CAS单点登录集成文档

一、介绍
CAS单点登录为业务系统提供统一的单点登录服务。

业务系统不需要开发自己的登录界面,系统使用者也避免了在多个业务系统间重复输入密码,改善了用户体验,同时密码实现集中维护,提高了系统的安全性。

单点登录演示地址:http://172.16.10.40:1433/cas/login(社管平台测试环境)业务系统可以使用这个地址进行开发测试。

二、下载
CAS为J2EE B/S应用提供了应用集成API,可以直接调用实现单点登录的集成。

:cas-client.jar
文件下载后复制到业务系统的WEB-INF/lib目录。

三、配置
在web.xml中配置认证过滤器(实现单点登录用户认证)和会话监听器(实现单点登录的注销),例如:
<listener>
<listener-class>com.iflytek.cas.listener.LogoutSessionListener</listener-class>
</listener>
<filter>
<filter-name>casFilter</filter-name>
<filter-class>com.iflytek.cas.filter.TicketValidationFilter</filter-class>
<init-param>
<param-name>appUrl</param-name>
<param-value></param-value>
</init-param>
<init-param>
<param-name>casLoginUrl</param-name>
<param-value>http://172.16.10.40:1433/cas/login</param-value>
</init-param>
<init-param>
<param-name>ticketValidateUrl</param-name>
<param-value>http://172.16.10.40:1433/cas/validate</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>casFilter</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
过滤器参数说明:
1、appUrl:Client会根据浏览器请求自动判断这个地址,所以一般情况下是不需要设置的。

但是在反向代理环境中,CAS Client会得到代理服务器的地址,所以必须手工指定这个地址。

2、casLoginUrl:CAS登录地址。

用户未登录的情况下,浏览器会自动重定向到这个地址,显示登录界面。

3、ticketValidateUrl:CAS后台票据验证地址。

应用服务器向这个地址发出请求,验证登录票据的正确性。

四、获取登录名
CAS Client将用户登录名存入Session容器,取出方法如下:
request.getSession().getAttribute("er")
五、用户注销
用户从浏览器访问如下地址实现注销,注销时会在CAS服务器和各业务系统服务器同时注销:
https://172.16.10.46/cas/logout(测试环境)
七、Spring集成
J2EE B/S开发一般采用Spring作为对象容器。

采用Spring集成的方法,请参考
"org.springframework.web.filter.DelegatingFilterProxy"的用法说明,采用Spring管理验证过滤器。

配置方式例如:
web.xml
<filter>
<filter-name>casFilter</filter-name>
<filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class>
<init-param>
<param-name>targetBeanName</param-name>
<param-value>casFilter</param-value>
</init-param>
</filter>
<filter-mapping>
<filter-name>casFilter</filter-name>
<url-pattern>/*</url-pattern>
</filter-mapping>
spring.xml
<bean name="casFilter" class="com.iflytek.cas.filter.TicketValidationFilter"
p:appUrl="" p:casLoginUrl="https://172.16.10.40/cas/login"
p:ticketValidateUrl="http://172.16.10.40/cas/validate"/>。

合集下载

springboot集成cas5.3实现sso单点登录详细流程

springboot集成cas5.3实现sso单点登录详细流程

springboot集成cas5.3实现sso单点登录详细流程什么是单点登录?单点登录(Single Sign On),简称为 SSO,是⽬前⽐较流⾏的企业业务整合的解决⽅案之⼀。

SSO的定义是在多个应⽤系统中,⽤户只需要登录⼀次就可以访问所有相互信任的应⽤系统。

我们⽬前的系统存在诸多⼦系统,⽽这些⼦系统是分别部署在不同的服务器中,那么使⽤传统⽅式的session是⽆法解决的,我们需要使⽤相关的单点登录技术来解决。

SSO单点登录访问流程主要有以下步骤:访问服务:SSO客户端发送请求访问应⽤系统提供的服务资源。

定向认证:SSO客户端会重定向⽤户请求到SSO服务器。

⽤户认证:⽤户⾝份认证。

发放票据:SSO服务器会产⽣⼀个随机的Service Ticket。

验证票据:SSO服务器验证票据Service Ticket的合法性,验证通过后,允许客户端访问服务。

传输⽤户信息:SSO服务器验证票据通过后,传输⽤户认证结果信息给客户端。

(作者补充:其实简单来说,cas就是中央认证服务,就是单点登录,单点登录简称为sso!)cas服务端部署mvn package3、把target下⽣成的war包重命名为cas.war放到tomcat下4、启动tomcat5、找到解压的⽂件由于cas默认使⽤的是基于https协议,需要改为兼容使⽤http协议,打开对应你的⽬录⽂件:D:\tomcat8\webapps\cas\WEB-INF\classes\application.properties修改application.properties⽂件,添加下⾯配置,使⽤http#使⽤http协议cas.tgc.secure=falsecas.serviceRegistry.initFromJson=true#由于https协议默认使⽤的端⼝为8443,还需我们修改为tomcat的8080端⼝server.port=8080修改HTTPSandIMAPS-10000001.json⽂件D:\tomcat8\webapps\cas\WEB-INF\classes\services⽬录下的HTTPSandIMAPS-10000001.json把原来的serviceId内容改成如下"serviceId" : "^(https|http|imaps)://.*",兼容http修改完毕。

