[cas-user] Re: CAS keeps generating RegexRegisteredService-********.json files in CAS/Services folder

2019-08-28 Thread john
Andy, i am using openid and as you mentioned, in generated json it has serviceid as mentioned below. But CAS generates new file when server is restarted instead of looking into already generated json file. On Thursday, August 29, 2019 at 6:43:48 AM UTC+5:30, Andy Ng wrote: > > Hi John, > >

[cas-user] Re: CAS keeps generating RegexRegisteredService-********.json files in CAS/Services folder

2019-08-28 Thread john
Andy, i am using openid and as you mentioned, in generated json it has serviceid as mentioned below. But CAS generates new file when server is restarted instead of looking into already generated json file. Thanks Gopal On Thursday, August 29, 2019 at 6:43:48 AM UTC+5:30, Andy Ng wrote: > > Hi

[cas-user] Re: CAS keeps generating RegexRegisteredService-********.json files in CAS/Services folder

2019-08-28 Thread Andy Ng
Hi John, On seconds thought, those might be some necessary service for OpenID to use Can you check if the serviceId is something like `https://cas.example .org:8443/cas/oauth2.0/callbackAuthorize`? If so, then you probably don't want to remove those, or else your CAS will most likely have

Re: [cas-user] Seamless login

2019-08-28 Thread Petr Gašparík - AMI Praha a . s .
Oh! I know! https://apereo.github.io/cas/6.0.x/installation/Surrogate-Authentication.html#preselected It is done simply by +user in REST authentication request, right? Genial! Petr On Wednesday, August 28, 2019 at 9:42:17 AM UTC+2, Petr Gašparík - AMI Praha a.s. wrote: > > Hi Misagh, > that's

Re: [cas-user] CAS 6.1-RC4 OIDC configuration

2019-08-28 Thread 'Mallory, Erik' via CAS Community
I did find these… cd /etc/ [root@appdev-523 etc]# grep -r cas.example * cas/config/services/RegexRegisteredService-8396761148980578304.json: serviceId: https://cas.example.org:8443/cas/oauth2.0/callbackAuthorize.* cas/config/services/RegexRegisteredService-7398083621929947136.json:

Re: [cas-user] CAS 6.1-RC4 OIDC configuration

2019-08-28 Thread 'Mallory, Erik' via CAS Community
I double checked that I didn’t have an errant file somewhere that would override the config. I un jared the cas.war file and grepped for cas.example.org JIC. All settings are loaded from the location below. CAS is running with embedded tomcat and is started by systemd. # The configuration

[cas-user] Re: CAS keeps generating RegexRegisteredService-********.json files in CAS/Services folder

2019-08-28 Thread Andy Ng
Hi John, Seems to me there are already discussion around this issue here: https://groups.google.com/a/apereo.org/forum/#!searchin/cas-user/json$20start$20service%7Csort:date/cas-user/yD9WXk3n1K8/FV51DLBjAAAJ See if the suggetion from the discussion can help you disable generting these json

Re: [cas-user] Re: CAS SSO with OpenID Connect and CAS protocol

2019-08-28 Thread Gandhi Pullalarevu
I'm able to make cas work with single login for both CAS and OAuth protocols with the steps mentioned. I see that this happens via TGC Cookie, which is created when the user logs in for the first time. Thanks a lot once again Andy. On Tue, Aug 20, 2019 at 10:10 AM Gandhi wrote: > Thanks a lot

[cas-user] Re: Apereo CAS Deployer Survey: 2019 Edition

2019-08-28 Thread Misagh Moayyed
Final reminder; The survey will close in less than a week. Thank you to all who have submitted answers so far. If you have not participated in the survey, please consider doing so by next Monday EOD. If you do need more time, please reach out to me directly. On Monday, July 15, 2019 at

Re: [cas-user] CAS 6.1-RC4 OIDC configuration

2019-08-28 Thread Misagh Moayyed
Are you certain your configuration values are not overridden by something else? > On Aug 28, 2019, at 1:30 AM, 'Mallory, Erik' via CAS Community > wrote: > > Yes. > # OpenID Authentication > cas.authn.oidc.issuer=http://cas-dev.wichita.edu/cas/oidc > > #

Re: [cas-user] SPNEGO : Retrieve Attribute from AD?

2019-08-28 Thread Sparadrus (FR)
Merci Fabrice ! I’ll test this when I have some time. In fact, it seemed to me appropriate to declare an Attribute Repository for the recovery of attributes by Kerberos. On the other hand, I have 3 Active Directory domains connected in triangle (federating/admin domain with 2 domains

Re: [cas-user] Seamless login

2019-08-28 Thread Petr Gašparík - AMI Praha a . s .
Hi Misagh, that's what I don't know for sure. Can be REST used for issuing TGT for different user than authenticated one? Like "sudo make TGT for userX" ? I studied wiki, I think sudoer needs to know user's password. -- s pozdravem *Petr Gašparík* solution architect gsm: [+420] 603 523 860