Just to follow up on this for others who stumble on this issue. I have confirmed that, at the moment, the Duo Proxy's HTTP feature does not support SSL. So without an option to disable SSL on CAS, it seems we will have to open our CAS servers for outbound 443 to the Internet.
On Thursday, August 17, 2017 at 10:33:30 AM UTC-4, Jim Mulvey wrote: > > Hello, > > I am configuring CAS 5.1.2 with Duo. I'd prefer not to open my CAS servers > for outbound TCP/443 to the entire Internet, so we've deployed the Duo > Proxy with HTTP configuration > <https://duo.com/docs/authproxy_reference#http-proxy-section>. I have > defined the Duo Proxy for "cas.authn.mfa.duo[0].duoApiHost=". CAS is > connecting to the host, but unfortunately, it seems the CAS server is > consistently trying to establish an SSL connection to the Duo Proxy. As far > as I can tell, Duo Proxy does not support presenting an SSL-enabled HTTP > endpoint to on-premise servers. > > Has anyone successfully enabled CAS with the Duo Proxy? > > - Jim > -- - CAS gitter chatroom: https://gitter.im/apereo/cas - CAS mailing list guidelines: https://apereo.github.io/cas/Mailing-Lists.html - CAS documentation website: https://apereo.github.io/cas - CAS project website: https://github.com/apereo/cas --- You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected]. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/c493c3d5-d20c-4de4-95e7-2b360c42a08d%40apereo.org.
