Thanks for tip, but that LDAP configuration is intended for looking up
legitimate surrogates as alternative to simple definition in cas.properties
I am using now.

Jozef

On Wed, Jul 12, 2017 at 10:51 AM, Ben Howell-Thomas <
[email protected]> wrote:

> I don't know for sure, but looking at SurrogateAuthenticationConfiguration
> and the properties documentation it looks like you need to specify the ldap
> configuration specifically for the surrogate lookup eg cas.authn.
> *surrogate*.ldap.ldapUrl.
>
> On 11 July 2017 at 23:45, Jozef Kotlar - EEA.sk <[email protected]>
> wrote:
>
>> Hello,
>>
>> I am investigating surrogate mechanism introduced in 5.1.0.
>> I seems that with static authentication this mechanism works as expected,
>> but when LDAP authentication is turned on, the
>> SurrogateAuthenticationAspect is not inspecting the authentication properly
>> (is not called anymore).
>>
>> Log from static authentication
>>
>> [org.apereo.cas.authentication.RegisteredServiceAuthenticationHandlerResolver]
>> - <Authentication handlers used for this transaction are
>> [HttpBasedServiceCredentialsAuthenticationHandlerAcceptUsers
>> AuthenticationHandler]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Transforming credential username
>> via [org.apereo.cas.configuration.support.Beans$$Lambda$72/703476267]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Attempting to encode credential
>> password via 
>> [org.springframework.security.crypto.password.NoOpPasswordEncoder]
>> for [casuser]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Attempting authentication
>> internally for transformed credential [casuser]>
>> [org.apereo.cas.authentication.*SurrogateAuthenticationAspect*] -
>> <Authenticated [casuser] will be checked for surrogate eligibility next...>
>> [org.apereo.cas.authentication.AbstractAuthenticationManager] -
>> <Authentication handler [AcceptUsersAuthenticationHandler] successfully
>> authenticated [[surrogateUsername=otheruser]]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Attempting to resolve a principal...>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Creating principal for [otheruser]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Retrieved [2] attribute(s) from the repository>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Found attribute [uid]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Found attribute [commonName]>
>> [org.apereo.cas.authentication.AbstractAuthenticationManager] -
>> <[org.apereo.cas.authentication.SurrogatePrincipalResolver@4
>> 951c83f[returnNullIfNoAttributes=false,principalAttributeName=<null>]]
>> resolved [otheruser] from [[surrogateUsername=otheruser]]>
>> [org.apereo.cas.authentication.AbstractAuthenticationManager] - <Final
>> principal resolved for this authentication event is [otheruser]>
>>
>>
>> Log from LDAP authentication
>>
>> [org.apereo.cas.authentication.RegisteredServiceAuthenticationHandlerResolver]
>> - <Authentication handlers used for this transaction are
>> [LdapAuthenticationHandlerHttpBasedServiceCredentialsAuthent
>> icationHandler]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Transforming credential username
>> via [org.apereo.cas.configuration.support.Beans$$Lambda$69/593438230]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Attempting to encode credential
>> password via 
>> [org.springframework.security.crypto.password.NoOpPasswordEncoder]
>> for [casuser]>
>> [org.apereo.cas.authentication.handler.support.AbstractUsern
>> amePasswordAuthenticationHandler] - <Attempting authentication
>> internally for transformed credential [casuser]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Attempting
>> LDAP authentication for [casuser]. Authenticator pre-configured attributes
>> are [null], additional requested attributes for this authentication request
>> are [[]]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <LDAP
>> response: [[org.ldaptive.auth.AuthenticationResponse@560783821::authen
>> ticationResultCode=AUTHENTICATION_HANDLER_SUCCESS,
>> resolvedDn=uid=casuser,ou=Users,dc=localdomain,
