CAS SSO Session Timeout Not Honored by Integrated Application After Migration to CAS 7.3.5

55 views
Skip to first unread message

Mohamed Iheb JEMAI

unread,
Jun 19, 2026, 7:26:49 AM (7 days ago) Jun 19
to CAS Community

Hello,

I have a question regarding session timeout behavior after migrating from CAS 6.6.15 to CAS 7.3.5.

In our CAS server, we have the following ticket configuration:

cas.ticket.tgt.hard-timeout.time-to-kill-in-seconds=7140
cas.ticket.st.time-to-kill-in-seconds=120

The TGT timeout is configured to be almost 2 hours, and this configuration was already working before the migration.

However, we have an external application integrated with our CAS SSO server using CAS authentication. This application logs users out every 1 hour, even though the CAS TGT is still supposed to be valid for nearly 2 hours.

Because of this behavior, I suspect the application is not taking the CAS session lifetime into account and may be managing its own session timeout.

Has anyone encountered a similar situation? Do you have any recommendations on how to investigate whether the timeout is coming from CAS or from the client application itself?

Thank you for your help.

Ray Bon

unread,
Jun 19, 2026, 1:24:51 PM (7 days ago) Jun 19
to cas-...@apereo.org
Mohamed,

The cas session (TGT) only applies to cas, the lifetime of SSO.
Every other service is responsible for its own session.
If the user has to log in again after an hour, perhaps the application is forcing a re-authn. See https://apereo.github.io/cas/7.3.x/protocol/CAS-Protocol-Specification.html#211-parameters

Ray

From: cas-...@apereo.org <cas-...@apereo.org> on behalf of Mohamed Iheb JEMAI <mohamedi...@gmail.com>
Sent: June 19, 2026 01:08
To: CAS Community <cas-...@apereo.org>
Subject: [cas-user] CAS SSO Session Timeout Not Honored by Integrated Application After Migration to CAS 7.3.5
 
--
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/52c0249e-443f-47da-8534-25d0dd8b61bbn%40apereo.org.

Eugene Willis

unread,
Jun 19, 2026, 1:46:26 PM (7 days ago) Jun 19
to cas-...@apereo.org, cas-...@apereo.org
I think by default the setting now built into cas. So you may be able to remove that stanza. I would have to look through my notes. I think cas default settings is 8 hours. Let me look through my notes to verify.
Sent from my iPhone

On Jun 19, 2026, at 1:24 PM, 'Ray Bon' via CAS Community <cas-...@apereo.org> wrote:


Reply all
Reply to author
Forward
0 new messages