Thanks for this information.  It is very helpful in clearing up what might 
lay ahead if we pursue SPNEGO support.

When you say that you can make SPEGO work on other clients as well, do you 
mean other clients can be configured to be a member of the active directory 
domain and provide same the transparent authentication experience?

If for some reason we didn't need to look up attributes from LDAP at all, 
could we use #{ null } as the principal resolver with both SPNEGO and the 
fall-back JAAS via Kerberos?  

Thanks for the reminder about logout.  I was wondering that myself.  Is 
there any information provided back to the application to indicate which 
method was used for authentication?  Something that could trigger the 
display of a logout button only when the fall-back form-based 
authentication was utilized?

Thanks.

On Monday, January 25, 2016 at 3:11:14 PM UTC-5, Fredrik Jönsson wrote:

> Hi, 
>
> We currently do this (kind of) using CAS 4.0.x, we've verified it with 
> 4.1.x but not upgraded yet.
>
> I'm wondering what happens in the case that the application is accessed 
> from 
>
> 1) browser that is not configured to trust the CAS server
>
>
> You can make the server fall back to the login form i SPNEGO-negotiation 
> fails.
>
> 2) a non-windows client
>
>
> Same as above. SPNEGO is not strictly Windows-only, you can make it work 
> on other clients as well. 
>
> In these cases, does the authentication simply fail or is there a 
> fail-over option to a login form?
> Would such a fall-back login form authentication be handled through AD 
> over the Kerberos protocols or would it require an entirely separate 
> AuthenticationHandler such as LdapAuthenticationHandler?
>
>
> Your choice, but you need another authenticator for fall back 
> authentication. We currently use a JAAS authenticator with Kerberos, but we 
> (and likely you) still need to look up user attributes with LDAP, so you 
> could just as well use ldap authentication. However, since you need a 
> separate principal resolver for SPNEGO, you want to separate authentication 
> and attribute resolving even if you use LDAP for authentication and 
> theoretically could look up the attributes at the same time.
>
> One thing to keep in mind if you enable SPNEGO is that Windows users will 
> not be able to log out the same way as before or other users.
>
> Regards,
> /Fredrik
>

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to