Security Review of CAS

Chris Hatton chris.hatton at gmail.com
Thu Dec 6 13:25:23 EST 2007


Hello, everyone,

I am considering adoption of CAS for an third-party integration with our
platform, but we require formal security reviews prior to adoption of any
new means of authentication.  We conducted a brief review internally, but
some concerns were raised (admittedly those concerns could be related
entirely to our own naivety).

Is anyone aware of any formal security reviews that have been conducted on
CAS?  Any relative comparisons of CAS vs. SAML?  CAS vs. Shibboleth?

Any information you could provide is appreciated...

Thanks,
Chris Hatton
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://tp.its.yale.edu/pipermail/cas/attachments/20071206/838e8a58/attachment.html 


More information about the cas mailing list