Hide CAS login box (and only use external identity providers)

101 views
Skip to first unread message

Paul Chauvet

unread,
Apr 28, 2021, 4:17:32 PM4/28/21
to cas-...@apereo.org
Hi all,

Is there a way (without making UI/theme changes) to completely hide the login box in CAS 6.3?

We're going to be delegating authentication to Azure via SAML - but I'd prefer to hide the regular login box completely and just want to leave the button under "External Identity Providers" there.

Apologies if I missed something obvious - and thanks all for any advice you can share.




Paul Chauvet, CISSP

Information Security Officer

State University of New York at New Paltz

chau...@newpaltz.edu


Ray Bon

unread,
Apr 28, 2021, 5:27:24 PM4/28/21
to cas-...@apereo.org
Paul,

If a service is defined as using delegated auth, the redirect will happen automatically. The login page may be visible during the redirect.
I have not tested with only delegated auth, so I do not know if you have to set delegated auth for each service.

Ray

On Wed, 2021-04-28 at 20:17 +0000, Paul Chauvet wrote:
Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.

Paul Chauvet

unread,
Apr 29, 2021, 11:08:41 AM4/29/21
to cas-...@apereo.org
Hi Ray,

Thanks for getting back to me!  The redirect comment was exactly what I needed.

I ended up adding the following to the cas properties which handles that automatic redirect:
cas.authn.pac4j.saml[0].autoRedirect=true

P.S.: It's still not done - but I'm trying to document my whole journey in getting CAS 6 (with Duo, Delegated Auth, and using Ansible to deploy/maintain CAS and Tomcat).  It's inspired by what David Curry did for his CAS 5 guide plus the Ansible stuff I've done in CAS the past couple years.

When it's complete (still need to do a couple more things - mostly on theming) I'll announce it to the list formally.  Hopefully someone else can benefit from where I've stumbled 🙂




Paul Chauvet, CISSP

Information Security Officer

State University of New York at New Paltz

chau...@newpaltz.edu




From: cas-...@apereo.org <cas-...@apereo.org> on behalf of Ray Bon <rb...@uvic.ca>
Sent: Wednesday, April 28, 2021 5:27 PM
To: cas-...@apereo.org <cas-...@apereo.org>
Subject: Re: [cas-user] Hide CAS login box (and only use external identity providers)
 
CAUTION: Message from a non-New Paltz email server. Treat message, links, and attachments with extra caution.

--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/d30df82f42cedf2e0e7b0e23179fe84be6204252.camel%40uvic.ca.

King, Robert

unread,
Apr 30, 2021, 9:55:31 AM4/30/21
to cas-...@apereo.org

Andy Ng

unread,
May 2, 2021, 11:00:16 PM5/2/21
to CAS Community, ro...@mun.ca
Hi Paul, 

The document is awesome, can't wait for the complete version :)

Cheers!
- Andy

Reply all
Reply to author
Forward
0 new messages