We have very similar needs (minus Open ID) here at Virginia Tech, and
we use CAS as the authentication provider for Shib,
http://www.ja-sig.org/wiki/display/CASUM/Shibboleth-CAS+Integration.
This way you can use CAS for internal SSO needs and Shib for external
SSO.  Although the two SSO domains are not unified in this integration
strategy, for us that's a benefit rather than a liability.

I don't see any need for CASShib in anything you wrote.  If you want
to go that route, you're in much less supported territory as far as I
can tell.

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to