"I understand you can make CAS use ADFS for backend authentication, or vise-a-versa, but i'm not sure that's exactly what i'm asking here... or is it?"

Yes, that is what you are asking. Otherwise they are two independent applications that know nothing about the state of one another, even though both are your systems. If you are starting from the beginning, you may want to examine the support status for ADFS. MS is putting most of their effort into Azure, so you may be better off starting there.

You should also consider what protocols are needed, and what external systems you need to federate with. You said "developers that aren't agreeing", that should be a protocol level concern. CAS can handle most of the protocols, including the odd WS-Fed protocol that ADFS provides. So, with an IdP that can support multiple different protocols, it shouldn't matter what IdP product you are running to support developers. That said, I'm a developer that operates and configures our IdPs. So that may be of concern.

On 10/21/21 11:26 AM, Nathan Lewan wrote:
hello all!

I have been reading through the CAS/ADFS configurations, and feel I somewhat get it, but I wanted to confirm something:

Important not to scenario: Both ADFS and CAS are aware of who *USER-A* is.

Is it possible if *USER-A* logs into an *ADFS* application, and then tries to log into a *CAS* application, *CAS* can check to see if they are already authenticated with *ADFS* and if so, let them in, SSO-style?

and on the flip side:

Is it possible if *USER-A* logs into a *CAS* application, and then tries to log into an *ADFS* application, *ADFS* can check to see if they are already authenticated with *CAS* and if so, let them in, SSO-style?

I have developers that aren't agreeing on one system or the other for SSO, and am looking into any possibility of having the two share info.

I understand you can make CAS use ADFS for backend authentication, or vise-a-versa, but i'm not sure that's exactly what i'm asking here... or is it?

thanks for any clarifications!
--
- Website: https://apereo.github.io/cas <https://apereo.github.io/cas>
- Gitter Chatroom: https://gitter.im/apereo/cas <https://gitter.im/apereo/cas>
- List Guidelines: https://goo.gl/1VRrw7 <https://goo.gl/1VRrw7>
- Contributions: https://goo.gl/mh7qDG <https://goo.gl/mh7qDG>
---
You received this message because you are subscribed to the Google Groups "CAS Community" group. To unsubscribe from this group and stop receiving emails from it, send an email to [email protected] <mailto:[email protected]>. To view this discussion on the web visit https://groups.google.com/a/apereo.org/d/msgid/cas-user/417d82f2-b60d-4173-a8e6-5fc7ce079613n%40apereo.org <https://groups.google.com/a/apereo.org/d/msgid/cas-user/417d82f2-b60d-4173-a8e6-5fc7ce079613n%40apereo.org?utm_medium=email&utm_source=footer>.


--
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- You received this message because you are subscribed to the Google Groups "CAS Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/d0795478-2241-c5d8-8bfd-a4e96f3e3d8b%40ndsu.edu.

Reply via email to