"I understand you can make CAS use ADFS for backend authentication, or
vise-a-versa, but i'm not sure that's exactly what i'm asking here... or
is it?"
Yes, that is what you are asking. Otherwise they are two independent
applications that know nothing about the state of one another, even
though both are your systems. If you are starting from the beginning,
you may want to examine the support status for ADFS. MS is putting most
of their effort into Azure, so you may be better off starting there.
You should also consider what protocols are needed, and what external
systems you need to federate with. You said "developers that aren't
agreeing", that should be a protocol level concern. CAS can handle most
of the protocols, including the odd WS-Fed protocol that ADFS provides.
So, with an IdP that can support multiple different protocols, it
shouldn't matter what IdP product you are running to support developers.
That said, I'm a developer that operates and configures our IdPs. So
that may be of concern.
On 10/21/21 11:26 AM, Nathan Lewan wrote:
hello all!
I have been reading through the CAS/ADFS configurations, and feel I
somewhat get it, but I wanted to confirm something:
Important not to scenario: Both ADFS and CAS are aware of who *USER-A* is.
Is it possible if *USER-A* logs into an *ADFS* application, and then
tries to log into a *CAS* application, *CAS* can check to see if they
are already authenticated with *ADFS* and if so, let them in, SSO-style?
and on the flip side:
Is it possible if *USER-A* logs into a *CAS* application, and then
tries to log into an *ADFS* application, *ADFS* can check to see if
they are already authenticated with *CAS* and if so, let them in,
SSO-style?
I have developers that aren't agreeing on one system or the other for
SSO, and am looking into any possibility of having the two share info.
I understand you can make CAS use ADFS for backend authentication, or
vise-a-versa, but i'm not sure that's exactly what i'm asking here...
or is it?
thanks for any clarifications!
--
- Website: https://apereo.github.io/cas <https://apereo.github.io/cas>
- Gitter Chatroom: https://gitter.im/apereo/cas
<https://gitter.im/apereo/cas>
- List Guidelines: https://goo.gl/1VRrw7 <https://goo.gl/1VRrw7>
- Contributions: https://goo.gl/mh7qDG <https://goo.gl/mh7qDG>
---
You received this message because you are subscribed to the Google
Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send
an email to [email protected]
<mailto:[email protected]>.
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/417d82f2-b60d-4173-a8e6-5fc7ce079613n%40apereo.org
<https://groups.google.com/a/apereo.org/d/msgid/cas-user/417d82f2-b60d-4173-a8e6-5fc7ce079613n%40apereo.org?utm_medium=email&utm_source=footer>.
--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
---
You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/a/apereo.org/d/msgid/cas-user/d0795478-2241-c5d8-8bfd-a4e96f3e3d8b%40ndsu.edu.