单点登录CAS与LDAP整合的实现

单点登录CAS与LDAP整合的实现

单点登录CAS与LDAP整合的实现单点登录(Single Sign-On,SSO)是一种身份验证和访问控制机制,允许用户使用一组凭据(如用户名和密码)登录到一个应用程序,然后在登录后访问其他应用程序而无需再次提供凭据。

这种机制的实现需要集成不同的身份验证系统,例如,CAS(Central Authentication Service)与LDAP(Lightweight Directory Access Protocol)。

CAS是一种基于Web的身份验证协议,它提供了一种单点登录解决方案,允许用户在一次登录后访问多个Web应用程序,并且不需要再次输入凭据。

CAS通过提供一个认证服务器来实现这一功能,该服务器负责验证用户的凭据,并生成一个票据(Ticket)以表示用户的身份。

LDAP是一种用于访问和维护分布式目录信息服务(Directory Information Services)的协议。

目录服务用于存储和组织用户和组的信息,包括用户名、密码和其他属性。

LDAP提供了一种标准化的方式来查找、添加、修改和删除目录条目,提供了对用户身份信息的集中存储和访问。

要将CAS和LDAP整合,首先需要配置CAS服务器以使用LDAP作为其用户存储和验证机制。

下面是实现此集成的步骤:1. 配置LDAP服务器:首先,需要在LDAP服务器上创建一个目录以存储用户和组的信息。

可以使用开源的LDAP服务器,如OpenLDAP或Microsoft的Active Directory。

2.配置LDAP属性映射:CAS需要将LDAP中的用户属性映射到CAS的用户模型中。

这些属性包括用户名、密码、姓名、角色等。

需要根据LDAP服务器的架构和CAS的用户模型进行正确的属性映射。

3.配置LDAP身份验证器:CAS使用一个或多个身份验证器来验证用户的凭据。

应该配置一个LDAP身份验证器来使用LDAP服务器进行用户身份验证。

4.配置CAS服务器:在CAS服务器上,需要配置CAS以使用LDAP身份验证器进行用户身份验证。

SSO、单点登录、集成CAS、OAuth2

SSO、单点登录、集成CAS、OAuth2

SSO、单点登录、集成CAS、OAuth2JeeSite 已经默认集成了两种单点登录方式(Single Sign On):1、SSO(简单登录)接口,实现快速登录系统。

2、与 Apereo CAS 服务器集成,快速实现系统登录(个人版)并实现了第三方登录 OAuth2,如:微信、QQ、支付宝、等等简单登录接口系统登录:1、设置application.yml(v4.0.x:jeesite.yml)的shiro.sso.secretKey 快速登录安全Key,若不设置将无法使用该接口。

shiro:# 简单 SSO 登录相关配置sso:# 如果启用/sso/{username}/{token}单点登录,请修改此安全key并与单点登录系统key一致。

secretKey: thinkgem# 是否加密单点登录安全KeyencryptKey: true2、举例调用地址如下,调用完成后自动登录系统:http://localhost/project/sso/{username}/{token}?url=/sys/us er/list?p1=v1%26p2=v2&relogin=true•username: 登录名,数据库中的 login_code 字段。

•token: 登录令牌,根据yml里配置的登录安全Key生产的密码。

•url: 登录之后要跳转的地址,如果url中携带参数,请使用转义字符,如“&”号,使用“%26”转义。

token生成方式:String username = "system"; // 登录系统名String secretKey = "thinkgem"; // yml 中设置的shiro.sso.secretKey 参数值。

String token = Md5Utils.md5(secretKey + username +DateUtils.getDate("yyyyMMdd"));// 如果 shiro.sso.encryptKey 为 true,则 secretKey 会自动加密。

CAS干单点登陆(SSO)

CAS干单点登陆(SSO)

CAS⼲单点登陆(SSO)CAS做单点登陆(SSO)——集成Java Web 项⽬添加cas-client的jar包下载cas-client,地址:/downloads/cas-clients/,当前最新版本是cas-client-3.2.1-release.zip。

然后解压cas-client-3.2.1-release.zip,在modules拷贝cas-client-core-3.2.1.jar到应⽤的WEB-INF/lib⽬录中。

撰写⽀持CAS集成的客户化包除了在web.xml添加CAS内置的filter外(具体看配置web.xml),我们需要撰写⾃⼰⽀持CAS集成的客户化包。

⼤致思路如下:@Overridepublic void doFilter(ServletRequest servletRequest, ServletResponse servletResponse, FilterChain filterChain) throws IOException, ServletException {HttpServletRequest request = (HttpServletRequest)servletRequest;HttpServletResponse response = (HttpServletResponse)servletResponse;HttpSession session = request.getSession();//在session中⾃定义⼀个参数,以它来校验是否完成过⾃动登陆Object user_login = session.getAttribute(AURORA_USER_LOGIN);if (user_login != null){//登陆过,就继续执⾏其他filterfilterChain.doFilter(request, response);return;}//通过CAS的API获得登陆账号String loginName = AssertionHolder.getAssertion().getPrincipal().getName();try {//执⾏本系统的登陆。

