> 25 jan. 2016 kl. 21:35 skrev [email protected]:
> 
> Thanks for this information.  It is very helpful in clearing up what might 
> lay ahead if we pursue SPNEGO support.
> 
> When you say that you can make SPEGO work on other clients as well, do you 
> mean other clients can be configured to be a member of the active directory 
> domain and provide same the transparent authentication experience?

Yes, or rather, users on the clients need to be able to get Kerberos tickets, 
the clients do not really need to be a member of the AD in that sense. Mac 
clients are actually possible to make members of the AD, but it is not 
necessary. What you have to do is configure Kerberos on the clients and use the 
AD controllers as key distribution centers (KDC). You can do this with Linux 
and Mac clients and many others.

Once that works, which may take some understanding of Kerberos and depend a bit 
on your setup, you can configure browsers to use SPNEGO for your server. I’ve 
successfully tried at least Firefox, Safari and Chrome.

> If for some reason we didn't need to look up attributes from LDAP at all, 
> could we use #{ null } as the principal resolver with both SPNEGO and the 
> fall-back JAAS via Kerberos? 

I’d think so, but don’t really know.

> Thanks for the reminder about logout.  I was wondering that myself.  Is there 
> any information provided back to the application to indicate which method was 
> used for authentication?  Something that could trigger the display of a 
> logout button only when the fall-back form-based authentication was utilised?

There is no notion of how authentication was made in the CAS protocol. You are 
actually logged out, it works in that sense. It’s just that you will get 
automatically logged in again which may seem confusing to users used to some 
other behaviour.

This is one of the reasons why we’ve not deployed SPNEGO support openly to all 
users yet. We’ve ”hidden” it, detecting a special string in the user-agent, for 
test purposes that a very limited number of users is trying out. I’m myself one 
of the persons using it.

Regards,
/Fredrik

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to