We say that CAS should only be run over SSL so I don't know how much
support needs to be in for non-HTTPS scenarios.

That said, if it really is confusing, we can add a simple message to the
JSP page (like we do for the login page).


On Thu, Dec 8, 2011 at 2:41 PM, Marvin Addison <[email protected]>wrote:

> > Should I file a bug in JIRA on this ?
>
> I agree this behavior is unhelpful, but all evidence suggests it's an
> edge case configuration that would even allow access to /logout over
> http.  We strongly recommend deploying CAS on SSL.  If anything I
> would favor adding a security constraint to the default web.xml to
> require a secure connection and add a comment to that effect so that
> deployers have to work against best practice to experience this
> behavior.
>
> Other opinions on how to address this?
>
> M
>
> --
> You are currently subscribed to [email protected] as:
> [email protected]
> To unsubscribe, change settings or access archives, see
> http://www.ja-sig.org/wiki/display/JSG/cas-user
>

-- 
You are currently subscribed to [email protected] as: 
[email protected]
To unsubscribe, change settings or access archives, see 
http://www.ja-sig.org/wiki/display/JSG/cas-user

Reply via email to