CAS实现单点登录

CAS实现单点登录

CAS实现单点登录1.简介SSO单点登录在多个相互信任的系统中,⽤户只需要登录⼀次就可以访问其他受信任的系统。

新浪微博与新浪博客是相互信任的应⽤系统。

*当⽤户⾸次访问新浪微博时,新浪微博识别到⽤户未登录,将请求重定向到认证中⼼,认证中⼼也识别到⽤户未登录,则将请求重定向到登录页。

*当⽤户已登录新浪微博访问新浪博客时,新浪博客识别到⽤户未登录,将请求重定向到认证中⼼,认证中⼼识别到⽤户已登录,返回⽤户的⾝份,此时⽤户⽆需登录即可使⽤新浪博客。

*只要多个系统使⽤同⼀套单点登录框架那么它们将是相互信任的。

CASYale ⼤学发起的⼀个开源项⽬,旨在为 Web 应⽤系统提供⼀种可靠的单点登录⽅法, CAS 在 2004 年 12 ⽉正式成为 JA-SIG 的⼀个项⽬。

CAS包含CAS Client 和 CAS Server两部分CAS Client:要使⽤单点登录的Web应⽤,将与同组下的Web应⽤构成相互信任的关系,只需在web应⽤中添加CAS提供的Listener和Filter即可成为CAS Client ,其主要负责对客户端的请求进⾏登录校验、重定向和校验ticket⼯作。

CAS Server:主要负责对⽤户的⽤户名/密码进⾏认证,颁发票据等,需要单独的进⾏部署。

*同组下的任意⼀个Web应⽤登录后其他应⽤都不需要登录即可使⽤。

2.CAS服务器搭建2.1 去CAS源码包将下载的源码包中的cas-server-webapp⼯程导⼊ide中,将⼯程打包为war包,直接放⼊tomcat下的webapp中运⾏。

*CAS 5.0版本以上需要jdk1.8和gradle进⾏构建、4.X版本使⽤maven进⾏构建(maven 3.3+)2.2 在Tomcat中开启HTTPS协议*由于CAS Server默认使⽤HTTPS协议进⾏访问,因此需要在Tomcat中开启HTTPS协议。

1.使⽤JDK提供的keytool命令⽣成秘钥库。

Django集成CAS单点登录的方法示例

Django集成CAS单点登录的方法示例

Django集成CAS单点登录的⽅法⽰例CAS 全称集中式认证服务(Central Authentication Service),是实现单点登录(SSO)的⼀中⼿段。

CAS 的通讯流程图如下(图⽚来⾃Google图库):对于本⽂⽤户可感知的层⾯,认证过程如下:1. 前端访问后端登录接⼝2. 后端返回重定向到 CAS 服务器的登录页⾯,并携带当前⽤户访问的⽹页链接3. ⽤户登录,浏览器发送请求到 CAS 服务器进⾏认证4. CAS 认证通过,将本次登录保存到会话,返回回调地址给后端5. 后端返回重定向请求给前端6. 前端重定向到跳转登录前的页⾯中间涉及到的 TGT 处理逻辑已经由开源 CAS Client(python-cas) 实现。

要注意,CAS 服务器本⾝有⼀些过滤条件,例如域名⽩名单等,因此接⼊的时候需要将新系统的域名或 IP 加⼊ CAS 服务端配置中。

出于安全考虑,CAS ⼀般不⽀持跨域,因此前后端分离开发时可能⽐较⿇烦。

(似乎有解决⽅案,但是未尝试过)接⼊ CAS因为是第⼀次接触 CAS ,为了⽅便调试,我在本地直接启动⼀个 CAS 服务端⽤于调试。

CAS 客户端也就是集成于我们实际开发的Django代码中。

CAS 服务端GitHub 中有很多 CAS 项⽬,我选了⼀个基于 Django 的django-mama-cas应⽤。

配置创建django-cas-server项⽬:django-admin startproject django-cas-server安装django-mama-cas依赖:pip install django-mama-cas在INSTALLED_APPS中添加'mama_cas'应⽤:settings.pyINSTALLED_APPS = [...'mama_cas',]添加mama_cas应⽤中的路由:urls.pyurlpatterns += [url(r'', include('mama_cas.urls'))]配置 CAS 信息:MAMA_CAS_SERVICES = [{# 必填项,此项为**Client** IP:Port,相当于⽩名单'SERVICE': 'http://127.0.0.1:8000',# 回调模式,具体参考官⽅⽂档'CALLBACKS': ['mama_er_model_attributes',],},]使⽤# 使⽤任意端⼝都可,此处我使⽤ 30000python manage.py runserver 0.0.0.0:30000问题来了,⽤户名密码是什么呢?我着实花了点时间才解决这个问题———— django-mama-cas默认使⽤的是django.auth模块User,使⽤django-admin创建超级⽤户,该⽤户也就可以⽤于登录 CAS :python manage.py createsuperuser输⼊⽤户密码即完成超级⽤户创建,接着使⽤这个⽤户登录即可。

单点登录CAS与权限管理框架Shiro集成

单点登录CAS与权限管理框架Shiro集成首先当然是要和现在的系统进行集成,现在系统采用cas来做登录验证,所以先把cas和shiro进行集成。

查看shiro官网,发现有个cas模块,下载试用,下面是集成方法,假设你已经搭建好cas服务器。

我是用maven管理项目的,先引入shiro的jar包[html]1.<dependency>2.<groupId>org.apache.shiro</groupId>3.<artifactId>shiro-cas</artifactId>4.<version>1.2.0</version>5.</dependency>配置web.xml,添加shiro过滤器[html]1.<filter>2.<filter-name>shiroFilter</filter-name>3.<filter-class>org.apache.shiro.web.servlet.IniShiroFilter</f ilter-class>4.<init-param>5.<param-name>configPath</param-name>6.<param-value>classpath:META-INF/shiro/shiro.ini</para m-value>7.</init-param>8.</filter>9.10.<filter-mapping>11.<filter-name>shiroFilter</filter-name>12.<url-pattern>/*</url-pattern>13.</filter-mapping>其中shiro.ini为shiro配置文件,可以根据具体情况指定其路径。

