Thanks Iain.  I have this working now for only filtering with IP 
addresses.  For those interested, I have the following in my cas.properties 
file:
----BEGIN snippet from cas.properties----
...
cas.monitor.endpoints.enabled=true
cas.monitor.endpoints.sensitive=false
cas.adminPagesSecurity.ip=10\.11\.12\.13\|14\.15\.16\.17
----END----

However, to pick up on Julien's issue, I am not able to get this working if 
I further restrict this to users logged in who are specified as authorized 
users in my adminusers.properties file.
Here is what I have:
----BEGIN snippet from cas.properties----
...
cas.monitor.endpoints.enabled=true
cas.monitor.endpoints.sensitive=false
cas.adminPagesSecurity.ip=10\.11\.12\.13\|14\.15\.16\.17
cas.adminPagesSecurity.loginUrl=https://my.test.cas.server/cas/login
cas.adminPagesSecurity.service=https://my.test.cas.server/cas/status/dashboard
cas.adminPagesSecurity.users=file:/etc/cas/config/adminusers.properties
cas.adminPagesSecurity.adminRoles[0]=ROLE_ADMIN
cas.adminPagesSecurity.actuatorEndpointsEnabled=true
cas.serviceRegistry.watcherEnabled=true
cas.serviceRegistry.initFromJson=true
----END----

And here are the contents of my adminusers.properties file (for now, I only 
have my username listed):
----BEGIN adminusers.properties----
user=crdaudt,ROLE_ADMIN
----END----

My results are as follows:
--When I visit https://my.test.cas.server/cas/status/dashboard, I am 
redirected to login.
--When I log in, my logs show the following:

----BEGIN log snippet----
>
2017-06-28 11:42:01,961 INFO 
[org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN
=============================================================
WHO: crdaudt
WHAT: 
TGT-**********************************************kloPuBba1M-my.test.cas.server
ACTION: TICKET_GRANTING_TICKET_CREATED
APPLICATION: CAS
WHEN: Wed Jun 28 11:42:01 EDT 2017
CLIENT IP ADDRESS: 10.11.12.13
SERVER IP ADDRESS: 10.10.10.100
=============================================================

>
2017-06-28 11:42:02,001 INFO 
[org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN
=============================================================
WHO: crdaudt
WHAT: ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server for 
https://my.test.cas.server/cas/status/dashboard
ACTION: SERVICE_TICKET_CREATED
APPLICATION: CAS
WHEN: Wed Jun 28 11:42:02 EDT 2017
CLIENT IP ADDRESS: 10.11.12.13
SERVER IP ADDRESS: 10.10.10.100
=============================================================

>
2017-06-28 11:42:02,206 INFO 
[org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit 
trail record BEGIN
=============================================================
WHO: crdaudt
WHAT: ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server
ACTION: SERVICE_TICKET_VALIDATED
APPLICATION: CAS
WHEN: Wed Jun 28 11:42:02 EDT 2017
CLIENT IP ADDRESS: 10.11.12.13
SERVER IP ADDRESS: 10.10.10.100
=============================================================
----END----

I am then redirected to 
https://my.test.cas.server/cas/status/dashboard?ticket=ST-1-Fe5a6Ieo3IMaPI2FScWC-my.test.cas.server,
 
and informed that:  "YOU ARE NOT AUTHORIZED TO BE AUTHORIZED!".

Any suggestions?


On Tuesday, June 27, 2017 at 2:19:58 PM UTC-4, Iain Workman wrote:
>
> The cas.adminPagesSecurity.ip setting is interpreted as a regex which the 
> sending ip of the request is matched against. If you can form a regex which 
> will match only the required ips that will work.
>
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/e315e2f4-4290-46d9-8680-29b7f5f62e10%40apereo.org.

Reply via email to