Hi,

We currently do this (kind of) using CAS 4.0.x, we've verified it with 4.1.x 
but not upgraded yet.

I'm wondering what happens in the case that the application is accessed from
1) browser that is not configured to trust the CAS server

You can make the server fall back to the login form i SPNEGO-negotiation fails.

2) a non-windows client

Same as above. SPNEGO is not strictly Windows-only, you can make it work on 
other clients as well.

In these cases, does the authentication simply fail or is there a fail-over 
option to a login form?
Would such a fall-back login form authentication be handled through AD over the 
Kerberos protocols or would it require an entirely separate 
AuthenticationHandler such as LdapAuthenticationHandler?

Your choice, but you need another authenticator for fall back authentication. 
We currently use a JAAS authenticator with Kerberos, but we (and likely you) 
still need to look up user attributes with LDAP, so you could just as well use 
ldap authentication. However, since you need a separate principal resolver for 
SPNEGO, you want to separate authentication and attribute resolving even if you 
use LDAP for authentication and theoretically could look up the attributes at 
the same time.

One thing to keep in mind if you enable SPNEGO is that Windows users will not 
be able to log out the same way as before or other users.

Regards,
/Fredrik

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to