Hi all,

Thanks for all your replies!

To Carl: 
Last time I check, using both cas.example.net and cas.special.example.net, 
one of them will not work (sso will be broken for that domain). We need to 
specified the cas.host.name=cas.example.net, hence cas.special.example.net 
will have no SSO capability. I will try it once more in 5.3.0-RC3 to see if 
this behavior is changed, but I still thinks that this behavior would not 
work.

To Misagh:
Thank you for your suggestion, I will do some research on "SSO 
Participation". I am Ok with doing a more customization configuration. If I 
come up with something workable I will post it here for future reference.

However, are there any plan for this kind of feature being added to CAS in 
future build? If so, I might try to build it more generic, so it might one 
day can fit into CAS main source code. Thanks!

Cheers!
- Andy

On Friday, 27 April 2018 02:23:49 UTC+8, Misagh Moayyed wrote:
>
> It's unlikely that you can build this correctly in CAS without pain 
> without accepting a few caveats that deal general session management. That 
> said, you want to start reviewing what is called "SSO Participation" 
> strategy components that basically decide how a service may opt in or out 
> of SSO, a trigger for which is renew=true for instance, etc. You need to 
> build one that looks into the TGT and queries its collection of services to 
> find if a session exists for that app.  It would do things based on the 
> presence or absence of that record. The outcome of the strategy determines 
> whether user should be challenged or else. You can try to build a strategy 
> that says: "If I have a record for BCD and no record of A, then 
> challenge...or not. If I dont have a record, then challenge, ... or not".
>
> --Misagh
>
> ------------------------------
>
>
>
>> On Wed, 2018-04-25 at 02:20 -0700, Andy Ng wrote:
>>
>> Hi all, 
>>
>> So I have done some research on this group and still doesn't find other 
>> with my use case, so I am asking for your help.
>>
>> Assume we have services A, B, C and D:
>>
>> B, C, D are normal SSO services, each one of them authenticate success, 
>> all BCD will login success.
>>
>> As for A, I want that even when BCD is authenticated, user still needs to 
>> authenticate once more before getting to A.
>>
>> At this point, theoretically all can be solved by* "renew=true"*. And 
>> the new *createSsoCookieOnRenewAuthn = false on 5.3.0* (
>> https://github.com/apereo/cas/blob/v5.3.0-RC3/api/cas-server-core-api-configuration-model/src/main/java/org/apereo/cas/configuration/model/core/sso/SsoProperties.java
>> )
>>
>> However, the tricky part is that, next time when user go back to service 
>> A , I want the user to no need to authenticate again.
>>
>> So it is basically like Service A is using another completely separated 
>> CAS server. Without actually using a separated CAS server (I don't want to 
>> make another server just for this).
>>
>> One more requirement would be to single logout all ABCD, but I know how 
>> to do that so no advice is needed there.
>>
>>
>> Any advice would be appreciated, Thanks!
>>
>> -Andy
>>
>>
>> -- 
>> Ray Bon
>> Programmer analyst
>> Development Services, University Systems
>> 2507218831 | CLE 019 | [email protected] <http://JAVASCRIPT-BLOCKED>
>>
>> -- 
> - Website: https://apereo.github.io/cas
> - Gitter Chatroom: https://gitter.im/apereo/cas
> - List Guidelines: https://goo.gl/1VRrw7
> - Contributions: https://goo.gl/mh7qDG
> --- 
> You received this message because you are subscribed to the Google Groups 
> "CAS Community" group.
> To unsubscribe from this group and stop receiving emails from it, send an 
> email to [email protected] <javascript:>.
> To view this discussion on the web visit 
> https://groups.google.com/a/apereo.org/d/msgid/cas-user/e4e8efc5-289b-4f1e-ab0f-dac399d7ec8a%40apereo.org
>  
> <https://groups.google.com/a/apereo.org/d/msgid/cas-user/e4e8efc5-289b-4f1e-ab0f-dac399d7ec8a%40apereo.org?utm_medium=email&utm_source=footer>
> .
>
>

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/55dc0c21-f1ee-4215-bea3-e3256f8006f7%40apereo.org.

Reply via email to