>> ldapEntry=[dn=uid=casuser,ou=Users,dc=localdomain[[uid[casuser]],
>> [sn[CAS User]], [cn[CAS User]], [objectClass[top, inetOrgPerson,
>> organizationalPerson, person]], [userPassword[e1NTSEF9YjdhTHpL
>> MEhHM2crT0pKWEZOVFJHL3hIQUkxbGRBK1Y=]]], responseControls=null,
>> messageId=-1], accountState=null, result=true, resultCode=SUCCESS,
>> message=null, controls=null]]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Applying
>> password policy to [[org.ldaptive.auth.AuthenticationResponse@560783821
>> ::authenticationResultCode=AUTHENTICATION_HANDLER_SUCCESS,
>> resolvedDn=uid=casuser,ou=Users,dc=localdomain,
>> ldapEntry=[dn=uid=casuser,ou=Users,dc=localdomain[[uid[casuser]],
>> [sn[CAS User]], [cn[CAS User]], [objectClass[top, inetOrgPerson,
>> organizationalPerson, person]], [userPassword[e1NTSEF9YjdhTHpL
>> MEhHM2crT0pKWEZOVFJHL3hIQUkxbGRBK1Y=]]], responseControls=null,
>> messageId=-1], accountState=null, result=true, resultCode=SUCCESS,
>> message=null, controls=null]]>
>> [org.apereo.cas.authentication.support.DefaultAccountStateHandler] -
>> <Account state not defined. Returning empty list of messages.>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <LDAP
>> response returned a result. Creating the final LDAP principal>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Creating
>> LDAP principal for [casuser] based on [uid=casuser,ou=Users,dc=localdomain]
>> and attributes [[uid, sn, cn, objectClass, userPassword]]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Principal
>> id attribute is not defined. Using the default provided user id [casuser]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Recording
>> principal DN attribute as [LdapAuthenticationHandler.casuser]>
>> [org.apereo.cas.authentication.LdapAuthenticationHandler] - <Created
>> LDAP principal for id [casuser] and [1] attributes>
>> [org.apereo.cas.authentication.AbstractAuthenticationManager] -
>> <Authentication handler [LdapAuthenticationHandler] successfully
>> authenticated [[surrogateUsername=otheruser]]>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Invoking principal resolver [org.apereo.cas.authentication
>> .SurrogatePrincipalResolver@5049b609[returnNullIfNoAttributes=false,
>> principalAttributeName=<null>]]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Attempting to resolve a principal...>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Creating principal for [casuser]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Retrieved [2] attribute(s) from the repository>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Found attribute [uid]>
>> [org.apereo.cas.authentication.principal.resolvers.PersonDirectoryPrincipalResolver]
>> - <Found attribute [commonName]>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Invoking principal resolver [org.apereo.cas.authentication
>> .principal.resolvers.EchoingPrincipalResolver@25924f08[]]>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Resolved principal [casuser]>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Adding attributes [{commonName=CAS User, uid=casuser}] for the final
>> principal>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Resolved principal [casuser]>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Adding attributes [{LdapAuthenticationHandler.ca
>> suser=uid=casuser,ou=Users,dc=localdomain}] for the final principal>
>> [org.apereo.cas.authentication.principal.resolvers.ChainingPrincipalResolver]
>> - <Final principal constructed by the chain of resolvers is [casuser]>
>>
>>
>> Used configuration is following
>>
>>
>> cas.authn.accept.users=
>>
>> cas.authn.ldap[0].type=AUTHENTICATED
>> cas.authn.ldap[0].ldapUrl=ldap://192.168.210.33:389
>> cas.authn.ldap[0].useSsl=false
>> cas.authn.ldap[0].baseDn=dc=localdomain
>> cas.authn.ldap[0].userFilter=uid={user}
>> cas.authn.ldap[0].subtreeSearch=true
>> cas.authn.ldap[0].bindDn=cn=admin,dc=localdomain
>> cas.authn.ldap[0].bindCredential=secret
>>
>> cas.authn.attributeRepository.ldap[0].attributes.uid=uid
>> cas.authn.attributeRepository.ldap[0].attributes.displayName=displayName
