Where communities thrive


  • Join over 1.5M+ people
  • Join over 100K+ communities
  • Free without limits
  • Create your own community
People
Repo info
Activity
  • Sep 25 08:04

    mmoayyed on master

    Build performance tweaks (#5232… (compare)

  • Sep 25 08:04
    unfurl-links[bot] commented #5232
  • Sep 25 08:04
    welcome[bot] commented #5232
  • Sep 25 08:04
    mmoayyed closed #5232
  • Sep 25 02:24
    codecov[bot] commented #5232
  • Sep 25 02:16
    codecov[bot] commented #5232
  • Sep 25 02:14
    codecov[bot] commented #5232
  • Sep 25 02:09
    codecov[bot] commented #5232
  • Sep 25 02:06
    codecov[bot] commented #5232
  • Sep 25 02:02
    codecov[bot] commented #5232
  • Sep 25 02:00
    codecov[bot] commented #5232
  • Sep 25 01:59
    codecov[bot] commented #5232
  • Sep 25 01:55
    codecov[bot] commented #5232
  • Sep 25 01:54
    codecov[bot] commented #5232
  • Sep 25 01:51
    codecov[bot] commented #5232
  • Sep 25 01:48
    codecov[bot] commented #5232
  • Sep 25 01:46
    codecov[bot] commented #5232
  • Sep 25 01:45
    codecov[bot] commented #5232
  • Sep 25 01:42
    codecov[bot] commented #5232
  • Sep 25 01:38
    codecov[bot] commented #5232
chris_hodgson
@chris_hodgson:matrix.org
[m]
I have a random question about CAS and was wondering if you guys could help? Is it possible for a CAS server to process requests both using the CAS and OAuth2 protocols so that it is able to process requests using either. I am working on a very old codebase and need to integrate new services using modern Auth and want to know if I need to set up a second CAS server or not?
xiutian wang
@1584286140
How to integrate jwt in the latest version?
paulchauvet
@paulchauvet
Hi @chris_hodgson:matrix.org - I've not done this - but I'm almost positive you can. If you have both OAuth2 and CAS enabled - they'll both have different targets. A CAS protocol service would connect to (for example) /cas/validate, where a OAuth one would go to /cas/OAuth2.0/ (https://apereo.github.io/cas/5.2.x/installation/OAuth-OpenId-Authentication.html)
Sorry - I'm going a slightly different method to handle newer protocols and delegating auth from CAS to an external SAML provider (Azure) - and also pointing OAuth clients there instead of at CAS so haven't done it myself :(
Wilber Saca
@wsaca
Hi, how could I override OidcLogoutEndpointController? its adding the "client_id" to the "post_logout_redirect_uri" and I would like to avoid it, but this bean has not the annotation @ConditionalOnMissingBean...
runiq
@runiq
Hi :) Has there been any movement on nested LDAP groups (like described here or here)? We'd really like that for our university.
Brian Monroe
@ParadoxGuitarist
We have MFA enabled in our CAS stack, but I wasn't sure about all the config options. Currently when a new user gets enrolled for MFA, The OTP setup and keys are generated at next login. Is there a way to set that up prior to the next login?
springnirps
@springnirps
@chris_hodgson:matrix.org yes, CAS does support Oauth and CAS SSO .... cas/login and cas/oauth2.0. endpoints ... Only thing about CAS version of OAUth is that it does not support scope
springnirps
@springnirps
i'm using jpa with an entity, repository, service classes. I'm trying to autowire my service class but getting a been not defined . I already have included ComponentScan in my calling class but still not picking up my service class. Is there something special I need to do with CAS?
fbusselgln
@fbusselgln
