It doesn't work for me. I'm using maven release 5.1.1 - LDAP login on CAS (https://myserver:8443*/cas/login* : *AUTHENTICATION_SUCCESS* - Acces to the */status* or /status/dashboard : "*YOU DID NOT SAY THE MAGIC WORD!.....*"
And i've only this on my cas.log : *2017-06-27 16:43:06,813 DEBUG [org.apereo.cas.util.cipher.BaseStringCipherExecutor] - <Decrypting value...>2017-06-27 16:43:06,814 DEBUG [org.apereo.cas.web.support.DefaultCasCookieValueManager] - <Decoded cookie value is [TGT-**********************************************[email protected]@Mozilla/5.0 (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko]>2017-06-27 16:43:06,814 DEBUG [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - <Creating new transaction with name [org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]: PROPAGATION_REQUIRED,ISOLATION_DEFAULT; 'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - <Creating new transaction with name [org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]: PROPAGATION_REQUIRED,ISOLATION_DEFAULT; 'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - <Initiating transaction commit>2017-06-27 16:43:06,814 DEBUG [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - <Resuming suspended transaction after completion of inner transaction>2017-06-27 16:43:06,815 DEBUG [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - <Initiating transaction commit>*Here my *cas.properties* cas.server.name=https://server.domain.prive.fr:8443 cas.server.prefix=https://server.domain.prive.fr:8443/cas > logging.config: file:/etc/cas/config/log4j2.xml > #======================================== > # Authentication #======================================== > cas.authn.accept.users= #======================================== ## > Embedded Tomcat HTTP/AJP ## Enable HTTP/AJP connections for the embedded > Tomcat container. #======================================== > cas.server.http.enabled=false #======================================== # > LDAP : #======================================== > cas.authn.ldap[0].type=AUTHENTICATED > cas.authn.ldap[0].ldapUrl=ldap://domain.prive.fr > cas.authn.ldap[0].useSsl=false > cas.authn.ldap[0].baseDn=dc=domain,dc=prive,dc=fr > cas.authn.ldap[0].userFilter=sAMAccountName={user} > cas.authn.ldap[0].bindDn=CN=BIND > Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr > cas.authn.ldap[0].bindCredential=password > cas.authn.attributeRepository.ldap.ldapUrl=Ldap://domain.prive.fr > cas.authn.attributeRepository.ldap.minPoolSize=3 > cas.authn.attributeRepository.ldap.maxPoolSize=10 > cas.authn.attributeRepository.ldap.validateOnCheckout=false > cas.authn.attributeRepository.ldap.validatePeriodically=true > cas.acceptableUsagePolicy.ldap.ldapUrl=Ldap://domain.prive.fr > cas.acceptableUsagePolicy.ldap.baseDn=dc=domain,dc=prive,dc=fr > cas.acceptableUsagePolicy.ldap.userFilter=sAMAccountName={user} > cas.acceptableUsagePolicy.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider > > cas.acceptableUsagePolicy.ldap.connectTimeout=5000 > cas.acceptableUsagePolicy.ldap.minPoolSize=3 > cas.acceptableUsagePolicy.ldap.maxPoolSize=10 > cas.acceptableUsagePolicy.ldap.validateOnCheckout=true > cas.acceptableUsagePolicy.ldap.validatePeriodically=true > cas.acceptableUsagePolicy.ldap.validatePeriod=600 > cas.acceptableUsagePolicy.ldap.idleTime=500 > cas.acceptableUsagePolicy.ldap.prunePeriod=600 > cas.acceptableUsagePolicy.ldap.blockWaitTime=5000 > cas.acceptableUsagePolicy.ldap.useStartTls=false > cas.serviceRegistry.ldap.idAttribute=sAMAccountName > cas.serviceRegistry.ldap.ldapUrl=Ldap://domain.prive.fr > cas.serviceRegistry.ldap.baseDn=dc=domain,dc=prive,dc=fr > cas.serviceRegistry.ldap.bindDn=CN=BIND > Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr > cas.serviceRegistry.ldap.bindCredential=password > cas.serviceRegistry.ldap.useSsl=false cas.mgmt.ldapAuthz.rolePrefix=ROLE_ > cas.mgmt.ldapAuthz.searchFilter=cn={user} cas.mgmt.ldapAuthz.roleAttribute > =uugid cas.mgmt.ldapAuthz.ldapUrl=Ldap://domain.prive.fr > cas.mgmt.ldapAuthz.baseDn=dc=domain,dc=prive,dc=fr > cas.mgmt.ldapAuthz.userFilter=sAMAccountName={user} > cas.mgmt.ldapAuthz.bindDn=CN=BIND > Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr > cas.mgmt.ldapAuthz.bindCredential=password cas.mgmt.ldapAuthz.useSsl=false > cas.adminPagesSecurity.ldap.type=AUTHENTICATED > cas.adminPagesSecurity.ldap.ldapUrl=Ldap://domain.prive.fr > cas.adminPagesSecurity.ldap.useSsl=false > cas.adminPagesSecurity.ldap.baseDn=dc=domain,dc=prive,dc=fr > cas.adminPagesSecurity.ldap.userFilter=sAMAccountName={user} > cas.adminPagesSecurity.ldap.bindDn=CN=BIND > Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr > cas.adminPagesSecurity.ldap.bindCredential=password > cas.monitor.ldap.ldapUrl=Ldap://domain.prive.fr > cas.monitor.ldap.baseDn=dc=domain,dc=prive,dc=fr > cas.monitor.ldap.userFilter=sAMAccountName={user} > cas.monitor.ldap.bindDn=CN=BIND > Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr > cas.monitor.ldap.bindCredential=password > cas.monitor.