Duo Universal Prompt no longer storing TGT cookie CAS 6.5.8.
33 views
Skip to first unread message
David Malia
unread,
Oct 7, 2022, 11:30:12 AM10/7/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to cas-...@apereo.org
Hello,
I'm attempting to upgrade CAS from 5.3.x to 6.5.x for the Duo Universal Prompt changes. Currently on 6.5.8. I've noticed since enabling the Universal Prompt, the TGT cookie is no longer being sent to the browser when Duo auth occurs. If a user is not going through the Duo authentication flow, the TGT cookie is set as expected. Is this something expected?
Thanks,
David Malia
David Malia
unread,
Oct 10, 2022, 5:12:24 PM10/10/22
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to cas-...@apereo.org
After more debugging, I can see the TGT cookie being set with a max age of 0 during the Universal Prompt flow, but non-Duo enabled logins have the max age of the cookie being set to the configured cas.tgc.max-age property's value.