Hey folks. I am trying to get a Spring Security based OIDC client to talk to a CAS 6.4.0-SNAPSHOT (current Master) instance with active cas-server-support-oidc module. The client is using the authorization code flow. After CAS has authenticated my test user, it creates a Service Ticket for the response, which is quite confusing. Of course the client which is registered as "@class" : "org.apereo.cas.services.OidcRegisteredService" does not understand the ST from the CAS protocol and expects an OIDC token. Logmessage from CAS: 2021-05-14 09:29:23,497 DEBUG [org.apereo.cas.authentication.principal.DefaultResponse] - <Final redirect response is [https://[myserver.tld]/testservice/login/oauth2/code/reg?ticket=ST-11-xgSjofkciebg00IvY1B-fdkDkh8-....]>
. Can anyone tell me this makes any sense at all or if it could be a bug in the current CAS version?
fbusselgln
@fbusselgln
tl;dr: Does it make sense to return an ST parameter to an OIDC redirect URL?
fbusselgln
@fbusselgln
In case this might be a bug and you need to view at some log files, this might help: https://pastebin.com/UXwjMNyu
Explicitly calling https://myhost.tld/testservice/oauth2/authorization/appOidcEndpoint afterwards on the other hand works perfectly fine.... :)
Qiukq
@Qiukq
hello,i am use the SAML2.0 protocol to connect cisco CMS.The program print ERROR when the CAS(IDP) signing the saml2 response.
Here is log: ERROR [org.apereo.cas.support.saml.web.idp.profile.builders.enc.SamlIdPObjectSigner] - <Credential private key cannot be null>
net.shibboleth.utilities.java.support.logic.ConstraintViolationException: Credential private key cannot be null
I don't know why the private key is null
hazem-hosny
@hazem-hosny
Sugar Man Bed Payol Man I Know Man
tobia
@tobia
Hello.
I just realized that SSO (single sign-out) is not playing well with Spring sessions stored on the DB (spring.session.store-type=jdbc) at least on the project I'm working on. Apparently SingleSignOutFilter and SingleSignOutHandler cannot find the session to invalidate in SessionMappingStorage.
Can anybody confirm that this is indeed an issue?
Does anybody know of a fix or a workaround?
tobia
@tobia
Update: this has nothing to do with DB storage of the sessions. Apparently I'm receiving a SAML11 request, which has the parameter named "SAMLart" (instead of "ticket") and this is not recognized as an artifact parameter by SingleSignOutHandler.
tobia
@tobia
I have added a configuration directive in the vein of singleSignOutFilter.setArtifactParameterName("SAMLart") and now the code is executed, but the session is still not dropped. I will keep debugging.
mijutu
@mijutu:ellipsis.fi
[m]
When using CAS as oauth client with pac4j, what is my "Authorization callback URL" that I'm supposed to give to the oauth server?
mijutu
@mijutu:ellipsis.fi
[m]
I tried "https://my.address/cas/login", but that just brought me back from oauth server to cas login page and did not log me in.
mijutu
@mijutu:ellipsis.fi
[m]
Authorization callback URL is "https://my.addess/cas/login/NAME" where NAME is probably the value of cas.authn.pac4j.xxx.client-name from cas.properties. And at least for github: cas.authn.pac4j.github.callback-url-type=PATH_PARAMETER
chenbo6398
@chenbo6398
Unable to start ServletWebServerApplicationContext due to missing ServletWebServerFactory bean
What's wrong with this
mijutu
@mijutu:ellipsis.fi
[m]
What do I need to write to a service registry json file if I want a service to NOT be available with any delegated authentication methods? I have other services that need deletgated authentication and I don't want to confuse users of all services with the extra buttons on login screen.
I could probably hide the buttons by creating a new theme, but I'd rather just configure them out in the service registry json.
chenbo6398
@chenbo6398
I try to start cas (with version 6+),but it block when tomcat starting.......
image.png
apascuag
@apascuag

hi @mmoayyed. I have a problem with cas-management 6.3.1.
When adding a value in the "properties" tab, I get the following error:

ERROR TypeError: e.value.split is not a function

Is it reported? Is a patch expected?

