Groups
Groups
Sign in
Groups
Groups
CAS Community
Conversations
About
Send feedback
Help
override cas.example.org DNS name
29 views
Skip to first unread message
cheekian yap
unread,
Dec 22, 2020, 12:48:13 AM
12/22/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community
Hi,
cas version: 6.2.6
I have added the following line inside application.properties:
cas.authn.saml-idp.entity-id=
https://xx.xx.xx.xx:8443/cas/idp/metadata
However, the certificate generated in /etc/cas/saml/idp-metadata.xml still shows:
X509v3 Subject Alternative Name:
DNS:
cas.example.org
, URI:
cas.example.org/idp/metadata
How can I override the default value?
Andy Ng
unread,
Dec 22, 2020, 9:29:37 AM
12/22/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community, yap.s...@gmail.com
Hello,
The endpoint seems to use the
cas.server.name
properties, see:
https://github.com/apereo/cas/blob/v6.2.6/support/cas-server-support-saml-idp-core/src/main/java/org/apereo/cas/support/saml/idp/metadata/generator/BaseSamlIdPMetadataGenerator.java#L121
Have you these
cas.server.name
for your CAS server? like so:
https://apereo.github.io/cas/6.2.x/configuration/Configuration-Properties.html#cas-server
If no, try and see if this fix it. FYI you also need to remove the idp-metadata.xml and the cert files for it to regenerate those files.
Cheers!
- Andy
cheekian yap
unread,
Dec 22, 2020, 10:36:41 AM
12/22/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community, Andy Ng, cheekian yap
Yes, changing
cas.server.name
does the trick. Thanks a lot!
Andy Ng 在 2020年12月22日 星期二下午10:29:37 [UTC+8] 的信中寫道:
Andy Ng
unread,
Dec 22, 2020, 10:43:45 AM
12/22/20
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to CAS Community, yap.s...@gmail.com, Andy Ng
np, glad it helps - Andy
Reply all
Reply to author
Forward
0 new messages