Notice: This message was sent from outside the University of Victoria email system. Please be cautious with links and sensitive information.
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/ebab25780f77a0697d2191e2fc4e466d00d59f56.camel%40uvic.ca.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/42932cfeeb2c1bfac9ca42c058f6017b46ab6196.camel%40uvic.ca.
Hi Vikash,a) regarding the NoClassDefFoundError , can you please try to add the following dependency to your Gradle (or do you use Maven?) project configuration and see if its helps?That's the library that should contain the missing DERObjectIdentifier class. According to the contents of https://github.com/apereo/cas/blob/v6.6.8/support/cas-server-support-radius-mfa/build.gradle, it seems this library is added to the project, but only conditionally, so maybe that's the reason this information doesn't seem to get projected to the final artifact, i.e. you won't find the bcprov library listed e.g. on https://mvnrepository.com/artifact/org.apereo.cas/cas-server-support-radius-mfa/6.6.10.b) Regarding the bypasses, I have no clue. I can only recommend checking the logs (with possibly increasing log level to DEBUG) and diff the configuration files against the CAS overlay template...Petr
Hi Vikash,I'm a bit confused now - because what you describe about pinging a Radius server seems to be just fine: you can see in the source code of RadiusMultifactorAuthenticationProvider (here) that the pinging method does send a testing username and password (i.e. not the ones from the login form) and it only fails when one of TimeoutException or SocketTimeoutException is thrown from all the setup Radius servers.So maybe your Radius server (host and/or port) is just not accessible from your CAS server? You hint above that you are using the default "cas.authn.mfa.radius.client.transport-type=UDP" and you have the appropriate UDP ports open - can you confirm this e.g. by using one of the tools listed at https://www.baeldung.com/linux/udp-port-testing?BTW I take your message as a confirmation that adding the bcprov library to your CAS instance explicitly did help and you are solving another problem within the flow now. Feel free to correct me.RegardsPetr
It's Network teamOn Wed, Aug 30, 2023, 2:03 AM <p.bo...@centrum.cz> wrote:Hi there,
what does "NW" stand for?
According to https://serverfault.com/questions/35218/in-windows-using-the-command-line-how-do-you-check-if-a-remote-port-is-open, they recommend either to use Portqry (download from https://www.microsoft.com/en-us/download/details.aspx?id=17148&6B49FDFB-8E5B-4B07-BC31-15695C5A2143=1, or there is also an UI version) or "a port of netcat" (download probably from https://eternallybored.org/misc/netcat/ and notice the remark about antiviruses...). I would probably go with the Portqry.
I don't use these tools myself (commonly testing just TCP connections), so thanks in advance to let me know about the results... :)
Petr
______________________________________________________________
> Od: "Vikash Chandra Ansh" <vikasha...@gmail.com>
> Komu: "Petr Bodnár" <p.bo...@centrum.cz>
> Datum: 29.08.2023 22:05
> Předmět: Re: [cas-user] Radius -MFA in cas 6.6.8
>Hi Peter,Yes transport type is UPD in our case. But however I was not able to test UDP ports on my Windows machine. I have asked my NW team, and they have confirmed that 1812 and 1813 has been enabled at destination end for my machine.Is there any way to test in windows machine
Hi Vikash,
congrats to making it finally work.
Regarding what you write about the bouncycastle.jar, this is an interesting "plot twist", because I wouldn't expect this library would relate to the connection issues you've reported lastly. Also, as I described before, I wouldn't even expect any bouncycastle.jar (bcprov.jar) be present in the cas.war, unless explicitly specified. But yeah, one always doesn't hit the target... ;)
> Could you suggest how we can add multiple inet address for RSA (edit: you surely mean RADIUS here).
______________________________________________________________
> Od: "Vikash Chandra Ansh" <vikasha...@gmail.com>
> Komu: "Petr Bodnár" <p.bo...@centrum.cz>, "CAS Community" <cas-...@apereo.org>
> Datum: 13.09.2023 11:16
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/20230913121336.FF0CC15C%40centrum.cz.