It's unlikely that you can build this correctly in CAS without pain without 
accepting a few caveats that deal general session management. That said, you 
want to start reviewing what is called "SSO Participation" strategy components 
that basically decide how a service may opt in or out of SSO, a trigger for 
which is renew=true for instance, etc. You need to build one that looks into 
the TGT and queries its collection of services to find if a session exists for 
that app. It would do things based on the presence or absence of that record. 
The outcome of the strategy determines whether user should be challenged or 
else. You can try to build a strategy that says: "If I have a record for BCD 
and no record of A, then challenge...or not. If I dont have a record, then 
challenge, ... or not". 

--Misagh 

>> On Wed, 2018-04-25 at 02:20 -0700, Andy Ng wrote:

>>> Hi all,

>>> So I have done some research on this group and still doesn't find other 
>>> with my
>>> use case, so I am asking for your help.

>>> Assume we have services A, B, C and D:

>>> B, C, D are normal SSO services, each one of them authenticate success, all 
>>> BCD
>>> will login success.

>>> As for A, I want that even when BCD is authenticated, user still needs to
>>> authenticate once more before getting to A.

>>> At this point, theoretically all can be solved by "renew=true" . And the new
>>> createSsoCookieOnRenewAuthn = false on 5.3.0 (
>>> https://github.com/apereo/cas/blob/v5.3.0-RC3/api/cas-server-core-api-configuration-model/src/main/java/org/apereo/cas/configuration/model/core/sso/SsoProperties.java
>>> )

>>> However, the tricky part is that, next time when user go back to service A 
>>> , I
>>> want the user to no need to authenticate again .

>>> So it is basically like Service A is using another completely separated CAS
>>> server. Without actually using a separated CAS server (I don't want to make
>>> another server just for this).

>>> One more requirement would be to single logout all ABCD, but I know how to 
>>> do
>>> that so no advice is needed there.

>>> Any advice would be appreciated, Thanks!

>>> -Andy

>> --
>> Ray Bon
>> Programmer analyst
>> Development Services, University Systems
>> 2507218831 | CLE 019 | [email protected]

> --
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> ---
> You received this message because you are subscribed to the Google Groups "CAS
> Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email
> to [email protected] .
> To view this discussion on the web visit
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/e4e8efc5-289b-4f1e-ab0f-dac399d7ec8a%40apereo.org
> .

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/882026322.20752303.1524767025786.JavaMail.zimbra%40unicon.net.

Reply via email to