Re: [cas-user] 7.0.8 vs 7.1.0 pac4j saml delegatedClient

2024-09-23 Thread 'Jonathon Taylor' via CAS Community
eceived this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.goog

Re: [cas-user] 7.0.8 vs 7.1.0 pac4j saml delegatedClient

2024-09-23 Thread 'Jonathon Taylor' via CAS Community
vider-metadata-path new: cas.authn.pac4j.saml[0].metadata.identity-provider-metadata-path cas.authn.pac4j.saml[0].principal-id-attribute cas.authn.pac4j.saml[0].metadata.service-provider.file-system.location On Mon, Sep 23, 2024 at 1:15 PM Jonathon Taylor wrote: > Hi Michael, > > Wit

Re: [cas-user] Combination of Delegated Authentication and Surrogate webflow issue in CAS7.0.6

2024-08-23 Thread 'Jonathon Taylor' via CAS Community
ils from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/508148fe-1864-4b15-a50d-ddfc19db74a3n%40apereo.org > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/508148fe-1864-4b

Re: [cas-user] Update tomcat version only

2023-11-06 Thread &#x27;Jonathon Taylor' via CAS Community
> Could not find method overlays() for arguments > [build_ep14vlqtz5elu1r5h6m9cwzsu$_run_closure1$_closure4@43ae0bb2] on > object of type org.gradle.api.internal.initialization.DefaultScriptHandler. > > I'm not sure what I am missing. Any thoughts? > > Thanks! >

Re: [cas-user] CAS 6.6.9 Hazelcast and Ticket Registry errors

2023-11-01 Thread &#x27;Jonathon Taylor' via CAS Community
receiving emails from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/bfd02539-1e72-4e46-98d2-e98969ae8538n%40apereo.org > <https://groups.google.com/a/apereo.org/d/msgid/

Re: [cas-user] Update tomcat version only

2023-10-19 Thread &#x27;Jonathon Taylor' via CAS Community
t; group. > To unsubscribe from this group and stop receiving emails from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/CALmwvcZLU41mQpPub942gXmca2t%3D7eoQau_oPDvKZGaqQNOEiQ%40mail.gmail

Re: [cas-user] Failed to parse address

2023-07-03 Thread Jonathon Taylor
.xx.xx.xx|xxx.xxx.xxx.xx|10.xx.xx.* >>>> >>>> # discoveryProfile used by cas-management, WORKS only by IP address >>>> access. Restrict it. >>>> cas.monitor.endpoints.endpoint.discoveryProfile.access[0]=IP_ADDRESS >>>> >>>> cas.m

Re: [cas-user] Surrogate LDAP configuration issue

2023-04-20 Thread Jonathon Taylor
unsubscribe from this group and stop receiving emails from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/BYAPR18MB2632F99B625E9716AA8F1FC8989D9%40BYAPR18MB2632.namprd18.prod.outlook.com

[cas-user] Use attributes from LDAP repository as input to Groovy repository

2022-11-22 Thread Jonathon Taylor
Hello, I am trying to find a way to use attributes resolved by an LDAP repository and pass them through to a Groovy repository in order to calculate/derive additional attributes. Does anyone know if this is possible? We are running CAS 6.5.8. # LDAP repo cas.authn.attribute-repository.ldap[0].o

Re: [cas-user] Impersonation / Surrogate-Authentication

2022-11-14 Thread Jonathon Taylor
surrogate config? >> >> Thank you, >> Matt >> >> On Monday, October 31, 2022 at 12:51:47 PM UTC-4 Jonathon Taylor wrote: >> >>> Not sure if this helps, but we use impersonation with LDAP and we did >>> not have to use a groovy script. We are on 6.

Re: [cas-user] Impersonation / Surrogate-Authentication

2022-10-31 Thread Jonathon Taylor
. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/6ec4d3ed-8cd8-4e32-96d6-81cb48d9fcecn%40apereo.org > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/6ec4d3ed-8cd8-4e32-96d6-81cb48d9fcecn%40apereo.org?utm_medium=email&utm_sour

Re: [cas-user] Duo Universal Prompt - ready to go?

