Hi, I setup jasig-cas-4.2.6 and I can login successful in cas-side but in my client I get login successful but phpCAS::getAttributes() no return my attribute such as mail and givenName
deployerConfigContext.xml is: <?xml version="1.0" encoding="UTF-8"?> <beans xmlns="http://www.springframework.org/schema/beans" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:context="http://www.springframework.org/schema/context" xmlns:p="http://www.springframework.org/schema/p" xmlns:c="http://www.springframework.org/schema/c" xmlns:aop="http://www.springframework.org/schema/aop" xmlns:tx="http://www.springframework.org/schema/tx" xmlns:util="http://www.springframework.org/schema/util" xmlns:sec="http://www.springframework.org/schema/security" xmlns:ldaptive="http://www.ldaptive.org/schema/spring-ext" xsi:schemaLocation="http://www.springframework.org/schema/beans http://www.springframework.org/schema/beans/spring-beans.xsd http://www.springframework.org/schema/tx http://www.springframework.org/schema/tx/spring-tx.xsd http://www.springframework.org/schema/aop http://www.springframework.org/schema/aop/spring-aop.xsd http://www.springframework.org/schema/context http://www.springframework.org/schema/context/spring-context.xsd http://www.springframework.org/schema/security http://www.springframework.org/schema/security/spring-security.xsd http://www.springframework.org/schema/util http://www.springframework.org/schema/util/spring-util.xsd http://www.ldaptive.org/schema/spring-ext http://www.ldaptive.org/schema/spring-ext.xsd"> <bean id="ldapAuthenticationHandler" class="org.jasig.cas.authentication.LdapAuthenticationHandler" c:authenticator-ref="authenticator"> <property name="principalAttributeMap"> <map> <entry key="givenName" value="firstName"/> <entry key="mail" value="email"/> </map> </property> </bean> <util:map id="authenticationHandlersResolvers"> <entry key-ref="proxyAuthenticationHandler" value-ref="proxyPrincipalResolver" /> <entry key-ref="ldapAuthenticationHandler" value="#{null}" /> </util:map> <util:list id="authenticationMetadataPopulators"> <ref bean="successfulHandlerMetaDataPopulator" /> <ref bean="rememberMeAuthenticationMetaDataPopulator" /> </util:list> <alias name="acceptUsersAuthenticationHandler" alias="primaryAuthenticationHandler" /> <alias name="personDirectoryPrincipalResolver" alias="primaryPrincipalResolver" /> <bean id="attributeRepository" class="org.jasig.services.persondir.support.NamedStubPersonAttributeDao" p:backingMap-ref="attrRepoBackingMap" /> <util:map id="attrRepoBackingMap"> <entry key="givenName" value="firstName"/> <entry key="mail" value="email"/> <entry> <key><value>memberOf</value></key> <list> <value>faculty</value> <value>staff</value> <value>org</value> </list> </entry> </util:map> <alias name="serviceThemeResolver" alias="themeResolver" /> <alias name="jsonServiceRegistryDao" alias="serviceRegistryDao" /> <alias name="defaultTicketRegistry" alias="ticketRegistry" /> <alias name="ticketGrantingTicketExpirationPolicy" alias="grantingTicketExpirationPolicy" /> <alias name="multiTimeUseOrTimeoutExpirationPolicy" alias="serviceTicketExpirationPolicy" /> <alias name="anyAuthenticationPolicy" alias="authenticationPolicy" /> <alias name="acceptAnyAuthenticationPolicyFactory" alias="authenticationPolicyFactory" /> <bean id="auditTrailManager" class="org.jasig.inspektr.audit.support.Slf4jLoggingAuditTrailManager" p:entrySeparator="${cas.audit.singleline.separator:|}" p:useSingleLine="${cas.audit.singleline:false}"/> <alias name="neverThrottle" alias="authenticationThrottle" /> <util:list id="monitorsList"> <ref bean="memoryMonitor" /> <ref bean="sessionMonitor" /> </util:list> <alias name="defaultPrincipalFactory" alias="principalFactory" /> <alias name="defaultAuthenticationTransactionManager" alias="authenticationTransactionManager" /> <alias name="defaultPrincipalElectionStrategy" alias="principalElectionStrategy" /> <alias name="tgcCipherExecutor" alias="defaultCookieCipherExecutor" /> <bean id="serviceRegistryDao" class="org.jasig.cas.services.InMemoryServiceRegistryDaoImpl" p:registeredServices-ref="registeredServicesList" /> <util:list id="registeredServicesList"> <bean class="org.jasig.cas.services.RegexRegisteredService" p:id="1" p:name="sso" p:serviceId="^(https?