EOS与开源单点登录产品cas集成指南

EOS与开源单点登录产品cas集成指南(2008-11-04 07:34:14)转载分类:安全标签:soassoit发布时间:2008年10月06日作者:majs最近我正在思考SOA与单点登录问题,今天看到一篇文章,觉得不错,特转在这里,方便以后查看。

介绍cas sso产品的原理、安装、调试和与EOS应用的集成1 总体解决方案1.1 单点登录概述单点登录的英文名称为Single Sign-On,简写为SSO,它是一个用户认证的过程,允许用户一次性进行认证之后,就访问系统中不同的应用;而不需要访问每个应用时,都重新输入密码。

IBM对SSO有一个形象的解释“单点登录、全网漫游”。

SSO将一个企业内部所有域中的用户登录和用户帐号管理集中到一起,SSO的好处显而易见:1. 减少用户在不同系统中登录耗费的时间,减少用户登录出错的可能性2. 实现安全的同时避免了处理和保存多套系统用户的认证信息3. 减少了系统管理员增加、删除用户和修改用户权限的时间4. 增加了安全性:系统管理员有了更好的方法管理用户,包括可以通过直接禁止和删除用户来取消该用户对所有系统资源的访问权限对于内部有多种应用系统的企业来说,单点登录的效果是十分明显的。

很多国际上的企业已经将单点登录作为系统设计的基本功能之一1.2 单点登录产品商业sso软件专门的SSO商业软件主要有:Netgrity的Siteminder,已经被CA收购。

Novell 公司的iChain。

RSA公司的ClearTrust 等。

门户产品供应商自己的SSO产品,如:BEA的WLES,IBM 的Tivoli Access Manager,Sun 公司的identity Server,Oracle公司的OID等。

上述商业软件一般适用于客户对SSO的需求很高,并且企业内部采用Domino、SAP、Sieble 等系统比较多的情况下。

单点登录产品通常需要在应用软件中增加代理模块,而商业SSO 产品主要针对大型软件制作了代码模块。

CAS实现单点登录(SSO)经典完整教程

CAS实现单点登录(SSO)经典完整教程一、简介1、cas是有耶鲁大学研发的单点登录服务器2、本教材所用环境∙Tomcat7.2∙JDK6∙CAS Service 版本 cas-server-3.4.8-release∙CAS Client版本 cas-client-3.2.1-release二、生成证书证书对于实现此单点登录非常之重要,证书是服务器端和客户端安全通信的凭证,本教程只是演示,所有用JDK自带的证书生成工具keytool。

当然在实际项目中你可以到专门的证书认证中心购买证书。

中文官方网站:/cn/1、用JDK自带的keytool生成证书[plain]view plaincopy1.命令:keytool -genkey -alias smalllove -keyalg RSA -keystore D:/keys/smallkey此命令是生成一个证书,其中smalllove 是证书别名此命令的执行如图所示:其中名字与姓氏这一最好写你的域名,如果在单击测试你可以在C:\Windows\System32\drivers\etc\hosts文件中映射一个虚拟域名,注意不要写IP。

2、导出证书[plain]view plaincopy1.命令:C:\>keytool -export -file d:/keys/small.crt -alias smalllove -keystore d:/keys/smallkey如图:密码为上步设置的密码。

3、把证书导入到客户端JDK中。

[plain]view plaincopy1.命令:keytool -import -keystore C:\Java\jdk1.6.0_21\lib\security\cacerts -file D:/keys/small.crt-alias smalllove此命令是把证书导入到JDK中。

如图:到此证书导入成功。

注意:在此步有可能出现如下错误[plain]view plaincopy1.C:\>keytool -import -keystore C:\Java\jdk1.6.0_21\lib\security\cacerts -file D:/keys/small.crt -alias smalllove2.输入keystore密码:3. keytool错误: java.io.IOException: Keystore was tampered with, or password was incorrect次错误的解决方法是,把%JAVA_HOME%\lib\security下的cacerts文件删除掉,在执行。

