Surrogate Auditing in Cas 6.1.5

36 views
Skip to first unread message

Robert Bond

unread,
Jul 13, 2020, 6:25:08 PM7/13/20
to CAS Community
I am having issues finding the audits for surrogate logins in Cas 6.1.5. Inside the audit log and in the console output I never see the audit even for a surrogate login like it is described in the docs here: https://apereo.github.io/cas/6.1.x/installation/Surrogate-Authentication.html#surrogate-audits

Looking for the audit log to contain the following like in the docs:
WHO: (Primary User: [casuser], Surrogate User: [testuser])

Is anyone using surrogacy and auditing or have an idea why the surrogate audits would not show up? 

Thanks so much!

Robert Bond

unread,
Jul 14, 2020, 12:03:33 PM7/14/20
to CAS Community, Robert Bond

Did some more digging it looks like cas does not audit the surrogacy login when a user selects the surrogate from the list menu, by logging in with "+username" and then selecting the surrogate from the menu. 
When logging in with "surrogate+username" cas does properly add audit log denoting it is a surrogate login. 

Audit log when using the selection menu, by logging in with "+bondr", and then selecting "bansecr_XXX"

ksnip_20200714-104544.png

Audit log when logging in with surrogate specified in the login url text box like "faisusr+bondr"

ksnip_20200714-103820.png

Any ideas on how to submit this as a bug? 

Thanks!
Reply all
Reply to author
Forward
0 new messages