We have a few old vendor apps that use SAML 1.1 and those are working fine 
with our cas 6.6.x instance that is delegating to Azure/Entra AD.

We recently spun up a test instance of CAS 7 and those apps seem to reject 
the ticket from CAS 7 when being delegated to Azure (they work when not 
being delegated). I believe it has to do with the url parameter CAS sends 
after receiving the Azure delegation response. In CAS 6.6 it sends the 
SAMLart url parameter:

?SAMLart=ST-

But in CAS 7 it sends a ticket param:

?ticket=ST-

It almost seems if CAS forgets it is using SAML 1.1 after the delegation is 
complete. Anybody else experience this or know if there's some config we 
are missing in CAS 7 causing this?

Thanks!

-- 
- Website: https://apereo.github.io/cas
- Gitter Chatroom: https://gitter.im/apereo/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to cas-user+unsubscr...@apereo.org.
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/69be0db0-4ec4-459b-b54b-256c20a4b181n%40apereo.org.

Reply via email to