Bonjour Julien, j'aurais quelques questions à vous poser au sujet de la version 5.1. Auriez vous qq minutes à m'accorder ? ( par téléphone ) Merci beaucoup
Cordialement Le mardi 27 juin 2017 17:05:38 UTC+2, Julien Whizz a écrit : > > It doesn't work for me. > > I'm using maven release 5.1.1 > - LDAP login on CAS (https://myserver:8443*/cas/login* : > *AUTHENTICATION_SUCCESS* > - Acces to the */status* or /status/dashboard : "*YOU DID NOT SAY THE > MAGIC WORD!.....*" > > And i've only this on my cas.log : > > > > > > > > > *2017-06-27 16:43:06,813 DEBUG > [org.apereo.cas.util.cipher.BaseStringCipherExecutor] - <Decrypting > value...>2017-06-27 16:43:06,814 DEBUG > [org.apereo.cas.web.support.DefaultCasCookieValueManager] - <Decoded cookie > value is > [TGT-**********************************************[email protected]@Mozilla/5.0 > > (Windows NT 6.1; WOW64; Trident/7.0; rv:11.0) like Gecko]>2017-06-27 > 16:43:06,814 DEBUG > [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - > <Creating new transaction with name > [org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]: > > PROPAGATION_REQUIRED,ISOLATION_DEFAULT; > 'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG > [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - > <Creating new transaction with name > [org.apereo.cas.ticket.registry.DefaultTicketRegistrySupport.getAuthenticatedPrincipalFrom]: > > PROPAGATION_REQUIRED,ISOLATION_DEFAULT; > 'ticketTransactionManager'>2017-06-27 16:43:06,814 DEBUG > [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - > <Initiating transaction commit>2017-06-27 16:43:06,814 DEBUG > [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - > <Resuming suspended transaction after completion of inner > transaction>2017-06-27 16:43:06,815 DEBUG > [org.apereo.cas.authentication.PseudoPlatformTransactionManager] - > <Initiating transaction commit>*Here my *cas.properties* > > cas.server.name=https://server.domain.prive.fr:8443 cas.server.prefix= >> https://server.domain.prive.fr:8443/cas logging.config: >> file:/etc/cas/config/log4j2.xml #======================================== >> # Authentication #======================================== >> cas.authn.accept.users= #======================================== ## >> Embedded Tomcat HTTP/AJP ## Enable HTTP/AJP connections for the embedded >> Tomcat container. #======================================== >> cas.server.http.enabled=false #======================================== >> # LDAP : #======================================== cas.authn.ldap[0].type >> =AUTHENTICATED cas.authn.ldap[0].ldapUrl=ldap://domain.prive.fr >> cas.authn.ldap[0].useSsl=false >> cas.authn.ldap[0].baseDn=dc=domain,dc=prive,dc=fr >> cas.authn.ldap[0].userFilter=sAMAccountName={user} >> cas.authn.ldap[0].bindDn=CN=BIND >> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr >> cas.authn.ldap[0].bindCredential=password >> cas.authn.attributeRepository.ldap.ldapUrl=Ldap://domain.prive.fr >> cas.authn.attributeRepository.ldap.minPoolSize=3 >> cas.authn.attributeRepository.ldap.maxPoolSize=10 >> cas.authn.attributeRepository.ldap.validateOnCheckout=false >> cas.authn.attributeRepository.ldap.validatePeriodically=true >> cas.acceptableUsagePolicy.ldap.ldapUrl=Ldap://domain.prive.fr >> cas.acceptableUsagePolicy.ldap.baseDn=dc=domain,dc=prive,dc=fr >> cas.acceptableUsagePolicy.ldap.userFilter=sAMAccountName={user} >> cas.acceptableUsagePolicy.