[cas-user] Sign in with apple

2020-05-18 Thread Koen De Jaeger
I joined a project last week at work where they are using cas 5.x to login the user with Twitter, Facebook and Google. Now they want us to add 'Sign on with Apple'. Is there a reason why this is not implemented yet in 6.x? -- - Website: https://apereo.github.io/cas - Gitter Chatroom:

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread mbar...@scad.edu
Thank you again for responding. I wish we didn't split email, but we did a long time ago - during the initial email implementation - and we never tried to consolidate. Fortunately, I don't have the "which account" problems. Students get a pretty clear setup, and anything extra would go to

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread mbar...@scad.edu
David, Richard, Thank you very much. Did you or do you have issues with students/staff getting confused on which account to use? Any tips for handling that other than FAQs? We've got several hundred people with dual accounts. Thank you, Mike On Monday, May 18, 2020 at 2:05:05 PM UTC-4,

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread David Curry
In our case no, because the "staff" account is really just an "administrator" account -- so it's the one used to be an application (or system) admin rather than the user's regular account. Most of the people who have those are IT people, although a few non-IT people are starting to get them as we

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread David Curry
If the double-account people are still the exception rather than the rule (even with a couple hundred), I recommend a consistent naming scheme for them with a prefix or something (like our "adm_netid"). Then you can just refer to "your xyz account" where "xyz" is the prefix, and it's always clear

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread David Curry
We do pretty much the same thing Richard is doing. The different accounts are in different OUs in AD, and IAM handles the provisioning. Way back when, we configured CAS with multiple "directories" that are the same AD server with different DNs (one for each OU). We could probably stop doing that

Re: [cas-user] Handling multiple accounts for one person

2020-05-18 Thread Richard Frovarp
We just have separate accounts in AD, which is where we are authenticating and doing attribute release from. The IAM system is responsible for correctly populating the directory and end application if needed in the correct way for each account. This requires multiple accounts and passwords, and

[cas-user] Passvators and Connection Strategy 6.1.6

2020-05-18 Thread 'Mallory, Erik' via CAS Community
Hello, Currently we are running CAS 6.1.6 and we have a problem when we reboot a domain controller. It would appear that the ldap connection is not failing to the second DC in the list causing logins to fail. We have four of DCs. CAS is configured to use all 4 with a connection strategy of

[cas-user] Can we remove the /adminlogin URL entirely?

2020-05-18 Thread 'Hedley Proctor' via CAS Community
We've recently upgraded from CAS3 to CAS6.0.3. I can see that it has an admin URL available at /adminlogin. For security, I would like to disable this admin login. I can't find much information about the admin login, but I believe it is the login for the management stats, as per:

[cas-user] Handling multiple accounts for one person

2020-05-18 Thread mbar...@scad.edu
At our university, we have some applications where one person will only have one account and the application is aware of the different "roles" a person might have, i.e., student, staff, faculty and/or alumni. We also have some other applications where a person may have a student account and

Re: [cas-user] Passvators and Connection Strategy 6.1.6

2020-05-18 Thread Daniel Fisher
On Mon, May 18, 2020 at 12:22 PM 'Mallory, Erik' via CAS Community < cas-user@apereo.org> wrote: > Could someone confirm and explain the relationship (if any) of > passivators to to the connection strategy configuration options? > Passivators are executed when a connection is returned to the