xu20160924
@xu20160924
I face the problem of java.io.FileNotFoundException: /etc/cas/thekeystore when I run the image of docker (I pulled latest version). Has anyone experienced the same problem?
2 replies
fbusselgln
@fbusselgln
Does anyone know what I am doing wrong when CAS returns Servicetickets to an OIDC Registered Client?
futureideasworld
@futureideasworld
Hi, I am getting Cannot redirect after HTTP headers have been sent as I am using .Net dotnet-cas-client. Need help please
mixman68
@mixman68
Hi guys, my issue described here : https://groups.google.com/a/apereo.org/g/cas-user/c/rGU-xgmp-Mw/m/ISSqFkxFCwAJ
is resolved on last 6.4 rc but still here in the las 6.3, will the fix back to 6.3 ?
elion
@elion

Hello!

jcifs-ext is not accessible. The repository dl.bintray.com/uniconiam/maven/ is down. It is a dependency of cas-server-support-spnego.

bondsta
@bondsta
I’m having issues logging into hoonuit it’s saying my institution has a specific way to log in but when I click on it it’s says CAS not authorized
Neil
@RealNeilB_twitter
Is there a way to remove all TGTs for a user so they will be forced to re-login for all their current CAS sessions?
xgdz
@xgdz
Can cas6.2 log in without secret?
oauthtester01
@oauthtester01
Has anyone used vouch proxy with CAS OIDC to secure web apps ? I am getting following error
{"level":"error","ts":1623440653.4036229,"msg":"no User found in jwt"}
{"level":"debug","ts":1623440653.4036324,"msg":"setting the cookie domain to grouperdev.idm.xxx.edu"}
{"level":"debug","ts":1623440653.4036362,"msg":"deleting cookie: my-vouch-ct"}
{"level":"debug","ts":1623440653.4036474,"msg":"CaptureWriter.Write set w.StatusCode 401"}
this is the error i recieve post authentication
mixman68
@mixman68
hi guys, when cas 6.4 will be released (there is no milestone in schedules)
Christopher Hoskin
@mans0954
Hello, is it possible to use https://casserver.herokuapp.com/ to test integration of a SAML SP with a CAS IdP? I looked for the IdP metadata at https://casserver.herokuapp.com/cas/idp/metadata but got a page not found. Thanks.
mwbi
@mwbi
hi guys, on centos7 with java-11-openjdk-11.0.11.0.9-1 after adding ldap and json-service-registry in the dependencies i've got an error
Task :compileJava FAILED
  • What went wrong:
    Execution failed for task ':compileJava'.
    error: release version 11 not supported
any hint for me ?
juandn
@juandn
hi, im configuring x509 auth, with ldap extra attributes, but i have a problem with matchin cert data with LDAP fields for filter. I have a principal like ABCD-1234567Z and need a searchfilter like cas.authn.attribute-repository.ldap[0].searchFilter=<ldapfield>=1234567Z, how can i trim principal in order to use them in searchfilter. thx
Marc K.
@V3ndetta
Hi, i'm trying to activate acceptable usage policy and get this Error: [..] in state 'acceptableUsagePolicyView' of flow 'login' -- action execution attributes were 'map[[empty]]' [..]
any ideas on how to fix this?
stourwalk-work
@stourwalk-work

Hi, i'm trying to activate acceptable usage policy and get this Error: [..] in state 'acceptableUsagePolicyView' of flow 'login' -- action execution attributes were 'map[[empty]]' [..]
any ideas on how to fix this?

Usually this happens when the query to find the aupAccepted value doesn't return anything at all. For example if you are using JDBC with 'SELECT aupAccepted from user where username = ?' and there is no row for the username specified then you will get the error you are seeing

Marc K.
@V3ndetta
@stourwalk-work Thanks, i'll try this later and debug the jdbc-connection. My first thought was something about webflow, so i looked at a very wrong end =)