Hi, We currently do this (kind of) using CAS 4.0.x, we've verified it with 4.1.x but not upgraded yet.
I'm wondering what happens in the case that the application is accessed from 1) browser that is not configured to trust the CAS server You can make the server fall back to the login form i SPNEGO-negotiation fails. 2) a non-windows client Same as above. SPNEGO is not strictly Windows-only, you can make it work on other clients as well. In these cases, does the authentication simply fail or is there a fail-over option to a login form? Would such a fall-back login form authentication be handled through AD over the Kerberos protocols or would it require an entirely separate AuthenticationHandler such as LdapAuthenticationHandler? Your choice, but you need another authenticator for fall back authentication. We currently use a JAAS authenticator with Kerberos, but we (and likely you) still need to look up user attributes with LDAP, so you could just as well use ldap authentication. However, since you need a separate principal resolver for SPNEGO, you want to separate authentication and attribute resolving even if you use LDAP for authentication and theoretically could look up the attributes at the same time. One thing to keep in mind if you enable SPNEGO is that Windows users will not be able to log out the same way as before or other users. Regards, /Fredrik -- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.