|imaps?|http?)://.*" p:description="sso cas" p:evaluationOrder="0" > <property name="attributeReleasePolicy"> <bean class="org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy"> <property name="allowedAttributes"> <list> <value>mail</value> <value>givenName</value> </list> </property> </bean> </property> </bean> </util:list> <ldaptive:ad-authenticator id="authenticator" ldapUrl="xxxx" baseDn="xxxxxx" userFilter="xx" bindDn="xxxxx" bindCredential="xxxxxxxx" connectTimeout="5000" useStartTLS="false" blockWaitTime="3000" maxPoolSize="10" allowMultipleDns="false" minPoolSize="1" validateOnCheckOut="false" validatePeriodically="true" validatePeriod="300" idleTime="600" prunePeriod="300" failFastInitialize="false" subtreeSearch="true" useSSL="false" /> </beans> does need i change HTTPSandIMAPS-10000001.json file for ReturnAllowedAttributeReleasePolicy?? is any help? thanks in advaned On Thursday, March 3, 2016 at 2:58:40 PM UTC+3:30, Misagh Moayyed wrote: > > Your configuration is not clear on what you intend to do. By my reading, > looks like the problem is you are getting static attributes rather than > what’s defined in LDAP? If so, it’s because of this: > > <entry key-ref="ldapAuthenticationHandler" > value-ref="primaryPrincipalResolver" /> > > What you’re saying there is, authenticate via ldap, then retrieve my > attributes defined by the resolver (which are static because this resolver > is connected to your static source). Your other handler right below it is > never involved, because this one simply succeeds. > > So: > > Turn this: > <entry key-ref="ldapAuthenticationHandler" > value-ref="primaryPrincipalResolver" /> > <entry key-ref="primaryAuthenticationHandler" value="#{null}" /> > > Into this: > <entry key-ref="ldapAuthenticationHandler" value="#{null}" /> > > Now, if you wish to get attributes from LDAP AND from a static config that > is also possible. But not this way. > > Note that “principalAttributeMap” of your handler can be a list too. If > you don’t have any special mappings, you can turn that map into a list. > Easier to read. > > Misagh > > From: David Lee <[email protected]> <javascript:> > Reply: David Lee <[email protected]> <javascript:> > Date: March 3, 2016 at 7:11:26 AM > To: CAS Community <[email protected]> <javascript:> > CC: [email protected] <javascript:> <[email protected]> > <javascript:>, [email protected] <javascript:> <[email protected]> > <javascript:> > Subject: Re: [cas-user] principal attributes from ldap in CAS 4.2 > > I'm struggling with the same problem.. > > <!-- See > http://jasig.github.io/cas/development/installation/LDAP-Authentication.html > --> > > <bean id="ldapAuthenticationHandler" > class="org.jasig.cas.authentication.LdapAuthenticationHandler" > p:principalIdAttribute="mail"> > > <constructor-arg ref="authenticator" /> > > <property name="principalAttributeMap"> > > <map> > > <!-- > > | This map provides a simple attribute > resolution mechanism. > > | Keys are LDAP attribute names, values > are CAS attribute names. > > | This facility can be used instead or > in addition to PrincipalResolver > > | components. > > --> > > <entry key="member" value="memberOf" /> > > <entry key="eduPersonAffiliation" value= > "affiliation" /> > > <entry key="mail" value="mail" /> > > <entry key="displayName" value= > "displayName" /> > > <entry key="cn" value="cn" /> > > <entry key="sn" value="sn" /> > > <entry key="entryUUID" value="entryUUID" > /> > > </map> > > </property> > > </bean> > > > Like above I added additional entries I would like to retrieve from LDAP, > and it works, but looks like the attributes generated by SimplePrinciple > was overwritten by the below, > > > > <bean