Here is one way to do it. It's not the only way, since CAS gives you so
many options, but it should be enough to get you started.
1. Set these to enable the dashboard (these settings enable all of the
endpoints; you can also pick and choose):
cas.adminPagesSecurity.actuatorEndpointsEnabled: true
cas.monitor.endpoints.enabled: true
endpoints.enabled: true
2. Set this to a regular expression that matches the IP address(es) you
want to allow access from:
cas.adminPagesSecurity.ip:
^192\\.168\\.(50\\.[0-9]{1,3}|1\\.[12]0)$
(This example matches 192.168.50.*, 192.168.1.10, and 192.168.1.20; the
intention is that the first pattern is the "IT subnet" where the
administrators live, and the other two IPs are the internal IPs of the load
balancers, which will be using the /status endpoint to check that the
server is up and running.)
3. Set these to enable CAS authentication (as opposed to Spring Security)
authentication:
cas.monitor.endpoints.sensitive: false
endpoints.sensitive: false
The CAS documentation explains other alternatives, if you want to use
Spring Security instead of CAS.
4. Configure CAS to perform the authentication:
cas.adminPagesSecurity.loginUrl: ${cas.server.prefix}/login
cas.adminPagesSecurity.service:
${cas.server.prefix}/status/dashboard
cas.adminPagesSecurity.users:
file:/etc/cas/config/admusers.properties
cas.adminPagesSecurity.adminRoles[0]: ROLE_ADMIN
5. Create an admusers.properties file (use whatever name you gave it in the
property above). List one user per line and give them whatever role you
defined above. This files does NOT create new users, it just lists the
usernames (which exist in LDAP or AD or whatever) who can access the
dashboard. Their password is whatever they use when authenticating to the
CAS server. In this case, it's a user named "gnarls":
# This file lists the users who are allowed access to the CAS /status/*
# endpoints ("adminpages").
#
# The syntax for each line is:
#
# username=password,grantedAuthority[,grantedAuthority][,enabled|disabled]
#
gnarls=passwordnotused,ROLE_ADMIN
6. Create a service registry entry for the dashboard (in
/etc/cas/services/CASAdminDashboard-123456789.json or wherever):
{
"@class" : "org.apereo.cas.services.RegexRegisteredService",
"serviceId" : "^
https://casserver.your.dom.ain/cas/status/dashboard(\\z|/.*)",
"name" : "CAS Admin Dashboard",
"id" : 123456789,
"description" : "CAS dashboard and administrative endpoints",
"evaluationOrder" : 5000
}
Restart the server, point your web browser at
https://casserver.your.dom.ain/cas/staus/dashboard, and log in as the
user(s) you listed in the admusers.properties file.
For a more detailed description (same steps, but more explanation behind
them), see
https://dacurry-tns.github.io/deploying-apereo-cas/building_server_dashboard_overview.html
.
--Dave
--
DAVID A. CURRY, CISSP
*DIRECTOR OF INFORMATION SECURITY*
INFORMATION TECHNOLOGY
71 FIFTH AVE., 9TH FL., NEW YORK, NY 10003
+1 212 229-5300 x4728 • [email protected]
[image: The New School]
On Mon, Dec 18, 2017 at 4:44 PM, Tim Tyler <[email protected]> wrote:
> I am running CAS 5.2 and have configured ldap for authentication. But I
> still have not figured out how to access the admin or management page.
> What do I need to configure to login to the management page?
>
> Do I need to define an admin account? Do I need to define the Admin
> Status Endpoints per https://apereo.github.io/cas/5.0.x/installation/
> Configuration-Properties.html ?
>
>
>
> Do I need to create an adminusers.properties file? Can I define an
> existing ldap user as an admin to access the management page(s)?
>
>
>
>
>
>
>
> Tim Tyler
>
> Network Engineer
>
> Beloit College
>
>
>
> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> To view this discussion on the web visit https://groups.google.com/a/
> apereo.org/d/msgid/cas-user/357545e0243806517d1dac6eed8c06
> ee%40mail.gmail.com
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/357545e0243806517d1dac6eed8c06ee%40mail.gmail.com?utm_medium=email&utm_source=footer>
> .
>
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CA%2Bd9XAON5qRK1A8U-3vgufMYby%2BOMQi_VsknpScpF2zbSHsqEQ%40mail.gmail.com.