[cas-user] Certificate with difference host problem!

2010-04-06 Thread Chatree Srichart
Hi all, I am implementing the CAS client in host A to call CAS server in host B. I got certificate from host B (server.cert) with common name (CN), "localhost", but the host B is xxx.yyy.com . As I create keystore from the certificate I got from host B, I can not call CAS server in host B and get

Re: [cas-user] SSL Error

2010-04-06 Thread Scott Battaglia
I don't see any SSL errors in the catalina.out Did I miss it? On Tue, Apr 6, 2010 at 5:05 PM, Jeff Chapin wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Is that related to the SSL issue? That error started when we began > logging to the database, and I have not had time to addres

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enfor

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: [cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

[cas-user] Re: Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread hajo . passon
Hallo, ich bin zurzeit im Urlaub und deshalb nicht via Mail erreichbar. Wenden Sie sich in dringenden Fällen bitte per Mail (i...@form4.de) oder telefonisch (030/27 87 84-0) an meine Kollegen. Ab dem 12.04.2010 können Sie mich wieder im Büro erreichen. Viele Grüße Hajo Passon -- You are curr

Re: [cas-user] Enabling LDAP Password Policy Enforcement

2010-04-06 Thread Jeff Chapin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I know I am grave digging, but I am working on getting this module working still. I have gotten LdapBind working, and I have the password working information getting initialized: This is from catalina.out: 2010-04-06 16:42:18,580 INFO [org.jasig.cas

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
And just so Scott stops hatin' on MySQL, here is the associated Oracle dump: SEVERE: A web application appears to have started a thread named [pool-1-thread-1] but has failed to stop it. This is very likely to create a memory leak. Apr 6, 2010 2:19:55 PM org.apache.catalina.loader.WebappClassLoade

[cas-user] SSO "exit your browser" tags, pamphlets, documentation?

2010-04-06 Thread Cary, Kim
As we're closing in on putting our portal behind CAS, I'd like to re-visit this subject with the list: What do you do to remind your users to exit their browser on public computers? We're thinking of printing some table tents for the labs & public access areas, or maybe laminated stick

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
This is also interesting, the log after a redeploy: Apr 6, 2010 2:04:05 PM org.apache.catalina.loader.WebappClassLoader clearReferencesJdbc SEVERE: A web application registered the JBDC driver [com.mysql.jdbc.Driver] but failed to unregister it when the web application was stopped. To prevent a me

Re: [cas-user] SSL Error

2010-04-06 Thread Jeff Chapin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Is that related to the SSL issue? That error started when we began logging to the database, and I have not had time to address thant one -- it is believed that the SSL error is much more critical. Jeff Scott Battaglia wrote: > The error is this: > Ex

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
Switched back to Tomcat 6 for a bit and found some more interesting stuff in catalina.out: log4j:ERROR Attempted to append to closed appender named [fileAppender]. Apr 6, 2010 1:47:13 PM org.apache.catalina.loader.WebappClassLoader clearReferencesJdbc SEVERE: A web application registered the JBDC

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Scott Battaglia
Based on your stack trace and the fact that Bamboo had the problem, I'd say its not specifically related to Inspektr. At the moment, I don't know the exact cause though :-) Looks like a classpath issue with logging or something though. On Tue, Apr 6, 2010 at 4:21 PM, Patrick Berry wrote: > >

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
On Tue, Apr 6, 2010 at 12:59 PM, Patrick Berry wrote: > > > On Tue, Apr 6, 2010 at 11:43 AM, Scott Battaglia < > scott.battag...@gmail.com> wrote: > >> Are you putting your pooling jar in Tomcat's common, or with the >> application? >> >> > With the application via a maven dependency, in both the

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
On Tue, Apr 6, 2010 at 11:43 AM, Scott Battaglia wrote: > Are you putting your pooling jar in Tomcat's common, or with the > application? > > With the application via a maven dependency, in both the dbcp and c3p0 cases. I'll try breaking them out and running through it again. -- You are current

Re: [cas-user] Changing the location of log4j.properties

2010-04-06 Thread Jeff Chapin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The method I did, which did not use an XML configuration file, did not require editing pom.xml at all. The snippit I gave was the only change - -- in addition to moving the log4j.properties file to a new location -- which existed prior to redeploying o

Re: [cas-user] leading and trailing backslashes on login

2010-04-06 Thread Scott Battaglia
Its actually Sun's JVM (JNDI) that's removing it. If its an issue for you, you can provide a custom validator that checks for that, or write a custom CredentialsToPrincipalResolver to remove them. Cheers, Scott On Tue, Apr 6, 2010 at 2:01 PM, Raymond D Walker wrote: > With CAS 3.3.5 it appear

