[cas-user] Authentication using JWT

2017-06-21 Thread Vladyslav Kutsenko
Dear CAS community, We are in process of integrating Apereo CAS with a JavaScript SPA application using JWT ticket. The ticket is generated by CAS and submitted to the rest façade of our application as a ‘ticket’ get parameter. We have some concerns about the ticket being not a one-ti

Re: [cas-user] CAS 5.1 Password expired issues

2017-06-21 Thread Ludovic Senecaux
Thanks Pavlos, it works ! Have you found any workarouds for : 1/ the use of pwdGraceAuthNLimit 2/ customize URL for password update (I tried to set "#{screen.mustchangepass.message(${cas.authn.pm.changeUrl})}" in pwdupdateform.html, but unsuccessfully) Regards, -- - CAS gitter chatroom: htt

[cas-user] Load authorities in bootiful-cas-client app

2017-06-21 Thread Coşkun Deniz
Hi, I have cas server and a client with auto configure spring boot application. I did it like this https://github.com/UniconLabs/bootiful-cas-client. Also i have an authorization application and it provides rest service for roles of users. I want to use this rest service, when user logged in cas

[cas-user] CAS 5.1.0: Cannot read/parse JSON [{}] to deserialize into type [] ... missing configuration/support module

2017-06-21 Thread Michael Kotowski
Hi. I am using CAS 5.1.0 and it is working fine including multifactor authentication. But, I get the following warning: org.apereo.cas.config.CasCoreTicketsConfiguration] - To get rid of the following warning and persist tickets I added the cas-server-support-mongo-ticket-registry dependency

Re: [cas-user] cas.sso.missingService and cas.sso.renewedAuthn

2017-06-21 Thread atilling
I'm not seeing any logged activity other than the normal service registry refreshes. Do you have a suggestion on a class that I should set to debug? I'm not the only one that has mentioned SSO not functioning: https://groups.google.com/a/apereo.org/forum/?utm_medium=email&utm_source=footer#!sear

[cas-user] Re: CAS-LDAP groups for authorization

2017-06-21 Thread öncül korkut
Well, finally I could achieve what I asked. Thank for CAS development team for the functionality provided; although, I had to merge some blogs , how-to's and stackoverflow questions to achieve this. For any one who would like to use same approach I wrote my resolution below (please notify me if

[cas-user] Re: Global Principal Attribute MFA trigger is not working as expected

2017-06-21 Thread Sai Mallela
Hello Dimitri, Can you please help me with gauth to work globally. Here are my settings in cas.properties and I still don't see the page or option to enter the google authentication code: cas.server.name: https://drupalvm.dev:8443 cas.server.prefix: https://drupalvm.dev:8443/cas cas.adminPages

Re: [cas-user] CAS 5.1 Password expired issues

2017-06-21 Thread Pavlos Drandakis
On 21/06/2017 12:10 μμ, Ludovic Senecaux wrote: Thanks Pavlos, it works ! Glad to hear it :-) Have you found any workarouds for : 1/ the use of pwdGraceAuthNLimit When pwdGraceAuthNLimit was enabled, I was keep getting NPE in logs and nothing in login form. After this change: https://githu

Re: [cas-user] CAS 5.1 Password expired issues

2017-06-21 Thread Ludovic Senecaux
I want to display a correct URL (defined in cas.properties) to users without modify messages.properties. I put a parameter to #{screen.mustchangepass.message} inn pwdupdatepass.html file that override "{0}" variable in messages_XX.properties like it is explained here : http://www.thymeleaf.org/doc/

Re: [cas-user] [CAS 5.0.1] Unable to browse any link of my CAS Client web application after successful user authentication through CAS Server

2017-06-21 Thread Ray Bon
John, Check config of your client. The order that client uses to process the request is important. For instance (java client uses filters), the first filter would check for logout request, after that check for validation request. The last filter would redirect to login. (There may be other filt

RE: [cas-user] CAS 5.1.0: Cannot read/parse JSON [{}] to deserialize into type [] ... missing configuration/support module

2017-06-21 Thread Misagh Moayyed
Nothing is missing in your config. This is a bug in JSON serialization. You’re welcome to file an issue. --Misagh From: cas-user@apereo.org [mailto:cas-user@apereo.org] On Behalf Of Michael Kotowski Sent: Wednesday, June 21, 2017 5:09 AM To: CAS Community Subject: [cas-user] CAS 5.1.0: Can

Re: [cas-user] Authentication using JWT

2017-06-21 Thread Ray Bon
Vladyslav, The CAS ST is invalidated on first use and short lived (approx 10s, configurable). If you want your application to create only one JWT, you will need to keep a list of CAS tickets and JWT tickets. Ray On Wed, 2017-06-21 at 01:38 -0700, Vladyslav Kutsenko wrote: Dear CAS community,

[cas-user] How to Logout All CAS Client From Other Domain/URL ?

2017-06-21 Thread Doan Moon
*Hi Everyone !* i'm Using CAS 5.0.5 and CAS Management 5.0.5. In CAS Management. I have 2 CAS Client that it is the same Source Code . I Set: http://localhost:9292 and http://192.168.100.11:9292. They are the same SourceCode. They is one Website that can access 2 way. But my problem is When l

Re: [cas-user] CAS 5.1 Password expired issues

2017-06-21 Thread Pavlos Drandakis
Ok, now I understand what you are trying to do, but I don't think that you can do it without editing messages{_xx}.properties. screen.mustchangepass.message doesn't have a {0} in it, so there is nothing to replace... The url is hard coded in the message. Regards, Pavlos On 21/06/2017 06:38 μμ

Re: [cas-user] cas.sso.missingService and cas.sso.renewedAuthn

2017-06-21 Thread Petr Gašparík - AMI Praha a . s .
No, sorry. I was just hoping to look into log file for something that hit me. -- s pozdravem Petr Gašparík solution architect gsm: [+420] 603 523 860 e-mail: petr.gaspa...@ami.cz AMI Praha a.s. Pláničkova 11 162 00 Praha 6 tel.: [+420] 274 783 239 web: www.ami.cz [image: AMI Praha a.s.] [i