Carl,

Are you referring to surrogate authentication?
https://apereo.github.io/cas/6.4.x/authentication/Surrogate-Authentication.html

Ray

On Wed, 2022-05-18 at 16:23 -0400, Carl Waldbieser wrote:
Notice: This message was sent from outside the University of Victoria email 
system. Please be cautious with links and sensitive information.

If I have an entry and an alias in an OpenLDAP DIT such that searching on 
"alias" dereferences "entry", is it possible to configure CAS to perform a 2 
stage BIND in this way?

I.e.


  1.  User enters "alias" and password at the CAS login form.
  2.  CAS searches the DIT with LDAP base "uid=alias,ou=aliases,o=myorg" and a 
filter like "(objectClass=*)".
  3.  The actual entry dereferenced has DN 
"uid=entry,ou=somedepartment,o=myorg".
  4.  CAS attempts a BIND against this DN with the provided password.

It's not obvious from the documentation how one might configure that, or even 
if it is possible.

Thanks,
Carl Waldbieser


--

Ray Bon
Programmer Analyst
Development Services, University Systems
2507218831 | CLE 019 | [email protected]<mailto:[email protected]>

I acknowledge and respect the lək̓ʷəŋən peoples on whose traditional territory 
the university stands, and the Songhees, Esquimalt and WSÁNEĆ peoples whose 
historical relationships with the land continue to this day.

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/868a2f900c274818b9e38f466497d550f92d75a7.camel%40uvic.ca.

Reply via email to