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Scott Battaglia
Are you putting your pooling jar in Tomcat's common, or with the application? On Tue, Apr 6, 2010 at 2:02 PM, Patrick Berry wrote: > Negative. I just switched to the Apache DBCP and I'm seeing the same > issue. This could be an Oracle bug. I'll try mysql and if it's still a > problem I guess

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
Okay, same problem with MySQL. Here is another interesting snippet from catalina.out: Apr 6, 2010 11:19:25 AM org.apache.coyote.http11.Http11BaseProtocol pause INFO: Pausing Coyote HTTP/1.1 on http-8080 Apr 6, 2010 11:19:25 AM org.apache.coyote.http11.Http11BaseProtocol pause INFO: Pausing Coyote

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
Negative. I just switched to the Apache DBCP and I'm seeing the same issue. This could be an Oracle bug. I'll try mysql and if it's still a problem I guess I'll create a JIRA issue. Pat On Tue, Apr 6, 2010 at 10:40 AM, Scott Battaglia wrote: > I wonder if its a bug in c3p0? > > Cheers, > Scot

[cas-user] leading and trailing backslashes on login

2010-04-06 Thread Raymond D Walker
With CAS 3.3.5 it appears that when adding leading and/or trailing backslashes creates some interesting behavior. Say the user enters "\bob\" instead of his normal login "bob". The user "\bob\" does not exist in the systems we are binding against, while "bob" does. When CAS binds against SunOn

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
I suppose I could test out another pooling library. I'll give that a shot. On Tue, Apr 6, 2010 at 10:40 AM, Scott Battaglia wrote: > I wonder if its a bug in c3p0? > > Cheers, > Scott > > > > On Tue, Apr 6, 2010 at 1:16 PM, Patrick Berry wrote: > >> Well, at least it isn't just CAS >> >> http:/

Re: [cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Scott Battaglia
I wonder if its a bug in c3p0? Cheers, Scott On Tue, Apr 6, 2010 at 1:16 PM, Patrick Berry wrote: > Well, at least it isn't just CAS > > http://jira.atlassian.com/browse/BAM-2770 > > > On Tue, Apr 6, 2010 at 10:09 AM, Patrick Berry wrote: > >> And of course I forget the one snippet from cata

Re:[cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
Well, at least it isn't just CAS http://jira.atlassian.com/browse/BAM-2770 On Tue, Apr 6, 2010 at 10:09 AM, Patrick Berry wrote: > And of course I forget the one snippet from catalina.out: > > Exception in thread "Timer-0" java.lang.NullPointerException > at > com.mchange.v2.log.log4j.Log4jMLo

[cas-user] Fail to pass non-English custom attribute

2010-04-06 Thread Bill Li
I need pass a full name from CAS to my apps. After checking several documents, my casServiceValidationSuccess.jsp was changed to: --- Start --- *<%@ page pageEncoding="UTF-8"%>* <%@ page session="false"%><%@ taglib prefix="c" uri="http://java.sun.com/jsp/jstl/core"%><%@ taglib uri="http://

Re:[cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
And of course I forget the one snippet from catalina.out: Exception in thread "Timer-0" java.lang.NullPointerException at com.mchange.v2.log.log4j.Log4jMLog$Log4jMLogger.isLoggable(Log4jMLog.java:257) at com.mchange.v2.resourcepool.BasicResourcePool$CullTask.run(BasicResourcePool.java:1934) at ja

[cas-user] 3.4.2 audit logging to a data source causing tomcat issues

2010-04-06 Thread Patrick Berry
I'm fairly certain this is a configuration problem on my end, but I'm at a loss on what exactly I'm screwing up. Once I enable auditing to the dataSource, tomcat will not shutdown cleanly. As soon as I go back to console auditing, everything is cool. Any ideas (besides giving up on database audi

Re: [cas-user] Setting additional domain-wide cookie on CAS login

2010-04-06 Thread John Thiltges
On 01/22/2010 10:35 PM, Scott Battaglia wrote: > Your cleanest way is to probably just add another action that > accomplishes what you want. > Cheers, > Scott > > On Fri, Jan 22, 2010 at 6:26 PM, John Thiltges > wrote: > > Hi all, > > I'm trying to extend CAS to

Re: [cas-user] Changing the location of log4j.properties

2010-04-06 Thread Patrick Berry
On Thu, Apr 1, 2010 at 12:28 PM, Marvin Addison wrote: > > I would like to place the config file log4j.properties outside the war > > file > > You'll want something like the following in your web.xml: > > >log4jConfigLocation >file://${cas.home}/log4j.xml > > > where cas.home is a prop

Re: [cas-user] SSL Error

2010-04-06 Thread Jeff Chapin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Actually, late last night I stumbled on something that may be related, and I am following up on that. It appears that the SSL certificate was improperly issued. It is a wildcard with the following alternative domains: server.domain.edu.domain.edu and