CAS and SSL
webzo
webzo2000 at yahoo.com
Tue May 1 18:57:10 EDT 2007
Scott,
I am using using the JA-SIG CAS Java for client, not the Yale CAS client. Any ideas on what needs to change for that? From my investigation before I saw your response, I changed the following-
1. CASFilter- removed check for https
2. SecureURL.retrieve( )- removed check for https.
After this, I can login without any issues. Does this sound right? Do I have change anything else?
Thanks.
----- Original Message ----
From: Scott Battaglia <scott.battaglia at gmail.com>
To: Yale CAS mailing list <cas at tp.its.yale.edu>
Sent: Tuesday, May 1, 2007 2:26:36 PM
Subject: Re: CAS and SSL
You can deploy the CAS Server without SSL and it will function fine. The only change would be:
1. In the cas-servlet.xml, the two cookie generators need the "secure" property set to false.
2. If you plan on doing proxy callback to clients without SSL, the HttpBasedServiceCredentialsAuthenticationHandler needs to be configured to allow non-https urls. Its a property on the handler.
I believe that is everything for the server. On the clients, it depends on the client. For the Yale CAS Client, there is a hardcoded check for https that would need to be removed.
-Scott
On 5/1/07, webzo <webzo2000 at yahoo.com> wrote:
I have some questions about CAS and SSL.
What parts of CAS actually require SSL? The client (CASFilter) seems to require that the validateUrl callback be "https" rather than "http". How about the server side? What parts there require SSL be used? The reason for these questions are that I am trying to find out if there is a way to use CAS without installing certificates. I know, Scott, Andrew and others on this forum have stated many times that CAS should be used with SSL. Still, I am in a situation where I need to use CAS with out any certificates being installed (because it is going to be hard to install it on the system in question).
I saw a message ( http://tp.its.yale.edu/pipermail/cas/2006-April/002652.html) where the implication seemed to be that SSL can be disabled with code changes. Can someone (Scott?) please provide more information on how to do this?
Thanks
Ahhh...imagining that irresistible "new car" smell?
Check out new cars at Yahoo! Autos.
_______________________________________________
Yale CAS mailing list
cas at tp.its.yale.edu
http://tp.its.yale.edu/mailman/listinfo/cas
--
-Scott Battaglia
LinkedIn: http://www.linkedin.com/in/scottbattaglia
_______________________________________________
Yale CAS mailing list
cas at tp.its.yale.edu
http://tp.its.yale.edu/mailman/listinfo/cas
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://tp.its.yale.edu/pipermail/cas/attachments/20070501/62fa3c3e/attachment.html
More information about the cas
mailing list