> Should I file a bug in JIRA on this ?

I agree this behavior is unhelpful, but all evidence suggests it's an
edge case configuration that would even allow access to /logout over
http.  We strongly recommend deploying CAS on SSL.  If anything I
would favor adding a security constraint to the default web.xml to
require a secure connection and add a comment to that effect so that
deployers have to work against best practice to experience this
behavior.

Other opinions on how to address this?

M

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to