Re: [cas-user] Missing features in dealing with SAML2 delegated authentication

2017-07-12 Thread Fabio Martelli
with? For pac4j I think I have to change into Pac4jProperties$Saml, haven't I? Thank you again for your reply. BR, F. --Misagh On July 11, 2017 at 12:33:04 PM, Fabio Martelli (fabio.marte...@gmail.com <mailto:fabio.marte...@gmail.com>) wrote: Hi All, I'm working to configure my CAS

Re: [cas-user] Missing features in dealing with SAML2 delegated authentication

2017-07-17 Thread Fabio Martelli
roups.google.com/a/apereo.org/d/msgid/cas-user/027601d2fb1f%24a7f31790%24f7d946b0%24%40unicon.net <https://groups.google.com/a/apereo.org/d/msgid/cas-user/027601d2fb1f%24a7f31790%24f7d946b0%24%40unicon.net?utm_medium=email_source=footer>. -- Fabio Martelli https://it.linkedin.com/pub/fa

[cas-user] X509 principal resolver to extract substring from CN

2017-07-17 Thread Fabio Martelli
it doesn't exist, can you give me a tip to specify a custom one? My CN is something like as "CN=fabio.martelli/611028099004.eHbeoxQkaF63vgZG+cX5jPQF7". I need to extract fabio.martelli as principal name. Thank you in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabi

[cas-user] Attribute resolution after X509 authentication

2017-07-17 Thread Fabio Martelli
is currently configured)? Thank you in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http

Re: [cas-user] X509 principal resolver to extract substring from CN

2017-07-17 Thread Fabio Martelli
for that). Hi Dimitriy, it works as expected. Thank you for your support. BR, F. Cheers, D. From: Fabio Martelli <fabio.marte...@gmail.com> <mailto:fabio.marte...@gmail.com> Reply: cas-user@apereo.org <cas-user@apereo.org> <mailto:cas-user@apereo.org> Date: July 17, 20

[cas-user] Missing features in dealing with SAML2 delegated authentication

2017-07-11 Thread Fabio Martelli
Hi All, I'm working to configure my CAS 5.1.1 in order to delegate the authentication to an external SAML2 identity provider. I successfully configured this scenario just by adding pac4j-webflow dependency + by including into my cas.properties file some cas.authn.pac4j.saml[0].* properties (as

Re: [cas-user] Missing features in dealing with SAML2 delegated authentication

2017-07-12 Thread Fabio Martelli
sgid/cas-user/etPan.59660db4.217acc40.56e%40unicon.net?utm_medium=email_source=footer>. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm A

Re: [cas-user] Missing features in dealing with SAML2 delegated authentication

2017-07-12 Thread Fabio Martelli
r/etPan.59660db4.217acc40.56e%40unicon.net?utm_medium=email_source=footer>. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Sync

[cas-user] Re: Need Help setting up CAS with x.509 authentication

2017-07-20 Thread Fabio Martelli
Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli/ -- - CAS gitter chatroom: https://gitter.im

[cas-user] Cannot retrieve user attributes from PHP application behind mod_auth_cas

2017-07-19 Thread Fabio Martelli
in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli/ -- - CAS gitter

Re: [cas-user] Configure CAS to have a good logout handling with a load balanced multi instance application

2017-07-24 Thread Fabio Martelli
. In any case, what should be the best practice with CAS 5.1? Best regards, F. Memcache is easy to setup. Regards. Le 21 juillet 2017 17:17:29 GMT+02:00, Fabio Martelli <fabio.marte...@gmail.com> a écrit : Hi All, I need your help to understand how I can configure my CAS

Re: [cas-user] Configure CAS to have a good logout handling with a load balanced multi instance application

2017-07-26 Thread Fabio Martelli
Il 24/07/2017 08:04, Fabio Martelli ha scritto: Il 21/07/2017 18:57, Sébastien Beaudlot ha scritto: Hi Do you have any backend configured for ticket registry ? This may be the easiest way to achieve your goal. Hi Sébastien, thank you for your prompt reply. No I have not a backend configured

[cas-user] Configure CAS to have a good logout handling with a load balanced multi instance application

