[cas-user] Install Cas 5.2.1 Support SAMLv2 Hostname cannot be null or empty

2018-01-30 Thread Bergner, Arnold
Hi, do you have cas.server.prefix and cas.server.name? https://apereo.github.io/cas/5.2.x/installation/Configuration-Properties.html#cas-server Arnold Von: cas-user@apereo.org [mailto:cas-user@apereo.org] Im Auftrag von jabang konate Gesendet: Mittwoch, 31. Januar 2018 07:45 An:

Re: [cas-user] Install Cas 5.2.1 Support SAMLv2 Hostname cannot be null or empty

2018-01-30 Thread jabang konate
hi. any advice for this problem? On Sat, Jan 27, 2018 at 5:03 PM, jabang konate wrote: > hi all. > > im trying to configure cas 5.2.1 to act as ane identity provider. i have > follow this site to configure samlv2. >

[cas-user] Re: Custom Authentication Handler

2018-01-30 Thread Ramakrishna G
Ignore previous mail. I need to write a for Custom Authentication Handler for CAS which takes userId, password and pancard number. All 3 parameters will be sent to custom server(My other server, Not in CAS) and validated and response is returned back. How can I achieve this is CAS overlay?

[cas-user] Custom Authentication Handler

2018-01-30 Thread Ramakrishna G
Hi Team, I need to write a for CAS which takes userId, password and pancard number. All 3 parameters will be sent to custom server(My other server, Not in CAS) and validated and response is returned back. How can I achieve this is CAS overlay? Thanks Ramakrishna G -- - Website:

Re: [cas-user] Blackboard Ultra

2018-01-30 Thread Bryan Wooten
"I certainly hope that Bb is not sending a logout request to CAS when 'its' session expires (not user initiated). That would single logout the user out of all services (that participate in SLO) regardless of CAS settings ==> unhappy users & confused administrators." This topic begs the question:

Re: [cas-user] Blackboard Ultra

2018-01-30 Thread Richard Frovarp
I think that they are. From my recollection that was what came up on the Bb admin list a couple of years ago. You have to specify a logout URL, and it sends the user to it after it kills its own session. People are providing the IdP logout URL, so that kicks it off. My suggestion would be to

Re: [cas-user] Blackboard Ultra

2018-01-30 Thread Ray Bon
I certainly hope that Bb is not sending a logout request to CAS when 'its' session expires (not user initiated). That would single logout the user out of all services (that participate in SLO) regardless of CAS settings ==> unhappy users & confused administrators. Ray On Tue, 2018-01-30 at

Re: [cas-user] Blackboard Ultra

2018-01-30 Thread Ray Bon
Michael, Default lifetime of a TGT is 2h. See https://apereo.github.io/cas/5.2.x/installation/Configuring-Ticket-Expiration-Policy.html The TGT may still be present in the ticket store, depends on the storage mechanism. Ray On Tue, 2018-01-30 at 13:08 +, Michael O Holstein wrote: We

Re: [cas-user] Cas - Unauthorized

2018-01-30 Thread Ray Bon
Ramakrishna, Perhaps there is something not right with your client application config? Is it running on https://192.168.111.118:8443 or is that CAS? Multiple service tickets in the URL suggests that the request is being redirected to CAS multiple times. Ray On Fri, 2018-01-26 at 16:49 +0530,

Re: [cas-user] Blackboard Ultra

2018-01-30 Thread Richard Frovarp
Do you have a logout URL configured? Best I know is that when a session expires in Bb, it kills the Bb session, then sends the browser to the IdP logout URL, which would kill your TGT. On 01/30/2018 07:08 AM, Michael O Holstein wrote: We recently moved onto Blackboard's SaaS offering (aka

Re: [cas-user] Cas - Unauthorized

2018-01-30 Thread David Hawes
It looks like you're using a serviceValidate endpoint with SAML validation. Comment out the CASValidateSAML lines and try again. Alternatively, keep the setting on and use a samlValidate endpoint. On Fri, Jan 26, 2018 at 6:19 AM, Ramakrishna G wrote: > Hi , > > Now I think I

[cas-user] Re: CAS documentation for a new user is terrible

2018-01-30 Thread Martin Bohun
“And so, my fellow cas-user-s: ask not what your cas can do for you—ask what you can do for your cas.” martin On Tuesday, October 31, 2017 at 12:50:43 AM UTC+11, Jan wrote: > > Hello, > > As a new user of CAS, I'd like to voice my opinion that the official > documentation of how one can get