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider > > cas.monitor.ldap.useSsl=false #======================================== # > Management Webapp #======================================== > cas.mgmt.adminRoles=ROLE_ADMIN > cas.mgmt.userPropertiesFile=file:/etc/cas/config/users.properties > #======================================== # Admin Status Endpoints # The > following properties describe access controls and settings for the /status > endpoint of CAS which provides administrative functionality and oversight > into the CAS software. To learn more about this topic, please review this > guide. #======================================== > cas.monitor.endpoints.enabled=true cas.monitor.endpoints.sensitive=false > cas.monitor.endpoints.dashboard.enabled=true > cas.monitor.endpoints.dashboard.sensitive=false > cas.monitor.endpoints.status.enabled=true > cas.monitor.endpoints.status.sensitive=false > cas.adminPagesSecurity.users=file:/etc/cas/config/adminusers.properties > cas.adminPagesSecurity.adminRoles=ROLE_ADMIN cas.adminPagesSecurity.ip= > #======================================== > # Service Registry #======================================== > cas.serviceRegistry.watcherEnabled=true cas.serviceRegistry.initFromJson= > true > Le lundi 26 juin 2017 22:29:21 UTC+2, crdaudt a écrit : > > I have set up a test instance of a CAS 5.1.0 server running under tomcat > with a fairly minimal configuration. I would like to enable the /status > from my workstation's IP address (or better yet, two or three ranges of IP > addresses). I am not able to make sense of the documentation for how to > accomplish this ( > https://apereo.github.io/cas/5.1.x/installation/Monitoring-Statistics.html, > https://apereo.github.io/cas/5.1.x/installation/Configuring-Monitoring.html, > and > https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html). > > When I attempt to visit https://<CAS_URL>/cas/status, I am directed to an > error pages that states "YOU DID NOT SAY THE MAGIC WORD!" and "We are > sorry. You do not have permission to view this page". > > Here is what I have so far: > ----------BEGIN cas.properties----------- > cas.server.name: https://my.test.cas.server > cas.server.prefix: https://my.test.cas.server/cas > cas.host.name: my.test.cas.server > logging.config: file:/etc/cas/config/log4j2.xml > ###cas.authn.accept.users=casuser::Mellon > cas.authn.accept.users= > #ldap stuff: > cas.authn.ldap[0].type=AUTHENTICATED > cas.authn.ldap[0].ldapUrl=ldaps://my.ldap.server:636/ > cas.authn.ldap[0].useSsl=true > cas.authn.ldap[0].useStartTls=false > > cas.authn.ldap[0].trustCertificates=file:/etc/cas/certificates_to_trust/i_trust_this_ca.cer > cas.authn.ldap[0].connectTimeout=5000 > cas.authn.ldap[0].principalAttributeID=sAMAccountName > > cas.authn.ldap[0].principalAttributeList=sAMAccountName,displayName,mail,memberOf,description:UDC_IDENTIFIER > cas.authn.ldap[0].baseDn=dc=xxx,dc=yyy,dc=edu > cas.authn.ldap[0].bindDn=cn=ldap,cn=Users,dc=xxx,dc=yyy,dc=edu > cas.authn.ldap[0].bindCredential=XXXXXXXXXX > cas.authn.ldap[0].userFilter=sAMAccountName={user} > cas.authn.ldap[0].subtreeSearch=true > cas.authn.ldap[0].minPoolSize=3 > cas.authn.ldap[0].maxPoolSize=10 > cas.authn.ldap[0].validateOnCheckout=true > cas.authn.ldap[0].validatePeriodically=true > cas.authn.ldap[0].validatePeriod=600 > cas.authn.ldap[0].failFast=true > cas.authn.ldap[0].idleTime=500 > cas.authn.ldap[0].prunePeriod=600 > cas.authn.ldap[0].blockWaitTime=5000 > ## attempting to grant /status privilege to the workstation with the > following IP address > cas.adminPagesSecurity.ip=10\.11\.12\.13 > ----------END cas.properties----------- > > For deploying CAS with maven overlay, I used the following for pom.xml: > > ----------BEGIN pom.xml----------- > <?xml version="1.0" encoding="UTF-8"?