Howard,

> So generally if foo.com <http://foo.com/> redirects to CAS with 
> service=foo.com <http://foo.com/>, and then gets back a service ticket, and 
> then redirects the browser with that ticket= to bar.com <http://bar.com/>, 
> then when bar.com <http://bar.com/> tries to validate the ticket with 
> validate?service=bar.com <http://bar.com/> the request is rejected because 
> “bar.com <http://bar.com/>” does not match the service ”foo.com 
> <http://foo.com/>” presented when the ticket was issued.


This is helpful.  If I were to reword this, the protocol allows the CAS server 
to associate the ticket with an intended service, but there’s nothing for a CAS 
client to check, and this is in the protocol rather than the payload.  Is that 
correct?

It’s interesting to me since SAML took the exact opposite approach, relying on 
the service to discard any inappropriate assertions.  I haven’t really thought 
through pros and cons.

Thanks for your help,
Nate.

-- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/.

Reply via email to