Re: [cas-user] Re: CAS documentation for a new user is terrible

2018-01-30 Thread David Curry
Yesterday, I said: "...in addition to Carl's task list (for lack of a better word)..." My mistake, it was Jan's task list; I didn't scroll back far enough in the thread. --Dave -- DAVID A. CURRY, CISSP *DIRECTOR OF INFORMATION SECURITY* INFORMATION TECHNOLOGY 71 FIFTH AVE., 9TH FL., NEW

Re: [cas-user] Re: CAS documentation for a new user is terrible

2018-01-30 Thread Waldbieser, Carl
While it is true that CAS is not a turnkey solution, and it is also true that the documentation has vastly improved since the early days of CAS, I think it is fair to say there is room for improvement in the CAS documentation. The criticism that the documentation is somewhat lacking in terms

[cas-user] Blackboard Ultra

2018-01-30 Thread Michael O Holstein
We recently moved onto Blackboard's SaaS offering (aka "Ultra") and random users are telling us it times out of them. While I suspect this is an issue of opening the app, letting it sit for 2 hours, and then noticing their session went away (which should re-auth as the TGT is still valid on our

Re: [cas-user] Problem integrating CAS 5.2.0 with ORCID and FACEBOOK.

2018-01-30 Thread Neha Gupta
Hello Jérôme, Thanks a lot for update. I tried making changes in the file you suggested but always not able to access CAS login page after that as CAS is throwing some error. Traces(CASTraces.txt) attached. Request you to please help me on this. Also when i tried to package the complete pac4j

Re: [cas-user] Cas - Unauthorized

2018-01-30 Thread Ramakrishna G
Hi David, As suggested I enabled Debug Mode. Error what I got to.. [Thu Jan 25 17:53:01.512443 2018] [ssl:info] [pid 28180] SSL Library Error: error:1407609C:SSL routines:SSL23_GET_CLIENT_HELLO:http request -- speaking HTTP to HTTPS port!? [Thu Jan 25 17:53:01.940036 2018] [ssl:info] [pid

[cas-user] CAS 5.2.1 Inspeckr jdbc mysql database not being populated.

2018-01-30 Thread 'Mallory, Erik' via CAS Community
Inspektr or jdbc does not seem to be working properly. The database tables are not getting created on start, so there is nothing for Inspektr to write to. The error: PreparedStatementCallback; bad SQL grammar [SELECT AUD_DATE FROM COM_AUDIT_TRAIL WHERE AUD_CLIENT_IP = ? AND AUD_USER = ? AND

[cas-user] CAS 5.2.1 Inspeckr jdbc mysql database not being populated.

2018-01-30 Thread 'Mallory, Erik' via CAS Community
Hello, Inspektr or jdbc does not seem to be working properly. The database tables are not getting created on start, so there is nothing for Inspektr to write to. The error: PreparedStatementCallback; bad SQL grammar [SELECT AUD_DATE FROM COM_AUDIT_TRAIL WHERE AUD_CLIENT_IP = ? AND AUD_USER = ?

[cas-user] CAS 5.2.1 Inspeckr jdbc mysql database not being populated.

2018-01-30 Thread 'Mallory, Erik' via CAS Community
Hello, Inspektr or jdbc does not seem to be working properly. The database tables are not getting created on start, so there is nothing for Inspektr to write to. The error: PreparedStatementCallback; bad SQL grammar [SELECT AUD_DATE FROM COM_AUDIT_TRAIL WHERE AUD_CLIENT_IP = ? AND AUD_USER = ?

Re: [cas-user] Cas - Unauthorized

2018-01-30 Thread Ramakrishna G
Hi , Now I think I resolved certificate issue. But I am getting this error [Fri Jan 26 16:22:24.270308 2018] [authz_core:debug] [pid 19878] mod_authz_core.c(809): [client 192.168.111.118:62974] AH01626: authorization result of Require valid-user : denied (no authenticated user yet) [Fri Jan 26

[cas-user] CAS 5.2.1 Inspecktr jdbc mysql database not being populated.

2018-01-30 Thread Erik Mallory
Hello, Inspektr or jdbc does not seem to be working properly. The database tables are not getting created on start, so there is nothing for Inspektr to write to. The error: PreparedStatementCallback; bad SQL grammar [SELECT AUD_DATE FROM COM_AUDIT_TRAIL WHERE AUD_CLIENT_IP = ? AND