[cas-user] CAS 5.1.6 cluster with ehcache hang

2018-02-22 Thread Duane Booher
Hi, we are running CAS 5.1.6 with a two host ehcache cluster. When we shutdown one of the two hosts, then the remaining host hangs and stops processing CAS login requests. Then when we start the down host back up, all of the CAS login requests work fine. Any ideas what might be going on here?

[cas-user] Re: CAS 5.1.6 TGT is destroyed early - but only during high volume

2018-01-22 Thread Duane Booher
org/forum/#!searchin/cas-user/LOCALTEMPSWAP/cas-user/sfiG6Aww9nk/AF7uKDLJFgAJ> I have also posted in CAS-DEV, the continuing saga once we ran over 15000 sessions. Duane On Thursday, January 18, 2018 at 11:22:21 AM UTC-7, Duane Booher wrote: > > Hi, we have been running a new production up

[cas-user] Re: CAS 5.1.6 TGT is destroyed early - but only during high volume

2018-01-19 Thread Duane Booher
that we should be concerned with and consider increasing? Duane On Thursday, January 18, 2018 at 11:22:21 AM UTC-7, Duane Booher wrote: > > Hi, we have been running a new production upgrade to CAS 5.1.6 for about a > week. Most things are working, however during our peak login times

[cas-user] Re: HELP: CAS 5.1.6 cas/status throws warning when sessions > 10000

2018-01-19 Thread Duane Booher
that we should be concerned with and consider increasing? Duane On Friday, January 19, 2018 at 9:54:42 AM UTC-7, Duane Booher wrote: > > Help, > > we have just increased ehcache from > default: cas.ticket.registry.ehcache.maxElementsInMemory=1 > to: maxElementsInMemory=15000

[cas-user] HELP: CAS 5.1.6 cas/status throws warning when sessions > 10000

2018-01-19 Thread Duane Booher
Help, we have just increased ehcache from default: cas.ticket.registry.ehcache.maxElementsInMemory=1 to: maxElementsInMemory=15000 due to ehcache ticket premature expirations, see my other post: CAS 5.1.6 TGT is destroyed early When our system goes above 1, then cas/status throws a

[cas-user] Re: CAS 5.1.6 TGT is destroyed early - but only during high volume

2018-01-19 Thread Duane Booher
UTC-7, Duane Booher wrote: > > Hi, we have been running a new production upgrade to CAS 5.1.6 for about a > week. Most things are working, however during our peak login times, our TGT > sessions do not last the expected default of two hours and require the user > to re-login early

[cas-user] CAS 5.1.6 TGT is destroyed early - but only during high volume

2018-01-18 Thread Duane Booher
Hi, we have been running a new production upgrade to CAS 5.1.6 for about a week. Most things are working, however during our peak login times, our TGT sessions do not last the expected default of two hours and require the user to re-login early. We have a two host cluster with ehcache enabled.

[cas-user] Re: Webflow error in CAS 5.1.4

2018-01-13 Thread Duane Booher
We also upgraded from CAS 4.x to in this case CAS 5.1.6, and have been getting a bunch of these errors: 2018-01-13 11:09:00,018 ERROR [org.springframework.boot.web.support.ErrorPageFilter] - _']> Some of the requesters are external ip, and some are internal. We contacted a couple of users and

[cas-user] ehcache issue on CAS 5.2.0-RC4

2017-11-21 Thread Duane Booher
/cas/development/installation/Ehcache-Ticket-Registry.html#configuration which does work on CAS 5.1.6. Duane Booher -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines: https://goo.gl/1VRrw7 - Contributions: https://goo.gl/mh7qDG

Re: [cas-user] Which CAS 5.x release are people running successfully in prod?

2017-11-16 Thread Duane Booher
gt; Ray > > On Thu, 2017-11-16 at 08:21 -0800, Duane Booher wrote: > > Hi, we have been trying to upgrade to CAS 5.x in our production > environment. We run successfully in our CAS-Test, but in our prod > environment we encounter various issues forcing us to revert back

[cas-user] Which CAS 5.x release are people running successfully in prod?

2017-11-16 Thread Duane Booher
Hi, we have been trying to upgrade to CAS 5.x in our production environment. We run successfully in our CAS-Test, but in our prod environment we encounter various issues forcing us to revert back to CAS 4. What CAS 5.x releases are people successfully running in production? Duane Booher

Re: [cas-user] CAS5 how large for tomcat maxHttpHeaderSize

2017-11-01 Thread Duane Booher
rview.html If people have not seen this, then they should definitely check it out!!! Duane Booher Northern Arizona University On Wednesday, November 1, 2017 at 5:20:44 AM UTC-7, David Curry wrote: > > > Tomcat's default value for maxPostSize is 2097152, so that's "normal."

[cas-user] CAS5 how large for tomcat maxHttpHeaderSize

2017-10-31 Thread Duane Booher
Hi, we were noticing server.tomcat.maxHttpHeaderSize=20971520 in https://apereo.github.io/cas/5.0.x/installation/Configuration-Properties.html#embedded-tomcat and server.tomcat.maxHttpPostSize=20971520 in

Re: [cas-user] CAS5 tgt ticket time out when session is inactive?

2017-10-27 Thread Duane Booher
Scratch my last comment. I did want the default behavior of the 2 hour sliding window with a max of 8 hours. Thanks On Thursday, October 26, 2017 at 3:56:59 PM UTC-7, Duane Booher wrote: > > Ray, I now have the behavior that I was hoping by using these se

Re: [cas-user] CAS5 tgt ticket time out when session is inactive?