CAS官方文档

Buildgit clone git@:Jasig/java-cas-client.gitcd java-cas-clientmvn clean packagePlease note that to be deployed in Maven Central, we mark a number of JARs as provided (related to JBoss and Memcache Clients). In order to build the clients, you must enable the commented out repositories in the appropriate pom.xml files in the modules(cas-client-integration-jboss and cas-client-support-distributed-memcached) or follow the instructions on how to install the file manually.Components∙Core functionality, which includes CAS authentication/validation filters.<dependency><groupId>org.jasig.cas.client</groupId><artifactId>cas-client-core</artifactId><version>${java.cas.client.version}</version></dependency>∙Support for SAML functionality is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-support-saml</artifactId><version>${java.cas.client.version}</version></dependency>∙Distributed proxy ticket caching with Ehcache is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-support-distributed-ehcache</artifactId><version>${java.cas.client.version}</version></dependency>∙Distributed proxy ticket caching with Memcached is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-support-distributed-memcached</artifactId><version>${java.cas.client.version}</version></dependency>∙Atlassian integration is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-integration-atlassian</artifactId><version>${java.cas.client.version}</version></dependency>∙JBoss integration is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-integration-jboss</artifactId><version>${java.cas.client.version}</version></dependency>∙Tomcat 6 integration is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-integration-tomcat-v6</artifactId><version>${java.cas.client.version}</version></dependency>∙Tomcat 7 is provided by this dependency:<dependency><groupId>org.jasig.cas</groupId><artifactId>cas-client-integration-tomcat-v7</artifactId><version>${java.cas.client.version}</version></dependency>ConfigurationStrategiesThe client provides multiple strategies for the deployer to provide client settings. The following strategies are supported:∙JNDI (JNDI)∙Properties File (PROPERTY_FILE). The configuration is provided via an external properties file.The path may be specified in the web context as such:<param-name>configFileLocation</param-name><param-value>/etc/cas/file.properties</param-value></context-param>If no location is specified, by default /etc/java-cas-client.properties will be used.∙System Properties (SYSTEM_PROPERTIES)∙Web Context (WEB_XML)∙Default (DEFAULT)In order to instruct the client to pick a strategy, strategy name must be specified in the web application's context:<context-param><param-name>configurationStrategy</param-name><param-value>DEFAULT</param-value></context-param>If no configurationStrategy is defined, DEFAULT is used which is a combination of WEB_XML and JNDI. Client Configuration Using web.xmlThe client can be configured in web.xml via a series of context-param s and filter init-param s. Each filter for the client has a required (and optional) set of properties. The filters are designed to look for these properties in the following way:∙Check the filter's local init-param s for a parameter matching the required property name.∙Check the context-param s for a parameter matching the required property name.∙If two properties are found with the same name in the init-param s and the context-param s, the init-param takes precedence.Note: If you're using the serverName property, you should note well that the fragment-URI (the stuff after the #) is not sent to the server by all browsers, thus the CAS client can't capture it as part of the URL. An example application that is protected by the client is available here.org.jasig.cas.client.authentication.AuthenticationFilterThe AuthenticationFilter is what detects whether a user needs to be authenticated or not. If a user needs to be authenticated, it will redirect the user to the CAS server.<filter><filter-name>CAS Authentication Filter</filter-name><filter-class>org.jasig.cas.client.authentication.AuthenticationFilter</filter-clas s><init-param><param-name>casServerLoginUrl</param-name><param-value>https://:8443/cas/login</param-value></init-param><param-name>serverName</param-name><param-value></param-value></init-param></filter><filter-mapping><filter-name>CAS Authentication Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Property Description RequiredcasServerLoginUrl Defines the location of the CAS serverlogin URL,i.e. https://localhost:8443/cas/loginYesserverName The name of the server this application is hosted on. Service URL will be dynamically constructed using this, i.e.https://localhost:8443 (you must includethe protocol, but port is optional if it'sa standard port).Yesservice The service URL to send to the CAS server,i.e.https://localhost:8443/yourwebapp/index.htmlNorenew specifies whether renew=true should besent to the CAS server. Valid values are either true/false(or no value at all). Notethat renew cannot be specified aslocal init-param setting.Nogateway specifies whether gateway=true should besent to the CAS server. Valid values are either true/false(or no value at all)NoartifactParameterName specifies the name of the request parameteron where to find the artifact(i.e. ticket).NoserviceParameterName specifies the name of the request parameteron where to find the service (i.e. service)NoencodeServiceUrl Whether the client should auto encode the service url. Defaults to trueNoignorePattern Defines the url pattern to ignore, when intercepting authentication requests.NoProperty Description RequiredignoreUrlPatternType Defines the type of the pattern specified. Defaults to REGEX. Other typesare CONTAINS,EXACT.NogatewayStorageClass The storage class used to record gateway requestsNoauthenticationRedirectStrategyClass The class name of the component to decidehow to handle authn redirects to CASNoorg.jasig.cas.client.authentication.Saml11AuthenticationFilterThe SAML 1.1 AuthenticationFilter is what detects whether a user needs to be authenticated or not.If a user needs to be authenticated, it will redirect the user to the CAS server.