2017-07-21 Thread Fabio Martelli
to route the request correctly. Can you suggest a solution? Thank you in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm

[cas-user] Key generation operations persist despite configurations provided

2017-08-23 Thread Fabio Martelli
=.. cas.webflow.encryption.keySize=16 cas.webflow.alg=AES cas.tgc.encryptionKey=... cas.tgc.signingKey=... cas.tgc.cipherEnabled=true -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http

[cas-user] Missing idp-signing.key during SAML2 Authentication

2017-08-23 Thread Fabio Martelli
since I cannot find references about into the documentation. Thank you in advance for your help. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html

Re: [cas-user] Key generation operations persist despite configurations provided

2017-08-23 Thread Fabio Martelli
-Ursprüngliche Nachricht- Von: cas-user@apereo.org [mailto:cas-user@apereo.org] Im Auftrag von Fabio Martelli Gesendet: Mittwoch, 23. August 2017 12:12 An: cas-user@apereo.org Betreff: [cas-user] Key generation operations persist despite configurations provided Hi All, I provided

[cas-user] Re: Trouble configuring SPNEGO

2017-09-15 Thread Fabio Martelli
Il 12/09/2017 16:54, Fabio Martelli ha scritto: Hi All, is there someone that can address me with this issue? I still have trouble with kerberos authentication. Why I can authenticate with a simple/sample java client but with Apereo CAS? Hi All, I solved my issue: it was just

[cas-user] SAML2 delegated authentication deflate problem

2017-09-18 Thread Fabio Martelli
Hi All, is there a way to skip HTTP redirect deflate encoder working with SAML2 delegated authentiation? My CAS installation is based on 5.2.0-RC3. Please, let me know. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio

Re: [cas-user] Re: Configuring SPNEGO with CAS 5.2.0-RC3-SNAPSHOT

2017-09-08 Thread Fabio Martelli
olečnost AMI Praha a.s. jakoukoliv smlouvu. Každá smlouva, pokud bude uzavřena, musí mít výhradně písemnou formu. 2017-09-07 17:43 GMT+02:00 Fabio Martelli <fabio.marte...@gmail.com <mailto:fabio.marte...@gmail.com>>: Hi, it seems that there is a conflict with X509 webflow.

[cas-user] Trouble configuring SPNEGO

2017-09-08 Thread Fabio Martelli
) at sun.security.krb5.internal.crypto.ArcFourHmac.decrypt(ArcFourHmac.java:91) at sun.security.krb5.internal.crypto.ArcFourHmacEType.decrypt(ArcFourHmacEType.java:100) ... 276 more -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio

[cas-user] Java CAS client request wrapper filter extension

2017-09-11 Thread Fabio Martelli
Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli/ -- - Website: https://apereo.github.io/cas

Re: [cas-user] SAML delegated authentcation missing AttributeConsumingServiceIndex

2017-09-05 Thread Fabio Martelli
see, this would be just a temporary workaround if there is a solution to my problem. Please, let me know. Thank you in advance, F. - Original Message - From: "Fabio Martelli" <fabio.marte...@gmail.com> To: "CAS Community" <cas-user@apereo.org> Sent: Tu

[cas-user] Custom SQL query for attribute retrieving

2017-09-05 Thread Fabio Martelli
that info is missing in my repo. How can I solve it? Thank you in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm

Re: [cas-user] SAML delegated authentcation missing AttributeConsumingServiceIndex

2017-09-06 Thread Fabio Martelli
Il 05/09/2017 16:51, Fabio Martelli ha scritto: Il 05/09/2017 16:47, Misagh Moayyed ha scritto: You have done fine. The [temporary] solution to "your" problem is the solution to "the" problem :) :) Turn your change into a PR, ping Jerome and send it over to pac4j. I

[cas-user] Re: Trouble configuring SPNEGO

2017-09-12 Thread Fabio Martelli
Hi All, is there someone that can address me with this issue? I still have trouble with kerberos authentication. Why I can authenticate with a simple/sample java client but with Apereo CAS? Please, help me if you can. BR, F. Il 08/09/2017 17:18, Fabio Martelli ha scritto: Hi, I configured my

