> I'm trying to debug something and would like to use a non-SSL proxy callback 
> URL.  Where is the setting to allow CAS to do this?

HttpBasedServiceCredentialsAuthenticationHandler#requireSecure

WARNING!  DANGER WILL ROBINSON!  Setting requireSecure=false removes
all forms of authentication of the proxy requester other than perhaps
the service registry "allowProxy" setting.  Granting proxy capability
is tantamount to delegated authentication, which is a power to be
wielded wisely.  You should be authenticating your proxies via some
means.

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to