-          Nothing in CAS “requires” https. As such, there is no MUST. There 
is a very very strong SHOULD. Everything if not all is by default configured 
to assume https. You can turn all that off to use http only, or a 
combination. You should not do that.

-          We recommend you use https for everything. That includes the CAS 
deployment, and all applications registered with CAS, and every callback URL 
and serviceId and logout URL and everything else.

-          Clients that initiate authentication with HTTP remain to be in 
HTTP as long as CAS allows HTTP access for that client. Same goes for HTTPS. 
You cannot change URL protocol in between.



From: [email protected] [mailto:[email protected]] On Behalf Of Jonathan 
Labin
Sent: Tuesday, January 26, 2016 12:59 PM
To: CAS Community <[email protected]>
Subject: [cas-user] Documentation Recommends https



Could someone please help me understand the recommendation in the 
documentation to use Secure Transport 
<http://jasig.github.io/cas/4.1.x/planning/Security-Guide.html#secure-transport-https>
 
?

During development, I've just used https for everything but I'd like to have 
a better understanding of which configuration items really require it.



The page specifically states that "all CAS urls must use HTTPS" and to me 
this means all of the applications should configure their clients with https 
urls to endpoints such as loginURL, serverUrlPrefix, ...

What about the URL provided as a service redirect argument to the /logout 
endpoint?

I might guess this is O.K. to be http.



The documentation also sates https should be used "when the generated 
service ticket is sent back to the application on the 'service' url"

What is the practical implication of this?  Does it mean that all serviceId 
values for registered services must begin with https?

Does this also mean that the client callbackUrl must also be https?



If these must all be https, does this mean that the application will always 
return from authentication in https?

If the client was in http before authentication started, is there any way 
that they can end up in http after authentication?



Thanks

-- 
You received this message because you are subscribed to the Google Groups 
"CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an 
email to [email protected] 
<mailto:[email protected]> .
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to