[cas-user] SAML2 Metadata UI parsing exception

2017-08-24 Thread Fabio Martelli
] at org.springframework.expression.spel.standard.SpelExpression.getValue(SpelExpression.java:324) ~[spring-expression-4.3.10.RELEASE.jar:4.3.10.RELEASE] at org.thymeleaf.spring4.expression.SPELVariableExpressionEvaluator.evaluate(SPELVariableExpressionEvaluator.java:263) ~[thymeleaf-spring4-3.0.7.RELEASE.jar:3.0.7.RELEASE] -- Fabio Martelli https

[cas-user] Delegated authentication issues moving from 5.2.0-RC2 to 5.2.0-RC3-SNAPSHOT

2017-08-25 Thread Fabio Martelli
something? Thank you in advance for your support. Best regards, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http

[cas-user] Re: Delegated authentication issues moving from 5.2.0-RC2 to 5.2.0-RC3-SNAPSHOT

2017-08-25 Thread Fabio Martelli
. Is SAML2 delegated authentication available just for providers supporting Redirect binding? Please, let me have a feedback. BR, F. cas.authn.pac4j.saml[0].destinationBinding=urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST Il 25/08/2017 10:17, Fabio Martelli ha scritto: Il 25/08/2017 09:13, Fabio

[cas-user] CAS 5.2.0-RC3-SNAPSHOT handle authentication exception

2017-08-28 Thread Fabio Martelli
Hi, what are the best practices to handle a Ldap authentication exception? I need to successfully authenticate active directory disabled users. Where can I act? Thank you in advance for your help. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http

[cas-user] Re: Delegated authentication issues moving from 5.2.0-RC2 to 5.2.0-RC3-SNAPSHOT

2017-08-25 Thread Fabio Martelli
Il 25/08/2017 09:13, Fabio Martelli ha scritto: Hi All, it seems that delegated authentication that was working fine with CAS 5.2.0-RC2 in not working anymore with 5.2.0-RC3-SNAPSHOT. In particular, the IdP URLs shown into the login page are not correct. Furthermore, nor the look seems

[cas-user] Re: CAS 5.2.0-RC3-SNAPSHOT handle authentication exception

2017-08-31 Thread Fabio Martelli
Il 28/08/2017 17:52, Fabio Martelli ha scritto: Hi, what are the best practices to handle a Ldap authentication exception? I need to successfully authenticate active directory disabled users. Where can I act? Thank you in advance for your help. BR, F. Hi, I solved my issue by providing

[cas-user] SAML delegated authentcation missing AttributeConsumingServiceIndex

2017-09-05 Thread Fabio Martelli
Hi All, with is there a way to specify AttributeConsumingServiceIndex AuthnRequest attribute with CAS 5.2.0-RC3? Please, let me know. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence

Re: [cas-user] SAML Authentication fails via mod_proxy_http

2017-11-14 Thread Fabio Martelli
* *binding* to send me the AuthnRequest. Is there a way to force CAS IdP to some useful behavior? Thank you in advance. BR, F. Tom. On Nov 14, 2017, at 8:59 AM, Fabio Martelli <fabio.marte...@gmail.com> wrote: Hi All, I have some trouble with SAML Authentication through mod_proxy_http. It

Re: [cas-user] Looking for french consulting

2017-11-17 Thread Fabio Martelli
medium=email_source=footer>. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli

[cas-user] SAML Authentication fails via mod_proxy_http

2017-11-14 Thread Fabio Martelli
/cas/support/saml/web/idp/profile/AbstractSamlProfileHandlerController.java#L386-L403 -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm

[cas-user] SAML Authentication fails through httpd reverse proxy

2017-11-07 Thread Fabio Martelli
? Thank you in advance. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli

[cas-user] authentication throttling and temporary account lockout

2018-01-11 Thread Fabio Martelli
.01). As anticipated, I would lockout a user after 3 consecutive failed login attempts occurred within 60 seconds. Is it possible? Thank you in advance for your help. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tir

[cas-user] Force Principal attributes releasing in HTTP Header

2018-01-19 Thread Fabio Martelli
Hi All, is there a way to force CAS 5.2.X to release principal attributes in HTTP Header for a java-cas-client? Thank you in advance for any help. BR, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open

Re: [cas-user] authentication throttling and temporary account lockout

2018-01-11 Thread Fabio Martelli
you in advance for your further reply. BR, F. Ray On Thu, 2018-01-11 at 15:13 +0100, Fabio Martelli wrote: Hi All, is there someone that can give me some tips to implement *temporary account lockout after 3 consecutive failed login attempts*? It seems that authentication throttling

[cas-user] mod_auth_cas environnment variable

2018-02-13 Thread Fabio Martelli
Hi All, is there a way to force mod_auth_cas to put retrieved principal attributes as env variable instead of headers? Thanks in advance for any help. BR, F. -- Fabio Martelli Tel +393204726071 https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio

[cas-user] Custom Spnego webflow filter

2018-03-15 Thread Fabio Martelli
-- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli/ -- - Website: https://apereo.github.io

Re: [cas-user] Re: Problem with SAML2 delegated administration

2018-10-31 Thread Fabio Martelli
2018 20:21:35 CET, Misagh Moayyed ha scritto: >If you mean the SP metadata, can you not modify that manually with the >right URLs to match your proxy? > >On Wednesday, October 31, 2018 at 12:09:52 PM UTC+3:30, Fabio Martelli >wrote: >> >> Dear All, I have to ask for yo

[cas-user] Problem with SAML2 delegated administration

2018-10-31 Thread Fabio Martelli
*. Is there a way to achieve this requirement? If I have to override something, could you address me where I have to change the behavior? Finally, if you think it could be a bug, please let me know if, in case, I have to provide a PR. Thank you in advance. Best regards, F. -- Fabio Martelli Tel

[cas-user] SAML2 SLO SP initiated

2018-09-12 Thread Fabio Martelli
for your help. Kind regards, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html?pk_campaign=email_kwd=fm Apache Syncope PMC http://people.apache.org/~fmartelli

[cas-user] Allow OPTIONS method request to /cas/login

2019-05-09 Thread Fabio Martelli
Hi All, is there a way to allow OPTIONS method requests to /cas/login? Please, let me know. Regards, F. -- Fabio Martelli https://it.linkedin.com/pub/fabio-martelli/1/974/a44 http://blog.tirasa.net/author/fabio/index.html Tirasa - Open Source Excellence http://www.tirasa.net/index.html

Re: [cas-user] Re: Ranking Providers for step-up authentication

2019-05-21 Thread Fabio Martelli
providers? * Is there a way to update an existing SSO session (step-up)? Thank you in advance. Kind regards, F. On Monday, May 20, 2019 at 4:09:19 AM UTC-7, Fabio Martelli wrote: Hi All, I'd like to exploit "Ranking Providers" feature [1] in order to implement a step-up auth

[cas-user] Ranking Providers for step-up authentication

2019-05-20 Thread Fabio Martelli
uot;rank". Can someone address me in this direction? I didn't find any documentation for implementing this feature. Thank you in advance. Regards, F. [1] https://apereo.github.io/cas/5.2.x/installation/Configuring-Multifactor-Authentication.html#ranking-providers -- Fabio Martelli htt

Re: [cas-user] Looking for IAM solution

2020-05-07 Thread Fabio Martelli
Hi Kazim, can I suggest a fully completed solution based on Apache Syncope and Apereo CAS? Please let me know if you need more info/details Regards, F. Il gio 7 mag 2020, 12:32 Kazim Koybasi ha scritto: > Hello, > > We are looking for an open source or proprietary IAM solution to use in > our

Re: [cas-user] Looking for IAM solution

2020-05-07 Thread Fabio Martelli
/confluence/display/SYNCOPE/%5BDISCUSS%5D+Syncope+3.0 [3] https://www.apereo.org/content/commercial-affiliates [4] http://syncope.apache.org/professional-services Regards. On Thu, 7 May 2020 at 14:08, Fabio Martelli <mailto:fabio.marte...@gmail.com>> wrote: Hi Kazim, can