CAS 5.3.3 delegated auth to CAS breaks SAML IdP

74 views
Skip to first unread message

Jon Anderson

unread,
Oct 3, 2018, 7:16:07 PM10/3/18
to CAS Community
I'm trying to configure CAS 5.3.3 as a SAML IdP. That part seems to work, but I want it to delegate authentication to an existing CAS server, but doing that it forgets to reply to the SP in SAML, and instead sends a CAS service ticket.

Before the CAS/IdP has a session for the user it breaks, forgetting to reply in saml:
SP =(saml)=> CAS/Idp =(cas)=> CAS =(cas)=> CAS/Idp =(cas!!)=> SP

Then trying again now that the CAS/IdP has a session for the user it works:
SP =(saml)=> CAS/IdP =(saml)=> SP

The IdP works.
The delegated auth to cas works.
Doing them together, how my users would, doesn't work.

Is this a bug?
Is there something I have to configure to get it to resume with saml when it has to do the delegated auth?

Thanks,
Jon

Daniel Ramos

unread,
Nov 5, 2018, 5:01:20 PM11/5/18
to CAS Community
Hi Jon,
    I am facing the same issue. Did you ever figure this out?

Thanks!
    - Danny

Jon Anderson

unread,
Nov 5, 2018, 5:02:47 PM11/5/18
to cas-...@apereo.org
Nope.
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email to cas-user+u...@apereo.org.
To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/1f25dc0d-2092-48b5-baab-69de716ec7d7%40apereo.org.

Daniel Ramos

unread,
Nov 8, 2018, 9:27:38 AM11/8/18
to CAS Community
Jon,
    I've figured out a fix for the bug. I'll likely be submitting a pull request for it for version 6, but if you want to add it to your overlay I can share.
Reply all
Reply to author
Forward
0 new messages