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider >> >> cas.acceptableUsagePolicy.ldap.connectTimeout=5000 >> cas.acceptableUsagePolicy.ldap.minPoolSize=3 >> cas.acceptableUsagePolicy.ldap.maxPoolSize=10 >> cas.acceptableUsagePolicy.ldap.validateOnCheckout=true >> cas.acceptableUsagePolicy.ldap.validatePeriodically=true >> cas.acceptableUsagePolicy.ldap.validatePeriod=600 >> cas.acceptableUsagePolicy.ldap.idleTime=500 >> cas.acceptableUsagePolicy.ldap.prunePeriod=600 >> cas.acceptableUsagePolicy.ldap.blockWaitTime=5000 >> cas.acceptableUsagePolicy.ldap.useStartTls=false >> cas.serviceRegistry.ldap.idAttribute=sAMAccountName >> cas.serviceRegistry.ldap.ldapUrl=Ldap://domain.prive.fr >> cas.serviceRegistry.ldap.baseDn=dc=domain,dc=prive,dc=fr >> cas.serviceRegistry.ldap.bindDn=CN=BIND >> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr >> cas.serviceRegistry.ldap.bindCredential=password >> cas.serviceRegistry.ldap.useSsl=false cas.mgmt.ldapAuthz.rolePrefix=ROLE_ >> cas.mgmt.ldapAuthz.searchFilter=cn={user} >> cas.mgmt.ldapAuthz.roleAttribute=uugid cas.mgmt.ldapAuthz.ldapUrl=Ldap:// >> domain.prive.fr cas.mgmt.ldapAuthz.baseDn=dc=domain,dc=prive,dc=fr >> cas.mgmt.ldapAuthz.userFilter=sAMAccountName={user} >> cas.mgmt.ldapAuthz.bindDn=CN=BIND >> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr >> cas.mgmt.ldapAuthz.bindCredential=password cas.mgmt.ldapAuthz.useSsl=false >> cas.adminPagesSecurity.ldap.type=AUTHENTICATED >> cas.adminPagesSecurity.ldap.ldapUrl=Ldap://domain.prive.fr >> cas.adminPagesSecurity.ldap.useSsl=false >> cas.adminPagesSecurity.ldap.baseDn=dc=domain,dc=prive,dc=fr >> cas.adminPagesSecurity.ldap.userFilter=sAMAccountName={user} >> cas.adminPagesSecurity.ldap.bindDn=CN=BIND >> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr >> cas.adminPagesSecurity.ldap.bindCredential=password >> cas.monitor.ldap.ldapUrl=Ldap://domain.prive.fr >> cas.monitor.ldap.baseDn=dc=domain,dc=prive,dc=fr >> cas.monitor.ldap.userFilter=sAMAccountName={user} cas.monitor.ldap.bindDn >> =CN=BIND >> Ldap,OU=Technique,OU=D.S.I.,OU=ADMINISTRATIFS,DC=domain,DC=prive,DC=fr >> cas.monitor.ldap.bindCredential=password >> cas.monitor.ldap.providerClass=org.ldaptive.provider.unboundid.UnboundIDProvider >> >> cas.monitor.ldap.useSsl=false #======================================== >> # Management Webapp #======================================== >> cas.mgmt.adminRoles=ROLE_ADMIN >> cas.mgmt.userPropertiesFile=file:/etc/cas/config/users.properties >> #======================================== # Admin Status Endpoints # The >> following properties describe access controls and settings for the /status >> endpoint of CAS which provides administrative functionality and oversight >> into the CAS software. To learn more about this topic, please review this >> guide. #======================================== >> cas.monitor.endpoints.enabled=true cas.monitor.endpoints.sensitive=false >> cas.monitor.endpoints.dashboard.enabled=true >> cas.monitor.endpoints.dashboard.sensitive=false >> cas.monitor.endpoints.status.enabled=true >> cas.monitor.endpoints.status.sensitive=false cas.adminPagesSecurity.users >> =file:/etc/cas/config/adminusers.properties >> cas.adminPagesSecurity.adminRoles=ROLE_ADMIN cas.adminPagesSecurity.ip= >> #======================================== >> # Service Registry #======================================== >> cas.serviceRegistry.watcherEnabled=true cas.serviceRegistry.initFromJson= >> true >> > > > > > > > Le lundi 26 juin 2017 22:29:21 UTC+2, crdaudt a écrit : >> >> I have set up a test instance of a CAS 5.1.0 server running under tomcat >> with a fairly minimal configuration. I would like to enable the /status >> from my workstation's IP address (or better yet, two or three ranges of IP >> addresses). I am not able to make sense of the documentation for how to >> accomplish this ( >> https://apereo.github.io/cas/5.1.x/installation/Monitoring-Statistics.html, >> >> https://apereo.github.io/cas/5.1.x/installation/Configuring-Monitoring.html, >> and >> https://apereo.github.io/cas/5.1.x/installation/Configuration-Properties.html). >> >> When I attempt to visit https://<CAS_URL>/cas/status, I am directed to an >> error pages that states "YOU DID NOT SAY THE MAGIC WORD!" and "We are >> sorry. You do not have permission to view this page". >> >> Here is what I have so far: >> ----------BEGIN cas.properties----------- >> cas.server.name: https://my.test.cas.server >> cas.server.prefix: https://my.test.cas.server/cas >> cas.host.name: my.test.cas.server >> logging.config: file:/etc/cas/config/log4j2.xml >> ###cas.authn.accept.users=casuser::Mellon >> cas.authn.accept.users= >> #ldap stuff: >> cas.authn.ldap[0].type=AUTHENTICATED >> cas.authn.ldap[0].ldapUrl=ldaps://my.ldap.server:636/ >> cas.authn.ldap[0].useSsl=true >> cas.authn.ldap[0].useStartTls=false >> >> cas.authn.ldap[0].trustCertificates=file:/etc/cas/certificates_to_trust/i_trust_this_ca.cer >> cas.authn.ldap[0].connectTimeout=5000 >> cas.authn.ldap[0].principalAttributeID=sAMAccountName >> >> cas.authn.ldap[0].principalAttributeList=sAMAccountName,displayName,mail,memberOf,description:UDC_IDENTIFIER >> cas.authn.ldap[0].baseDn=dc=xxx,dc=yyy,dc=edu >> cas.authn.ldap[0].bindDn=cn=ldap,cn=Users,dc=xxx,dc=yyy,dc=edu >> cas.authn.ldap[0].bindCredential=XXXXXXXXXX >> cas.authn.ldap[0].userFilter=sAMAccountName={user} >> cas.authn.ldap[0].subtreeSearch=true >> cas.authn.ldap[0].minPoolSize=3 >> cas.authn.ldap[0].maxPoolSize=10 >> cas.authn.ldap[0].validateOnCheckout=true >> cas.authn.ldap[0].validatePeriodically=true >> cas.authn.ldap[0].validatePeriod=600 >> cas.authn.ldap[0].failFast=true >> cas.authn.ldap[0].idleTime=500 >> cas.authn.ldap[0].prunePeriod=600 >> cas.authn.ldap[0].blockWaitTime=5000 >> ## attempting to grant /status privilege to the workstation with the >> following IP address >> cas.adminPagesSecurity.ip=10\.11\.12\.13 >> ----------END cas.properties----------- >> >> For deploying CAS with maven overlay, I used the following for pom.xml: >> >> ----------BEGIN pom.xml----------- >> <?xml version="1.0" encoding="UTF-8"?> >> <project xmlns="http://maven.apache.org/POM/4.0.0" >> xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" >> xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 >> http://maven.apache.org/xsd/maven-4.0.0.xsd "> >> <modelVersion>4.0.0</modelVersion> >> <groupId>org.apereo.cas</groupId> >> <artifactId>cas-overlay</artifactId> >> <packaging>war</packaging> >> <version>1.0</version> >> >> <build> >> <plugins> >> <plugin> >> <groupId>com.rimerosolutions.maven.plugins</groupId> >> <artifactId>wrapper-maven-plugin</artifactId> >> <version>0.0.4</version> >> <configuration> >> <verifyDownload>true</verifyDownload> >> <checksumAlgorithm>MD5</checksumAlgorithm> >> </configuration> >> </plugin> >> <plugin> >> <groupId>org.springframework.boot</groupId> >> <artifactId>spring-boot-maven-plugin</artifactId> >> <version>${springboot.version}</version> >> <configuration> >> >> <mainClass>org.springframework.boot.loader.WarLauncher</mainClass> >> <addResources>true</addResources> >> </configuration> >> </plugin> >> <plugin> >> <groupId>org.apache.maven.plugins</groupId> >> <artifactId>maven-war-plugin</artifactId> >> <version>2.6</version> >> <configuration> >> <warName>cas</warName> >> <failOnMissingWebXml>false</failOnMissingWebXml> >> <recompressZippedFiles>false</recompressZippedFiles> >> <archive> >> <compress>false</compress> >> >> <manifestFile>${project.build.directory}/war/work/org.apereo.cas/cas-server-webapp/META-INF/MANIFEST.MF >> </manifestFile> >> </archive> >> <overlays> >> <overlay> >> <groupId>org.apereo.cas</groupId> >> <artifactId>cas-server-webapp</artifactId> >> </overlay> >> </overlays> >> </configuration> >> </plugin> >> <plugin> >> <groupId>org.apache.maven.plugins</groupId> >> <artifactId>maven-compiler-plugin</artifactId> >> <version>3.3</version> >> </plugin> >> </plugins> >> <finalName>cas</finalName> >> </build> >> >> <dependencies> >> <dependency> >> <groupId>org.apereo.cas</groupId> >> <artifactId>cas-server-webapp</artifactId> >> <version>${cas.version}</version> >> <type>war</type> >> <scope>runtime</scope> >> </dependency> >> <dependency> >> <groupId>org.apereo.cas</groupId> >> <artifactId>cas-server-support-ldap</artifactId> >> <version>${cas.version}</version> >> </dependency> >> <dependency> >> <groupId>org.ldaptive</groupId> >> <artifactId>ldaptive-unboundid</artifactId> >> <version>1.0</version> >> </dependency> >> </dependencies> >> >> <properties> >> <cas.version>5.1.0</cas.version> >> <springboot.version>1.5.3.RELEASE</springboot.version> >> <maven.compiler.source>1.8</maven.compiler.source> >> <maven.compiler.target>1.8</maven.compiler.target> >> <project.build.sourceEncoding>UTF-8</project.build.sourceEncoding> >> </properties> >> >> <repositories> >> <repository> >> <id>sonatype-releases</id> >> <url>http://oss.sonatype.org/content/repositories/releases/ >> </url> >> <snapshots> >> <enabled>false</enabled> >> </snapshots> >> <releases> >> <enabled>true</enabled> >> </releases> >> </repository> >> <repository> >> <id>sonatype-snapshots</id> >> <url>https://oss.sonatype.org/content/repositories/snapshots/ >> </url> >> <snapshots> >> <enabled>true</enabled> >> </snapshots> >> <releases> >> <enabled>false</enabled> >> </releases> >> </repository> >> <repository> >> <id>shibboleth-releases</id> >> <url> >> https://build.shibboleth.net/nexus/content/repositories/releases</url> >> </repository> >> <repository> >> <id>spring-milestones</id> >> <url>https://repo.spring.io/milestone</url> >> </repository> >> </repositories> >> >> <profiles> >> <profile> >> <activation> >> <activeByDefault>false</activeByDefault> >> </activation> >> <id>pgp</id> >> <build> >> <plugins> >> <plugin> >> <groupId>com.github.s4u.plugins</groupId> >> <artifactId>pgpverify-maven-plugin</artifactId> >> <version>1.1.0</version> >> <executions> >> <execution> >> <goals> >> <goal>check</goal> >> </goals> >> </execution> >> </executions> >> <configuration> >> <pgpKeyServer>hkp://pool.sks-keyservers.net >> </pgpKeyServer> >> >> <pgpKeysCachePath>${settings.localRepository}/pgpkeys-cache</pgpKeysCachePath> >> <scope>test</scope> >> <verifyPomFiles>true</verifyPomFiles> >> <failNoSignature>false</failNoSignature> >> </configuration> >> </plugin> >> </plugins> >> </build> >> </profile> >> </profiles> >> </project> >> ----------END pom.xml----------- >> >> -- >> - CAS gitter chatroom: https://gitter.im/apereo/cas >> - CAS mailing list guidelines: >> https://apereo.github.io/cas/Mailing-Lists.html >> - CAS documentation website: https://apereo.github.io/cas >> - CAS project website: https://github.com/apereo/cas >> --- >> You received this message because you are subscribed to the Google Groups >> "CAS Community" group. >> To unsubscribe from this group and stop receiving emails from it, send an >> email to [email protected]. >> To view this discussion on the web visit >> https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org >> >> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/b694d5ab-6e73-42dc-a784-36bcdda42925%40apereo.org?utm_medium=email&utm_source=footer> >> . >> > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/c2895e2b-2f46-4c69-862f-ac3dba8dda50%40apereo.org.
