Re: [cas-user] Service Access Strategy help needed

2020-07-03 Thread Ray Bon
Emilian, It opens a vector for phishing, etc, putting your users at risk. Ray On Thu, 2020-07-02 at 23:24 -0700, Emilian Mitocariu wrote: Ok, I'll take your answers into consideration. I agree adding new json entries isn't that hard as we won't have new services everyday, it's just that I was

[cas-user] Re: Multiple entries when using JPA with u2f resgitration

2020-07-03 Thread John Bond
Just a quick update that i tested this with 6.2.0 (original test with 6.1.5) and saw the same behaviour On Wednesday, July 1, 2020 at 12:20:18 PM UTC+2 John Bond wrote: > > cas.authn.mfa.u2f.crypto.signing.key=***REDACTED*** > there is also:

Re: [cas-user] Service Access Strategy help needed

2020-07-03 Thread Emilian Mitocariu
Ok, I'll take your answers into consideration. I agree adding new json entries isn't that hard as we won't have new services everyday, it's just that I was asked to look into this strategy among others. Also, I know having the serviceid like that is going to allow any application to