On Tue, 24 Apr 2012 16:12:14 -0400
"Smith, Matthew J." <[email protected]> wrote:

> Jérôme,

Hello, 

> Just to make sure I understand -- if you use PHPCAS, without using
> mod_auth_cas, you experience the same redirect loop? 

Yes. I've made two different tests for the non-reverse proxied CAS
server : 

* One with mod_auth_cas in Apache, alone, just in a <Location>
  statement; 
* One with PHPCAS, a simple example PHP script already in the tarball. 

Both expose loop redirection between the CASified URI service and the
CAS server URI after the authentication phase. 

> Is the
> application using PHPCAS being accessed over HTTPS ?

No, but I've created a service id for http://** wildcard URIs and the
CAS server do the authentication for the service on HTTP and
redirect to the service URI, the CASified URI then redirect me to
the CAS server URI and so on. 

I can test with HTTPS everywhere but since the authentication phase
go well, I'm not sure it will make my pb go away. 

> 
> The configuration directives for mod_auth_cas are all in the README,
> accessible here: https://github.com/jasig/mod_auth_cas

My complain is about the CAS server and its lack of documentation, not
the apache CAS module :p 

> 
> Using mod_auth_cas, can you add both "CASDebug On" and "LogLevel
> DEBUG" to your Apache config, and send us the debug logs?
> 

Will do. 

Thks for your help. 

-- 
Jérôme Benoit aka fraggle
La Météo du Net - http://grenouille.com
OpenPGP Key ID : 9FE9161D
Key fingerprint : 9CA4 0249 AF57 A35B 34B3 AC15 FAA0 CB50 9FE9 161D

Attachment: signature.asc
Description: PGP signature

Reply via email to