id="attributeRepository" class= > "org.jasig.services.persondir.support.NamedStubPersonAttributeDao" > > p:backingMap-ref="attrRepoBackingMap" /> > > <util:map id="attrRepoBackingMap"> > > <entry key="uid" value="uid" /> > > <entry key="eduPersonAffiliation" value="eduPersonAffiliation" /> > > <entry key="groupMembership" value="groupMembership" /> > > <entry key="mail" value="mail" /> > > <entry key="cn" value="cn" /> > > <entry key="sn" value="sn" /> > > <entry> > > <key><value>memberOf</value></key> > > <list> > > <value>faculty</value> > > <value>staff</value> > > <value>org</value> > > </list> > > </entry> > > </util:map> > > > So when I tried to get the attributes in the CAS client as below, > > > AttributePrincipal principal = > (AttributePrincipal)request.getUserPrincipal(); > > > > Map attributes = principal.getAttributes(); > > > > Iterator attributeNames = attributes.keySet().iterator(); > > > It populates static entries defined in the backing map. > > > For your reference, I followed all the posts in this question thread and > did as below, > > > <util:map id="authenticationHandlersResolvers"> > > <entry key-ref="proxyAuthenticationHandler" > value-ref="proxyPrincipalResolver" > /> > > <entry key-ref="ldapAuthenticationHandler" > value-ref="primaryPrincipalResolver" > /> > > <entry key-ref="primaryAuthenticationHandler" value="#{null}" /> > > </util:map> > > > cas.principal.resolver.persondir.return.null=false // in cas.properties I > did this. > > And added the below to the service JSON file > ... > > "attributeReleasePolicy" : { > > "@class" : > "org.jasig.cas.services.ReturnAllowedAttributeReleasePolicy", > > "principalAttributesRepository" : { > > "@class" : > "org.jasig.cas.authentication.principal.DefaultPrincipalAttributesRepository" > > }, > > "authorizedToReleaseCredentialPassword" : false, > > "authorizedToReleaseProxyGrantingTicket" : false, > > "allowedAttributes" : [ "java.util.ArrayList", [ "cn", "mail", "sn" ] > ] > > }, > ... > > But it still retrieves the mapped static entries... > > Could you please share how you could get the attributes in the map in > > <bean id="ldapAuthenticationHandler" > class="org.jasig.cas.authentication.LdapAuthenticationHandler" > p:principalIdAttribute="mail"> > > <constructor-arg ref="authenticator" /> > > <property name="principalAttributeMap"> > > <map> > > <!-- > > | This map provides a simple attribute > resolution mechanism. > > | Keys are LDAP attribute names, values > are CAS attribute names. > > | This facility can be used instead or > in addition to PrincipalResolver > > | components. > > --> > > <entry key="member" value="memberOf" /> > > <entry key="eduPersonAffiliation" value= > "affiliation" /> > > <entry key="mail" value="mail" /> > > <entry key="displayName" value= > "displayName" /> > > <entry key="cn" value="cn" /> > > <entry key="sn" value="sn" /> > > <entry key="entryUUID" value="entryUUID" > /> > > </map> > > </property> > > </bean> > > > Thanks in advance. > > > On Monday, February 8, 2016 at 6:34:55 PM UTC+9, Mikko Tuumanen wrote: >> >> Study >>> http://jasig.github.io/cas/4.2.x/installation/Configuring-Principal-Resolution.html#principalresolver-vs-authenticationhandler >>> >>> >>> >> >> <entry key-ref="primaryAuthenticationHandler" value-ref="#{null}" /> >> >> causes >> >> Caused by: org.springframework.beans.factory.BeanCreationException: Error >> creating >> bean with name 'authenticationHandlersResolvers': Cannot resolve >> reference to bean '#{null}' while setting bean property 'sourceMap' with >> key [<primaryAuthenticationHandler>]; nested exception is org. >> springframework.beans.factory.NoSuchBeanDefinitionException: No bean >> named 'null' is defined >> >> >> >> -- > You received this message because you are subscribed to the Google Groups > "CAS Community" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to [email protected] <javascript:>. > Visit this group at https://groups.google.com/a/apereo.org/group/cas-user/ > . > > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/3d44741a-7c8b-4154-99c8-d1e768ca38f3%40apereo.org.