> > <project xmlns="http://maven.apache.org/POM/4.0.0" > xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" > xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 > http://maven.apache.org/xsd/maven-4.0.0.xsd "> > <modelVersion>4.0.0</modelVersion> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-overlay</artifactId> > <packaging>war</packaging> > <version>1.0</version> > > <build> > <plugins> > <plugin> > <groupId>com.rimerosolutions.maven.plugins</groupId> > <artifactId>wrapper-maven-plugin</artifactId> > <version>0.0.4</version> > <configuration> > <verifyDownload>true</verifyDownload> > <checksumAlgorithm>MD5</checksumAlgorithm> > </configuration> > </plugin> > <plugin> > <groupId>org.springframework.boot</groupId> > <artifactId>spring-boot-maven-plugin</artifactId> > <version>${springboot.version}</version> > <configuration> > > <mainClass>org.springframework.boot.loader.WarLauncher</mainClass> > <addResources>true</addResources> > </configuration> > </plugin> > <plugin> > <groupId>org.apache.maven.plugins</groupId> > <artifactId>maven-war-plugin</artifactId> > <version>2.6</version> > <configuration> > <warName>cas</warName> > <failOnMissingWebXml>false</failOnMissingWebXml> > <recompressZippedFiles>false</recompressZippedFiles> > <archive> > <compress>false</compress> > > <manifestFile>${project.build.directory}/war/work/org.apereo.cas/cas-server-webapp/META-INF/MANIFEST.MF > </manifestFile> > </archive> > <overlays> > <overlay> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-webapp</artifactId> > </overlay> > </overlays> > </configuration> > </plugin> > <plugin> > <groupId>org.apache.maven.plugins</groupId> > <artifactId>maven-compiler-plugin</artifactId> > <version>3.3</version> > </plugin> > </plugins> > <finalName>cas</finalName> > </build> > > <dependencies> > <dependency> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-webapp</artifactId> > <version>${cas.version}</version> > <type>war</type> > <scope>runtime</scope> > </dependency> > <dependency> > <groupId>org.apereo.cas</groupId> > <artifactId>cas-server-support-ldap</artifactId> > <version>${cas.version}</version> > </dependency> > <dependency> > <groupId>org.ldaptive</groupId> > <artifactId>ldaptive-unboundid</artifactId> > <version>1.0</version> > </dependency> > </dependencies> > > <properties> > <cas.version>5.1.0</cas.version> > <springboot.version>1.5.3.RELEASE</springboot.version> > <maven.compiler.source>1.8</maven.compiler.source> > <maven.compiler.target>1.8</maven.compiler.target> > <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> > </properties> > > <repositories> > <repository> > <id>sonatype-releases</id> > <url>http://oss.sonatype.org/content/repositories/releases/ > </url> > <snapshots> > <enabled>false</enabled> > </snapshots> > <releases> > <enabled>true</enabled> > </releases> > </repository> > <repository> > <id>sonatype-snapshots</id> > <url>https://oss.sonatype.org/content/repositories/snapshots/ > </url> > <snapshots> > <enabled>true</enabled> > </snapshots> > <releases> > <enabled>false</enabled> > </releases> > </repository> > <repository> > <id>shibboleth-releases</id> > <url> > https://build.shibboleth.net/nexus/content/repositories/releases</url> > </repository> > <repository> > <id>spring-milestones</id> > <url>https://repo.spring.io/milestone</url> > </repository> > </repositories> > > <profiles> > <profile> > <activation> > <activeByDefault>false</activeByDefault> > </activation> > <id>pgp</id> > <build> > <plugins> > <plugin> > <groupId>com.github.s4u.plugins</groupId> > <artifactId>pgpverify-maven-plugin</artifactId> > <version>1.1.0</version> > <executions> > <execution> > <goals> > <goal>check</goal> > </goals> > </execution> > </executions> > <configuration> > <pgpKeyServer>hkp://pool.sks-keyservers.net > </pgpKeyServer> > > <pgpKeysCachePath>${settings.localRepository}/pgpkeys-cache</pgpKeysCachePath> > <scope>test</scope> > <verifyPomFiles>true</verifyPomFiles> > <failNoSignature>false</failNoSignature> > </configuration> > </plugin> > </plugins> > </build> > </profile> > </profiles> > </project> > ----------END pom.xml----------- > > -- > - CAS gitter chatroom: https://gitter.im/apereo/cas > - CAS mailing list guidelines: > https://apereo.github.io/cas/Mailing-Lists.html > - CAS documentation website: https://apereo.github.io/cas > - CAS project website: https://github.com/apereo/cas > --- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:>. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org > > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org?utm_medium=email&utm_source=footer> > . > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/631812e1-a712-4370-8e15-1217ba91cdef%40googlegroups.com.
