About session expiration

30 views
Skip to first unread message

Gökhan Öner (IT)

unread,
Jun 13, 2023, 11:17:21 PM6/13/23
to CAS Community
Dear friends,

This is Gokhan, a sysadmin from Sabanci University. I just want to take your attention to one of my simple questions about the CAS session.

We are using CAS 6.5.5 and when I change my network connection (from wired to wireless or when a VPN connection is turned on) my CAS session ends and I need to reauthenticate again. 

Do you have any ideas or recommendations?

Best regards.

Petr Fišer

unread,
Jun 14, 2023, 1:52:16 AM6/14/23
to 'Gökhan Öner (IT)' via CAS Community
Hello,
When you change a network, your IP address usually changes as well.
As per https://apereo.github.io/cas/6.5.x/authentication/Configuring-SSO.html :
"The cookie value is linked to the active ticket-granting ticket, the remote IP address that initiated the request as well as the user agent that submitted the request. The final cookie value is then encrypted and signed."

The parameter to influence this behavior should be cas.tgc.pin-to-session=true/false . (You can find more info on the page I linked above.)

Cheers,
Fiisch
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/1b8ac0c3-feea-44d8-a4e9-8b3c567cdbecn%40apereo.org.

Miguel Martínez De Espronceda Cámara

unread,
Jun 14, 2023, 9:06:48 AM6/14/23
to cas-...@apereo.org
Dear Gokhan,
Check this setting:

  • cas.tgc.pin-to-session=true
  • When generating cookie values, determine whether the value should be compounded and signed with the properties of the current session, such as IP address, user-agent, etc.

By default, when the client changes its IP address, CAS invalidates the session. 
Best regards,
Miguel

--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/1b8ac0c3-feea-44d8-a4e9-8b3c567cdbecn%40apereo.org.

Este mensaje puede contener información confidencial. Si usted no es el destinatario o lo ha recibido por error, por favor, bórrelo de sus sistemas y comuníquelo a la mayor brevedad al remitente. Los datos personales incluidos en los correos electrónicos que intercambie con el personal de la Universidad de Navarra podrán ser almacenados en la libreta de direcciones de su interlocutor y/o en los servidores de la Universidad durante el tiempo fijado en su política interna de conservación de información. La Universidad de Navarra gestiona dichos datos con fines meramente operativos, para permitir el contacto por email entre sus trabajadores/colaboradores y terceros. Puede consultar la Política de Privacidad de la Universidad de Navarra en la dirección: https://www.unav.edu/aviso-legal

 

This email message may contain confidential information. If you are not the intended recipient of this message or their agent, or if this message has been addressed to you in error, please immediately alert the sender by reply email and then delete this message and any attachments.  The personal information included in email messages exchanged with employees of the University of Navarra may be stored in the database of your interlocutor and/or the servers of the University for the time-period stipulated by its internal information storage policy. The University stores such data for purely administrative purposes, to facilitate e-mail contact between its employees and third parties. The University of Navarra Privacy Policy may be accessed at https://www.unav.edu/aviso-legal      

 

Antes de imprimir este mensaje o sus documentos anexos, asegúrese de que es necesario. Proteger el medio ambiente está en nuestras manos.
Before printing this e-mail or attachments, be sure it is necessary. 
It is in our hands to protect the environment.

Ray Bon

unread,
Jun 14, 2023, 1:09:29 PM6/14/23
to cas-...@apereo.org
Gökhan,

Perhaps this attribute:
cas.tgc.pin-to-session=true


Ray

On Tue, 2023-06-13 at 12:41 -0700, 'Gökhan Öner (IT)' via CAS Community wrote:
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.

Gökhan Öner (IT)

unread,
Jul 2, 2023, 7:46:22 AM7/2/23
to CAS Community
Dear everyone,

Thanks for your replies. We'll check the related parameter and apply it our environment.

Best regards.
Reply all
Reply to author
Forward
0 new messages