<filter><filter-name>CAS Authentication Filter</filter-name><filter-class>org.jasig.cas.client.authentication.Saml11AuthenticationFilter</filter-class><init-param><param-name>casServerLoginUrl</param-name><param-value>https://:8443/cas/login</param-value></init-param><init-param><param-name>serverName</param-name><param-value></param-value></init-param></filter><filter-mapping><filter-name>CAS Authentication Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Property Description RequiredcasServerLoginUrl Defines the location of the CAS server login URL,i.e.https://localhost:8443/cas/loginYesserverName The name of the server this application is hostedon. Service URL will be dynamically constructedusing this, i.e. https://localhost:8443 (you must include the protocol, but port is optional if it'sa standard port).YesProperty Description Requiredservice The service URL to send to the CAS server,i.e.https://localhost:8443/yourwebapp/index.htmlNorenew specifies whether renew=true should be sent to theCAS server. Valid values are either true/false(orno value at all). Note that renew cannot bespecified as local init-param setting.Nogateway specifies whether gateway=true should be sent tothe CAS server. Valid values areeither true/false(or no value at all)NoartifactParameterName specifies the name of the request parameter on whereto find the artifact (i.e. SAMLart).NoserviceParameterName specifies the name of the request parameter on whereto find the service (i.e. TARGET)NoencodeServiceUrl Whether the client should auto encode the serviceurl. Defaults to trueNoorg.jasig.cas.client.validation.Cas10TicketValidationFilterValidates tickets using the CAS 1.0 Protocol.<filter><filter-name>CAS Validation Filter</filter-name><filter-class>org.jasig.cas.client.validation.Cas10TicketValidationFilter</filter-class><init-param><param-name>casServerUrlPrefix</param-name><param-value>https://:8443/cas</param-value></init-param></filter><filter-mapping><filter-name>CAS Validation Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Property DescriptioncasServerUrlPrefix The start of the CAS server URL, i.e.https://localhost:8443/cas serverName The name of the server this application is hosted on. ServiceProperty Descriptionwill be dynamically constructed using this,i.e. https://localhost:8443(you must include the protocol, bport is optional if it's a standard port).renew Specifies whether renew=true should be sent to the CAS ser Valid values are either true/false(or no value at all). Not that renew cannot be specified as local init-param setting.redirectAfterValidation Whether to redirect to the same URL after ticket validation, without the ticket in the parameter. Defaults to true.useSession Whether to store the Assertion in session or not. If sessions not used, tickets will be required for each request. Defaul to true.exceptionOnValidationFailure Whether to throw an exception or not on ticket validation fail Defaults to true.sslConfigFile A reference to a properties file that includes SSL settings client-side SSL config, used during back-channel calls. The configuration includes keys for protocol which defaultsto SSL,keyStoreType, keyStorePath, keyStorePass,keyManagerType w defaults to SunX509and certificatePassword.encoding Specifies the encoding charset the client should use hostnameVerifier Hostname verifier class name, used when making back-channel c org.jasig.cas.client.validation.Saml11TicketValidationFilterValidates tickets using the SAML 1.1 protocol.<filter><filter-name>CAS Validation Filter</filter-name><filter-class>org.jasig.cas.client.validation.Saml11TicketValidationFilter</filter-class><init-param><param-name>casServerUrlPrefix</param-name><param-value>https://:8443/cas</param-value></init-param><init-param><param-name>serverName</param-name><param-value></param-value></init-param></filter><filter-mapping><filter-name>CAS Validation Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Property Description casServerUrlPrefix The start of the CAS server URL, i.e.https://localhost:8443/casserverName The name of the server this application is hosted on. Service will be dynamically constructed using this,i.e. https://localhost:8443(you must include the protocol, b port is optional if it's a standard port).renew Specifies whether renew=true should be sent to the CAS ser Valid values are either true/false(or no value at all). Not that renew cannot be specified as local init-param setting.redirectAfterValidation Whether to redirect to the same URL after ticket validation, without the ticket in the parameter. Defaults to true.useSession Whether to store the Assertion in session or not. If sessions not used, tickets will be required for each request. Defaul to true.exceptionOnValidationFailure whether to throw an exception or not on ticket validation fail Defaults to truetolerance The tolerance for drifting clocks when validating SAML tick Note that 10 seconds should be more than enough for most environments that have NTP time synchronization. Defaults to msecsslConfigFile A reference to a properties file that includes SSL settings client-side SSL config, used during back-channel calls. The configuration includes keys for protocol which defaultsto SSL,keyStoreType, keyStorePath, keyStorePass,keyManagerType w defaults to SunX509and certificatePassword.encoding Specifies the encoding charset the client should use hostnameVerifier Hostname verifier class name, used when making back-channel c org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilterValidates the tickets using the CAS 2.0 protocol. If you provide either the acceptAnyProxy orthe allowedProxyChains parameters, a Cas20ProxyTicketValidator will be constructed. Otherwise ageneral Cas20ServiceTicketValidator will be constructed that does not accept proxy tickets.Note: If you are using proxy validation, you should place the filter-mapping of the validation filterbefore the authentication filter.