Re: [cas-user] Duo Universal Prompt behind proxy

2023-03-08 Thread 'Richard Frovarp' via CAS Community
On 3/8/23 12:59, 'Richard Frovarp' via CAS Community wrote: On CAS 6.6.6 and using the Duo Universal Prompt, it is exposing my internal hostname, rather than the load balancer. It's not clear to me why this is happening. It is also not clear to me what the correct configuration options are for

Re: [cas-user] Duo Universal Prompt behind proxy

2023-03-08 Thread Pascal Rigaux
Hi, With spring-boot with embedded tomcat, I suggest the following in cas.properties: server.tomcat.remoteip.internal-proxies=... (a regexp) With external tomcat, I suggest configuring RemoteIpValve in conf/server.xml, eg: cu On 08/03/2023 19:59, 'Richard Frovarp' via CAS

[cas-user] Duo Universal Prompt behind proxy

2023-03-08 Thread 'Richard Frovarp' via CAS Community
On CAS 6.6.6 and using the Duo Universal Prompt, it is exposing my internal hostname, rather than the load balancer. It's not clear to me why this is happening. It is also not clear to me what the correct configuration options are for a load balanced CAS with respect to hostname / proxy

Re: [cas-user] Preventing removal of OAuth tokens upon TGT expiration for one service

2023-03-08 Thread Yan Zhou
Hi, We are using CAS 6.4.6.6, I still find this is the case, RT is removed (We like it to expire in 7 days), but it was removed after 8 hours, because the underlying TGT expired, which is default to 8 hours. i did not understand why Logout behavior would affect RT retention when TGT is

Re: [EXTERNAL SENDER] Re: [cas-user] requiredIpAddresses specification?

2023-03-08 Thread Baron Fujimoto
It does take CIDR, but sometimes for small address ranges, a regex is more concise and readable in the context than a series of appropriate CIDRs (and sometimes vice versa). However, bizarrely, it doesn't log any warnings for this variation, which makes no sense to me in terms of consistency.

RE: [EXTERNAL SENDER] Re: [cas-user] requiredIpAddresses specification?

2023-03-08 Thread King, Robert
Does it take CIDR? 10.17.133.2/31,10.17.133.4/32 From: cas-user@apereo.org On Behalf Of Baron Fujimoto Sent: Tuesday, March 7, 2023 10:14 PM To: CAS Community Subject: [EXTERNAL SENDER] Re: [cas-user] requiredIpAddresses specification? Actually, I've belatedly discovered I'm also seeing

[cas-user] Github as a generic OAuth20 IDP Token Parse Exception

2023-03-08 Thread Dominic Cohrs
Hi, I use the Github Identity Provider from CAS for Delegated Authentication and this works fine. Now i have a use case where i have to define multiple Github IDPs. So I started to define a generic OAuth20 IDP for Github in my cas.properties. cas.authn.pac4j.oauth2[0].enabled=true

Re: [cas-user] requiredIpAddresses specification?

2023-03-08 Thread Baron Fujimoto
Actually, I've belatedly discovered I'm also seeing warnings logged about being unable to parse regular expressions for IP addresses in 6.6.5, I'm setting something like the following: cas.monitor.endpoints.endpoint.defaults.required-ip-addresses=127.0.0.1, 10.17.133.[234], ... But the following

[cas-user] Re: CAS Initializr has v6.6.6 instead of v6.6.5

2023-03-08 Thread Jon Anderson
Thank you. I must say that it is confusing, but it was just a red hearing. Starting again from simple Initializr calls and working up, my problem appears to be about the dependencies. This worked for me on 6.6.4: -d dependencies=hazelcast,jsonsvc,pac4j,saml1,webapp (Although webapp deleted the

[cas-user] [OT] Job Posting

2023-03-08 Thread Francesco Chicchiriccò
Hi there! Sorry for OT, at Tirasa we are looking for two job profiles: 1. Principal IAM Engineer - https://www.tirasa.net/en/contacts/work-with-us#principal-iam 2. Junior IAM Developer - https://www.tirasa.net/en/contacts/work-with-us#junior-iam Background: Tirasa is an Italian company