2017-10-26 Thread Duane Booher
t.timeToKillInSeconds) will > provide a sliding window, adding 2 hours every time the TGC is used up to 8 > h. My config above sets a fixed timeout to 2 h unless user checks remember > me (setting enable to true will show a check box on the login page). > > Ray > > On T

Re: [cas-user] CAS5 tgt ticket time out when session is inactive?

2017-10-25 Thread Duane Booher
is in place). > After 2 hours the SSO session would expire; a user would be presented with > the login screen when accessing a different client service. > > Ray > > On Wed, 2017-10-25 at 11:48 -0700, Duane Booher wrote: > > Hello I'm running CAS5.0 with all of the tgt session

[cas-user] CAS5 tgt ticket time out when session is inactive?

2017-10-25 Thread Duane Booher
Hello I'm running CAS5.0 with all of the tgt session defaults. We are testing we are testing tgt timeout when a tgt session is inactive with no new activity. I was assuming that the default setting of cas.ticket.tgt.timeToKillInSeconds=7200 would kill the session, however it is going beyond 2

[cas-user] CAS5 /cas/status cas.adminPagesSecurity.ip

2017-10-25 Thread Duane Booher
For CAS 5.0 /cas/status access, the only way I can get access is with a single ip, such as cas.adminPagesSecurity.ip=127.0.0.1 My question, is there any additional pattern matching capabilities and/or a list of ip addresses? In CAS4 there use to be a subnet mask option, such as xx.xx.xx.xx/24,

[cas-user] Re: CAS Load Test Scripts

2017-10-18 Thread Duane Booher
ts/jmeter" directory in the CAS source repo, > https://github.com/apereo/cas. > > Hope that helps! > > Axel > > On Tuesday, October 17, 2017 at 2:33:14 PM UTC-7, Duane Booher wrote: >> >> Hi, does anyone have suggestions for a load test script tool? We have >&

[cas-user] CAS Load Test Scripts

2017-10-17 Thread Duane Booher
Hi, does anyone have suggestions for a load test script tool? We have plenty of CAS applications and want to put a load on our new CAS system before deployment. Thanks, Duane -- - Website: https://apereo.github.io/cas - Gitter Chatroom: https://gitter.im/apereo/cas - List Guidelines:

[cas-user] Re: CAS 5.0.5 password warning login?execution= too long for Windows IE/Edge browsers

2017-08-21 Thread Duane Booher
, 2017 at 2:42:54 PM UTC-7, Duane Booher wrote: > > We have cas.authn.ldap[0].passwordPolicy.warningDays=5 firing a password > change warning from casLoginMessageView.html > > When we press continue, then the URL fires with login?execution=... being > too long for the Window

[cas-user] Re: CAS 5.0.5 password warning login?execution= too long for Windows IE/Edge browsers

2017-08-21 Thread Duane Booher
browsers support the larger URL lengths except for both Windows IE and Edge which truncate url at 10k. On Friday, August 18, 2017 at 2:42:54 PM UTC-7, Duane Booher wrote: > > We have cas.authn.ldap[0].passwordPolicy.warningDays=5 firing a password > change warning from casLoginMessageView.html

[cas-user] Re: CAS 5.0.5 password warning login?execution= too long for Windows IE/Edge browsers

2017-08-18 Thread Duane Booher
:42:54 PM UTC-7, Duane Booher wrote: > > We have cas.authn.ldap[0].passwordPolicy.warningDays=5 firing a password > change warning from casLoginMessageView.html > > When we press continue, then the URL fires with login?execution=... being > too long for the Windows IE/Edge brows

[cas-user] CAS 5.0.5 password warning login?execution= too long for Windows IE/Edge browsers

2017-08-18 Thread Duane Booher
We have cas.authn.ldap[0].passwordPolicy.warningDays=5 firing a password change warning from casLoginMessageView.html When we press continue, then the URL fires with login?execution=... being too long for the Windows IE/Edge browsers. It works for all of the other host browsers, are there any

[cas-user] cas 5.0.6 proxy 505 error

2017-06-26 Thread Duane Booher
Hello, on CAS 5.0.6 we are trying to run our internal authentication application (runs successfully on CAS4) which calls cas/serviceVerify and cas/proxy after cas/login?service= and the cas/proxy is failing with 505 error. So far we have tried alternate service json rules but with no success

[cas-user] Re: CAS 5.0.5 Build error when using Acceptable Use Policy

2017-05-30 Thread Duane Booher
Correction, in my case I was using cas-server-support-actions-aup-ldap which had the same maven dependency problem as cas-server-support-actions-aup-webflow. On Tuesday, May 30, 2017 at 5:35:17 AM UTC-7, Duane Booher wrote: > > I also had this same problem. I was able to work

[cas-user] Re: CAS 5.0.5 Build error when using Acceptable Use Policy

2017-05-30 Thread Duane Booher
I also had this same problem. I was able to work around this (for now) by building https://github.com/apereo/cas.git w/ tag v5.0.5 and then pull in cas-server-support-actions-aup-webflow into the cas overlay using mvn a dependency with scope=system. This got me to the next step of testing with

[cas-user] CAS5 pom.xml org.ldaptive version

2017-04-25 Thread Duane Booher
We have CAS5 running on a test system with LDAP configured using unboundID, and it is working. Where in the CAS5 doc is the org.ldaptive maven pom documented, and what dependency version should be used to match say the CAS 5.0.4 version? Currently I am using: 1.2.1 Here are snips of my pom: