Thanks Iain. I have this working now for only filtering with IP addresses. For those interested, I have the following in my cas.properties file: ----BEGIN snippet from cas.properties---- ... cas.monitor.endpoints.enabled=true cas.monitor.endpoints.sensitive=false cas.adminPagesSecurity.ip=10\.11\.12\.13\|14\.15\.16\.17 ----END----
However, to pick up on Julien's issue, I am not able to get this working if I further restrict this to users logged in who are specified as authorized users in my adminusers.properties file. Here is what I have: ----BEGIN snippet from cas.properties---- ... cas.monitor.endpoints.enabled=true cas.monitor.endpoints.sensitive=false cas.adminPagesSecurity.ip=10\.11\.12\.13\|14\.15\.16\.17 cas.adminPagesSecurity.loginUrl=https://my.test.cas.server/cas/login cas.adminPagesSecurity.service=https://my.test.cas.server/cas/status/dashboard cas.adminPagesSecurity.users=file:/etc/cas/config/adminusers.properties cas.adminPagesSecurity.adminRoles[0]=ROLE_ADMIN cas.adminPagesSecurity.actuatorEndpointsEnabled=true cas.serviceRegistry.watcherEnabled=true cas.serviceRegistry.initFromJson=true ----END---- And here are the contents of my adminusers.properties file (for now, I only have my username listed): ----BEGIN adminusers.properties---- user=crdaudt,ROLE_ADMIN ----END---- My results are as follows: --When I visit https://my.test.cas.server/cas/status/dashboard, I am redirected to login. --When I log in, my logs show the following: ----BEGIN log snippet---- > 2017-06-28 11:42:01,961 INFO [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN ============================================================= WHO: crdaudt WHAT: TGT-**********************************************kloPuBba1M-my.test.cas.server ACTION: TICKET_GRANTING_TICKET_CREATED APPLICATION: CAS WHEN: Wed Jun 28 11:42:01 EDT 2017 CLIENT IP ADDRESS: 10.11.12.13 SERVER IP ADDRESS: 10.10.10.100 ============================================================= > 2017-06-28 11:42:02,001 INFO [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN ============================================================= WHO: crdaudt WHAT: ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server for https://my.test.cas.server/cas/status/dashboard ACTION: SERVICE_TICKET_CREATED APPLICATION: CAS WHEN: Wed Jun 28 11:42:02 EDT 2017 CLIENT IP ADDRESS: 10.11.12.13 SERVER IP ADDRESS: 10.10.10.100 ============================================================= > 2017-06-28 11:42:02,206 INFO [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN ============================================================= WHO: crdaudt WHAT: ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server ACTION: SERVICE_TICKET_VALIDATED APPLICATION: CAS WHEN: Wed Jun 28 11:42:02 EDT 2017 CLIENT IP ADDRESS: 10.11.12.13 SERVER IP ADDRESS: 10.10.10.100 ============================================================= ----END---- I am then redirected to https://my.test.cas.server/cas/status/dashboard?ticket=ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server, and informed that: "YOU ARE NOT AUTHORIZED TO BE AUTHORIZED!". Any suggestions? On Tuesday, June 27, 2017 at 2:19:58 PM UTC-4, Iain Workman wrote: > > The cas.adminPagesSecurity.ip setting is interpreted as a regex which the > sending ip of the request is matched against. If you can form a regex which > will match only the required ips that will work. > > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/e315e2f4-4290-46d9-8680-29b7f5f62e10%40apereo.org.