<filter><filter-name>CAS Validation Filter</filter-name><filter-class>org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter</filter-class><init-param><param-name>casServerUrlPrefix</param-name><param-value>https://:8443/cas</param-value></init-param><init-param><param-name>serverName</param-name><param-value></param-value></init-param></filter><filter-mapping><filter-name>CAS Validation Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Property Description casServerUrlPrefix The start of the CAS server URL, i.e.https://localhost:8443/serverName The name of the server this application is hosted on. Serv will be dynamically constructed using this,i.e.https://localhost:8443(you must include the protocol, b is optional if it's a standard port).renew Specifies whether renew=true should be sent to the CAS s Valid values are either true/false(or no value at all). N that renew cannot be specified as local init-param settinredirectAfterValidation Whether to redirect to the same URL after ticket validati without the ticket in the parameter. Defaults to true.useSession Whether to store the Assertion in session or not. If sessi not used, tickets will be required for each request. Def to true.exceptionOnValidationFailure whether to throw an exception or not on ticket validation f Defaults to trueproxyReceptorUrl The URL to watch for PGTIOU/PGT responses from the CAS s Should be defined from the root of the context. For exam your application is deployed in /cas-client-app and you wanProperty Descriptionproxy receptor URL to be/cas-client-app/my/receptor you needconfigure proxyReceptorUrl to be/my/receptor. acceptAnyProxy Specifies whether any proxy is OK. Defaults to false.allowedProxyChains Specifies the proxy chain. Each acceptable proxy chain s include a space-separated list of URLs. Each acceptable prox should appear on its own line.proxyCallbackUrl The callback URL to provide the CAS server to accept Proxy G Tickets.proxyGrantingTicketStorageClass Specify an implementation of the ProxyGrantingTicketStorag that has a no-arg constructor.sslConfigFile A reference to a properties file that includes SSL setti client-side SSL config, used during back-channel calls. configuration includes keys for protocol which defaults to SSL, keyStoreType, keyStorePath,keyStorePass, keyManagerType defaults to SunX509and certificatePassword.encoding Specifies the encoding charset the client should usesecretKey The secret key used by the proxyGrantingTicketStorageClass if supports encryption.cipherAlgorithm The algorithm used by the proxyGrantingTicketStorageClass if i supports encryption. Defaults to DESedemillisBetweenCleanUps Startup delay for the cleanup task to remove expired ticke the storage. Defaults to60000 msecticketValidatorClass Ticket validator class to use/createhostnameVerifier Hostname verifier class name, used when making back-channe org.jasig.cas.client.validation.Cas30ProxyReceivingTicketValidationFilterValidates the tickets using the CAS 3.0 protocol. If you provide either the acceptAnyProxy orthe allowedProxyChains parameters, a Cas30ProxyTicketValidator will be constructed. Otherwise ageneral Cas30ServiceTicketValidator will be constructed that does not accept proxy tickets.Supports all configurations that are available for Cas20ProxyReceivingTicketValidationFilter.Proxy Authentication vs. Distributed CachingThe client has support for clustering and distributing the TGT state among application nodes that arebehind a load balancer. In order to do so, the parameter needs to be defined as such for the filter.EhcacheConfigure the client:<init-param><param-name>proxyGrantingTicketStorageClass</param-name><param-value>org.jasig.cas.client.proxy.EhcacheBackedProxyGrantingTicketStorageImpl </param-value></init-param>The setting provides an implementation for proxy storage using EhCache to take advantage of its replication features so that the PGT is successfully replicated and shared among nodes, regardless which node is selected as the result of the load balancer rerouting.Configuration of this parameter is not enough. The EhCache configuration needs to enable the replication mechanism through once of its suggested ways. A sample of that configuration based on RMI replication can be found here. Please note that while the sample is done for a distributed ticket registry implementation, the basic idea and configuration should easily be transferable.When loading from the web.xml, the Jasig CAS Client relies on a series of default values, one of which being that the cache must be configured in the default location (i.e. classpath:ehcache.xml).<cacheManagerPeerProviderFactoryclass="net.sf.ehcache.distribution.RMICacheManagerPeerProviderFactory"properties="peerDiscovery=automatic,multicastGroupAddress=230.0.0.1, multicastGroupPort=4446"/><cacheManagerPeerListenerFactoryclass="net.sf.ehcache.distribution.RMICacheManagerPeerListenerFactory"/><cachename="org.jasig.cas.client.proxy.EhcacheBackedProxyGrantingTicketStorageImpl.cache"maxElementsInMemory="100"eternal="false"timeToIdleSeconds="100"timeToLiveSeconds="100"overflowToDisk="false"><cacheEventListenerFactoryclass="net.sf.ehcache.distribution.RMICacheReplicatorFactory"/></cache>MemcachedA similar implementation based on Memcached is also available.Configure the client:<init-param><param-name>proxyGrantingTicketStorageClass</param-name><param-value>org.jasig.cas.client.proxy. MemcachedBackedProxyGrantingTicketStorageImpl</param-value></init-param>When loading from the web.xml, the Client relies on a series of default values, one of which being that the list of memcached servers must be defined in /cas/casclient_memcached_hosts.txt on the classpath). The file is a simple list of <hostname>:<ports> on separate lines. BE SURE NOT TO HAVE EXTRA LINE BREAKS.org.jasig.cas.client.util.HttpServletRequestWrapperFilterWraps an HttpServletRequest so that the getRemoteUser and getPrincipal return the CAS related entries.org.jasig.cas.client.util.AssertionThreadLocalFilterPlaces the Assertion in a ThreadLocal for portions of the application that need access to it. This is useful when the Web application that this filter "fronts" needs to get the Principal name, but it has no access to the HttpServletRequest, hence making getRemoteUser() call impossible.