2022-07-29 Thread Jonathon Taylor
jcuA4X1a9r-Hyw%40mail.gmail.com > <https://groups.google.com/a/apereo.org/d/msgid/cas-user/CAEdMQHWitmLUJfHXMt8Q%2BUWaKi18KXi%3DB%3Dk0jcuA4X1a9r-Hyw%40mail.gmail.com?utm_medium=email&utm_source=footer> > . > -- Jonathon Taylor Information Security Office jonath...@berkeley.edu -

Re: [cas-user] Need endpoint for our LoadBalancers

2022-07-08 Thread Jonathon Taylor
uot; group. > To unsubscribe from this group and stop receiving emails from it, send an > email to cas-user+unsubscr...@apereo.org. > To view this discussion on the web visit > https://groups.google.com/a/apereo.org/d/msgid/cas-user/2d595a8b059e5e77af5b5bb0a55b534cb46da992.c

Re: [cas-user] Diffie-Hellman parameter's size

2021-02-18 Thread Jonathon Taylor
Hi, If you haven't already figured this out, I believe you need to set this as a Java option at CAS startup (-Djdk.tls.ephemeralDHKeySize=2048). We use external Tomcat and have something like this in our systemd unit file, but it should work just as well if you are using just the CAS WAR: Enviro

Re: [cas-user] CAS 6.2.x custom theme problem - theme not changing

2020-10-21 Thread Jonathon Taylor
John, We saw the same behavior and fixed it by disabling Spring thymeleaf caching. Performance testing shows no difference so seems like an OK fix. Try adding this to cas.properties: spring.thymeleaf.cache=false Jonathon On Wed, Oct 21, 2020 at 3:12 PM John Wagenleitner < joh...@mail.fresnosta

[cas-user] Couple of issues with cas-management 6.2.x

2020-09-30 Thread Jonathon Taylor
Throwing these out there in case anyone else has found workarounds for a couple of issues I'm seeing with the cas-management 6.2.x branch. The first issue is that when I edit any existing service that has a delegated provider, the web app's Delegated Authentication tab does not show what is def

[cas-user] Has anyone used CAS + reCAPTCHA v3?

2020-08-21 Thread Jonathon Taylor
We are testing the addition of reCAPTCHA v3 to our CAS instance and it looks promising. Does anyone here have it running in production? If so can you share your experience with false positives and perhaps what score you settled on? We are somewhat concerned with potential false positives with V3

[cas-user] Re: cas-management 6.1 RC4 turn off version control

2020-06-18 Thread Jonathon Taylor
Sorry to also chime in on an old thread but I've just been trying to upgrade to the latest cas-management overlay today and ran into similar issues. For the issue where *existing* services weren't showing up it might be incorrect permissions on the git repo that is automatically generated in t

Re: [cas-user] CAS with LDAP: ObjectGUID retrieved with attribute repository different than with authentication handler

2020-05-13 Thread Jonathon Taylor
s lonely with my issue! > If you are allowed to share any code or patch I would gladly try to apply > it to my instance to see if it fixes this. > > Have a nice day, > > Benjamin > > Le mardi 12 mai 2020 18:53:40 UTC+2, Jonathon Taylor a écrit : >> >> Benjamin, &

Re: [cas-user] CAS with LDAP: ObjectGUID retrieved with attribute repository different than with authentication handler

2020-05-12 Thread Jonathon Taylor
Benjamin, We are running into a similar issue with CAS 5.3.15.1. In our case AD is a secondary attribute repository and we specifically need the objectGUID. We are seeing the same behavior where the GUID is not being converted correctly. We use a third-party vendor for CAS customizations/suppo

Re: [cas-user] CAS 5.3.x Hazelcast Cipher errors when undergoes medium stress - and some a possible cause

2018-11-30 Thread Jonathon Taylor
Andy, We just upgraded our test instance to 5.3.6 today and based on your findings ran a quick JMeter test. We also hit at least one of the exceptions already (and seemingly randomly): javax.crypto.BadPaddingException: Given final block not properly padded. Such issues can arise if a bad key is