>> cas.authn.attributeRepository.ldap[0].attributes.cn=commonName
>> cas.authn.attributeRepository.ldap[0].attributes.affiliation
>> =groupMembership
>>
>> cas.authn.attributeRepository.ldap[0].ldapUrl=ldap://192.168.210.33:389
>> cas.authn.attributeRepository.ldap[0].useSsl=false
>> cas.authn.attributeRepository.ldap[0].baseDn=dc=localdomain
>> cas.authn.attributeRepository.ldap[0].userFilter=uid={user}
>> cas.authn.attributeRepository.ldap[0].subtreeSearch=true
>> cas.authn.attributeRepository.ldap[0].bindDn=cn=admin,dc=localdomain
>> cas.authn.attributeRepository.ldap[0].bindCredential=secret
>>
>> cas.authn.surrogate.simple.surrogates.casuser=otheruser
>>
>>
>> Am I missing something?
>>
>> Thanks,
>> Jozef
>>
>> --
>> - CAS gitter chatroom: https://gitter.im/apereo/cas
>> - CAS mailing list guidelines: https://apereo.github.io/cas/M
>> ailing-Lists.html
>> - CAS documentation website: https://apereo.github.io/cas
>> - CAS project website: https://github.com/apereo/cas
>> ---
>> You received this message because you are subscribed to the Google Groups
>> "CAS Community" group.
>> To unsubscribe from this group and stop receiving emails from it, send an
>> email to [email protected].
>> To view this discussion on the web visit https://groups.google.com/a/ap
>> ereo.org/d/msgid/cas-user/91ae56c6-25e0-430a-afee-4bcf962f3b
>> 3a%40apereo.org
>> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/91ae56c6-25e0-430a-afee-4bcf962f3b3a%40apereo.org?utm_medium=email&utm_source=footer>
>> .
>>
>
>
> This email is sent on behalf of Northgate Public Services (UK) Limited and
> its associated companies including Rave Technologies (India) Pvt Limited
> (together "Northgate Public Services") and is strictly confidential and
> intended solely for the addressee(s).
> If you are not the intended recipient of this email you must: (i) not
> disclose, copy or distribute its contents to any other person nor use its
> contents in any way or you may be acting unlawfully;  (ii) contact
> Northgate Public Services immediately on +44(0)1908 264500
> <+44%201908%20264500> quoting the name of the sender and the addressee
> then delete it from your system.
> Northgate Public Services has taken reasonable precautions to ensure that
> no viruses are contained in this email, but does not accept any
> responsibility once this email has been transmitted.  You should scan
> attachments (if any) for viruses.
>
> Northgate Public Services (UK) Limited, registered in England and Wales
> under number 00968498 with a registered address of Peoplebuilding 2,
> Peoplebuilding Estate, Maylands Avenue, Hemel Hempstead, Hertfordshire, HP2
> 4NN.  Rave Technologies (India) Pvt Limited, registered in India under
> number 117068 with a registered address of 2nd Floor, Ballard House, Adi
> Marzban Marg, Ballard Estate, Mumbai, Maharashtra, India, 400001.
>
> --
> - CAS gitter chatroom: https://gitter.im/apereo/cas
> - CAS mailing list guidelines: https://apereo.github.io/cas/
> Mailing-Lists.html
> - CAS documentation website: https://apereo.github.io/cas
> - CAS project website: https://github.com/apereo/cas
> ---
> You received this message because you are subscribed to a topic in the
> Google Groups "CAS Community" group.
> To unsubscribe from this topic, visit https://groups.google.com/a/
> apereo.org/d/topic/cas-user/k1ccrj8wp6Y/unsubscribe.
> To unsubscribe from this group and all its topics, send an email to
> [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/CAD0p8puQT13nDDK%2BCFu%3D0QO%
> 2BCc_o2DH219NEtyW069oFgj6P-Q%40mail.gmail.com
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAD0p8puQT13nDDK%2BCFu%3D0QO%2BCc_o2DH219NEtyW069oFgj6P-Q%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>

-- 
- CAS gitter chatroom: https://gitter.im/apereo/cas
- CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html
- CAS documentation website: https://apereo.github.io/cas
- CAS project website: https://github.com/apereo/cas
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CACKWwDhgMzAL3NAmC-gmQHwD4Gpbc%3DT11iMwm94SteT50kCcDQ%40mail.gmail.com.

Reply via email to