<filter><filter-name>CAS Assertion Thread Local Filter</filter-name><filter-class>org.jasig.cas.client.util.AssertionThreadLocalFilter</filter-class> </filter><filter-mapping><filter-name>CAS Assertion Thread Local Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Client Configuration Using SpringConfiguration via Spring IoC will depend heavily on DelegatingFilterProxy class. For each filter that will be configured for CAS via Spring, a corresponding DelegatingFilterProxy is needed in the web.xml.Asthe SingleSignOutFilter, HttpServletRequestWrapperFilter and AssertionThreadLocalFilte r have no configuration options, we recommend you just configure them in the web.xml<filter><filter-name>CAS Authentication Filter</filter-name><filter-class>org.springframework.web.filter.DelegatingFilterProxy</filter-class> <init-param><param-name>targetBeanName</param-name><param-value>authenticationFilter</param-value></init-param></filter><filter-mapping><filter-name>CAS Authentication Filter</filter-name><url-pattern>/*</url-pattern></filter-mapping>Bean ConfigurationAuthenticationFilter<beanname="authenticationFilter"class="org.jasig.cas.client.authentication.AuthenticationFilter"p:casServerLoginUrl="https://localhost:8443/cas/login"p:renew="false"p:gateway="false"p:service="https:///cas-client" />Cas10TicketValidationFilter<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Cas10TicketValidationFilter"p:service="https:///cas-client"><property name="ticketValidator"><bean class="org.jasig.cas.client.validation.Cas10TicketValidator"><constructor-arg index="0"value="https://localhost:8443/cas" /></bean></property></bean>Saml11TicketValidationFilter<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Saml11TicketValidationFilter"p:service="https:///cas-client"><property name="ticketValidator"><bean class="org.jasig.cas.client.validation.Saml11TicketValidator"><constructor-arg index="0"value="https://localhost:8443/cas" /></bean></property></bean>Cas20ProxyReceivingTicketValidationFilterConfiguration to validate tickets:<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter"p:service="https:///cas-client"><property name="ticketValidator"><bean class="org.jasig.cas.client.validation.Cas20ServiceTicketValidator"> <constructor-arg index="0"value="https://localhost:8443/cas" /></bean></property></bean>Configuration to accept a Proxy Granting Ticket:<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter"p:service="https:///cas-client"p:proxyReceptorUrl="/proxy/receptor"><property name="ticketValidator"><beanclass="org.jasig.cas.client.validation.Cas20ServiceTicketValidator"p:proxyCallbackUrl="/proxy/receptor"><constructor-arg index="0"value="https://localhost:8443/cas" /></bean></property></bean>Configuration to accept any Proxy Ticket (and Proxy Granting Tickets):<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter"p:service="https:///cas-client"p:proxyReceptorUrl="/proxy/receptor"><property name="ticketValidator"><bean class="org.jasig.cas.client.validation.Cas20ProxyTicketValidator"p:acceptAnyProxy="true"p:proxyCallbackUrl="/proxy/receptor"><constructor-arg index="0"value="https://localhost:8443/cas" /></bean></property></bean>Configuration to accept Proxy Ticket from a chain (and Proxy Granting Tickets):<beanname="ticketValidationFilter"class="org.jasig.cas.client.validation.Cas20ProxyReceivingTicketValidationFilter"p:service="https:///cas-client"p:proxyReceptorUrl="/proxy/receptor"><property name="ticketValidator"><bean class="org.jasig.cas.client.validation.Cas20ProxyTicketValidator"p:proxyCallbackUrl="/proxy/receptor"><constructor-arg index="0"value="https://localhost:8443/cas" /><property name="allowedProxyChains"><list><value>http://proxy1 http://proxy2</value></list></property></bean></property></bean>The specific filters can be configured in the following ways. Please see the JavaDocs included in the distribution for specific required and optional properties:Client Configuration Using JNDIConfiguring the CAS client via JNDI is essentially the same as configuring the client via the web.xml, except the properties will reside in JNDI and not in the web.xml. All properties that are placed in JNDI should be placed under java:comp/env/casWe use the following conventions: 1. JNDI will first look in java:comp/env/cas/{SHORT FILTER NAME}/{PROPERTY NAME} (i.e. java:comp/env/cas/AuthenticationFilter/serverName) 2. JNDI will as a last resort look in java:comp/env/cas/{PROPERTY NAME} (i.e. java:comp/env/cas/serverName)This is an update to the META-INF/context.xml that is included in Tomcat's Manager application:<?xml version="1.0" encoding="UTF-8"?><Context antiResourceLocking="false"privileged="true"><Environment description="Server Name"name="cas/serverName"override="false"type="ng.String"value="http://localhost:8080"/><Environment description="CAS Login Url"name="cas/AuthenticationFilter/casServerLoginUrl"override="false"type="ng.String"value="https:///cas/login"/><Environment description="CAS Url Prefix"name="cas/Cas20ProxyReceivingTicketValidationFilter/casServerUrlPrefix"override="false"type="ng.String"value="https:///cas"/></Context>Configuring Single Sign OutThe Single Sign Out support in CAS consists of configuring one SingleSignOutFilter andone ContextListener. Please note that if you have configured the CAS Client for Java as Web filters,this filter must come before the other filters as described.The SingleSignOutFilter can affect character encoding. This becomes most obvious when used inconjunction with applications such as Atlassian Confluence. Its recommended you explicitly configureeither the VT Character Encoding Filter or the Spring Character Encoding Filter with explicit encodings.ConfigurationProperty Description RequiredartifactParameterName The ticket artifact parameter name. Defaultsto ticketNologoutParameterName Defaults to logoutRequest No frontLogoutParameterName Defaults to SAMLRequest No relayStateParameterName Defaults to RelayState No eagerlyCreateSessions Defaults to true No artifactParameterOverPost Defaults to false No casServerUrlPrefix URL to root of CAS Web application context. Yes CAS Protocol。

  1. 1、下载文档前请自行甄别文档内容的完整性,平台不提供额外的编辑、内容补充、找答案等附加服务。
  2. 2、"仅部分预览"的文档,不可在线预览部分如存在完整性等问题,可反馈申请退款(可完整预览的文档不适用该条件!)。
  3. 3、如文档侵犯您的权益,请联系客服反馈,我们会尽快为您处理(人工客服工作时间:9:00-18:30)。
相关文档
最新文档