiler.target>1.8</maven.compiler.target>
>         <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
>     </properties>
>
>     <repositories>
>         <repository>
>             <id>sonatype-releases</id>
>             <url>http://oss.sonatype.org/content/repositories/releases/
> </url>
>             <snapshots>
>                 <enabled>false</enabled>
>             </snapshots>
>             <releases>
>                 <enabled>true</enabled>
>             </releases>
>         </repository>
>         <repository>
>             <id>sonatype-snapshots</id>
>             <url>https://oss.sonatype.org/content/repositories/snapshots/
> </url>
>             <snapshots>
>                 <enabled>true</enabled>
>             </snapshots>
>             <releases>
>                 <enabled>false</enabled>
>             </releases>
>         </repository>
>         <repository>
>             <id>shibboleth-releases</id>
>             <url>
> https://build.shibboleth.net/nexus/content/repositories/releases</url>
>         </repository>
>         <repository>
>             <id>spring-milestones</id>
>             <url>https://repo.spring.io/milestone</url>
>         </repository>
>     </repositories>
>
>     <profiles>
>         <profile>
>             <activation>
>                 <activeByDefault>false</activeByDefault>
>             </activation>
>             <id>pgp</id>
>             <build>
>                 <plugins>
>                     <plugin>
>                         <groupId>com.github.s4u.plugins</groupId>
>                         <artifactId>pgpverify-maven-plugin</artifactId>
>                         <version>1.1.0</version>
>                         <executions>
>                             <execution>
>                                 <goals>
>                                     <goal>check</goal>
>                                 </goals>
>                             </execution>
>                         </executions>
>                         <configuration>
>                             <pgpKeyServer>hkp://pool.sks-keyservers.net
> </pgpKeyServer>
>                             
> <pgpKeysCachePath>${settings.localRepository}/pgpkeys-cache</pgpKeysCachePath>
>                             <scope>test</scope>
>                             <verifyPomFiles>true</verifyPomFiles>
>                             <failNoSignature>false</failNoSignature>
>                         </configuration>
>                     </plugin>
>                 </plugins>
>             </build>
>         </profile>
>     </profiles>
> </project>
> ----------END pom.xml-----------
>
> -- 
> - CAS gitter chatroom: https://gitter.im/apereo/cas
> - CAS mailing list guidelines: 
> https://apereo.github.io/cas/Mailing-Lists.html
> - CAS documentation website: https://apereo.github.io/cas
> - CAS project website: https://github.com/apereo/cas
> --- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] <javascript:>.
> To view this discussion on the web visit 
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org
>  
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org?utm_medium=email&utm_source=footer>
> .
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/631812e1-a712-4370-8e15-1217ba91cdef%40googlegroups.com.

Reply via email to