Saml2

91 views
Skip to first unread message

Jesse

unread,
Jul 24, 2024, 7:30:18 PM (17 hours ago) Jul 24
to CAS Community
We are trying to use cas as IDP and IOS app as ServiceProvider and we want to land from ios app(has ServiceTicket) to safari(web application) without login using saml2. Is there a way to handle this? We came up with getting saml request from ios to cas and getting saml response back but saml response is too big to pass it in the url to the web browser application. Any design or secure way to do it with saml and how we can land without login again in the web browser.

Ray Bon

unread,
Jul 24, 2024, 11:10:27 PM (14 hours ago) Jul 24
to cas-...@apereo.org
Jesse,

What authentication protocols are available for your iOS app?

ServiceTicket is part of CAS protocol (different from cas service / IdP); SAML is another protocol. Cas service supports other protocols.

Whatever protocol you want to use, you need a client / service provider / relying party to handle the response from cas.

The SP is typically associated with the application(s) being protected, not on a users device.

Ray

From: cas-...@apereo.org <cas-...@apereo.org> on behalf of Jesse <jesse...@gmail.com>
Sent: 24 July 2024 15:36
To: CAS Community <cas-...@apereo.org>
Subject: [cas-user] Saml2
 
You don't often get email from jesse...@gmail.com. Learn why this is important
We are trying to use cas as IDP and IOS app as ServiceProvider and we want to land from ios app(has ServiceTicket) to safari(web application) without login using saml2. Is there a way to handle this? We came up with getting saml request from ios to cas and getting saml response back but saml response is too big to pass it in the url to the web browser application. Any design or secure way to do it with saml and how we can land without login again in the web browser.

--
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/a2800488-9813-49af-8b1b-81c3cb1a69dan%40apereo.org.

Essey T

unread,
Jul 24, 2024, 11:29:40 PM (13 hours ago) Jul 24
to cas-...@apereo.org


Ray,
The iOS app is using CAS protocol. But we want to implement SAML feature, can I use iOS as service provider, web browser application as Service provider 2, and IDP CAS. Is it possible to send Saml request and receive SAML response to SP2(web browser app) to validated the assertion and open session for the user. Or is there way to do SSO login using CAS from iOS to safari


Reply all
Reply to author
Forward
0 new messages