<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco Share SSO using CAS in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176973#M130103</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have also been using the solution posted &lt;/SPAN&gt;&lt;A href="http://translate.google.com/translate?u=http://blog.atolcd.com/%3Fp%3D115&amp;amp;sl=fr&amp;amp;tl=en" rel="nofollow noopener noreferrer"&gt;here&lt;/A&gt;&lt;SPAN&gt;. For Alfresco 3.3 I have changed the code slightly and now it works fine with CAS for Alfresco and Alfresco Share.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;See my solution &lt;/SPAN&gt;&lt;A href="http://akselsarchitecture.blogspot.com/" rel="nofollow noopener noreferrer"&gt;here&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Sep 2010 12:45:59 GMT</pubDate>
    <dc:creator>akselb</dc:creator>
    <dc:date>2010-09-02T12:45:59Z</dc:date>
    <item>
      <title>Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176967#M130097</link>
      <description>Hi,I have implemented Alfresco with CAS without any issues, but I'm struggling to get Alfresco Share to work with CAS. Has anyone come right with this? ThanksZaine</description>
      <pubDate>Mon, 23 Feb 2009 10:27:19 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176967#M130097</guid>
      <dc:creator>zaine</dc:creator>
      <dc:date>2009-02-23T10:27:19Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176968#M130098</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I would also appreciate some help in this direction. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have been looking at the NTLM auth implementation in Share which relies on a specificially configured endpoint (wcs) on the Alfresco side. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Will a CAS SSO implementation for Share need to employ the same type of mechanism?&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Are the endpoint init parameters used on the NTLM auth filter in Share specific to that module or are they generic to Alfresco authenticator classes?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 01 Mar 2009 12:15:53 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176968#M130098</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2009-03-01T12:15:53Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176969#M130099</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Same here. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I am also looking at the NTLMAuthenticationFilter in Share as a reference point.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;By default /share apparently does not use a filter for authentication , unlike /alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren, have you made any progress?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Hongbo&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 11 Apr 2009 13:20:51 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176969#M130099</guid>
      <dc:creator>hongbo</dc:creator>
      <dc:date>2009-04-11T13:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176970#M130100</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;I have implemented Alfresco with CAS without any issues, but I'm struggling to get Alfresco Share to work with CAS. Has anyone come right with this?&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;&lt;SPAN&gt;Yes, see &lt;/SPAN&gt;&lt;A href="http://translate.google.com/translate?u=http://blog.atolcd.com/%3Fp%3D115&amp;amp;sl=fr&amp;amp;tl=en" rel="nofollow noopener noreferrer"&gt;http://translate.google.com/translate?u=http://blog.atolcd.com/%3Fp%3D115&amp;amp;sl=fr&amp;amp;tl=en&lt;/A&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 May 2009 12:43:40 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176970#M130100</guid>
      <dc:creator>t_broyer</dc:creator>
      <dc:date>2009-05-11T12:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176971#M130101</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;This procedure works great for getting /alfresco cassified. But /share is causing me some grief. What's happening is that the PGTIOU gets issued, but this does not translate to a PGT per the logs below. Stepping through the code I see that the PGTIOU does not map to a PGT in the cache collection (ProxyGrantingTicketImpl.java). &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;(I'm using cas-client-3.1.8 with the 3.3.4 cas-server. And all this is on Alfresco 3.2r Community.)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;1. Sign into /share, get redirected to CAS&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Log into CAS, get a ticket with service redirect to /share:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;09:22:04,064&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:22:04,067&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] no ticket and no assertion found&lt;BR /&gt;09:22:04,067&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] Constructed service url: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:22:04,068&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] redirecting to "&lt;A href="https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index" rel="nofollow noopener noreferrer"&gt;https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index&lt;/A&gt;"&lt;BR /&gt;09:22:22,520&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:22:22,520&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] no ticket and no assertion found&lt;BR /&gt;09:22:22,520&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] Constructed service url: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:22:22,520&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] redirecting to "&lt;A href="https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index" rel="nofollow noopener noreferrer"&gt;https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index&lt;/A&gt;"&lt;BR /&gt;09:22:34,764&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;3. CAS validates ticket:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;09:23:51,230&amp;nbsp; DEBUG [client.validation.Cas20ProxyReceivingTicketValidationFilter] Attempting to validate ticket: ST-14-UJ16RLSTe4DhnwR3ncUS-cas&lt;BR /&gt;09:23:52,315&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:23:58,287&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Placing URL parameters in map.&lt;BR /&gt;09:23:58,290&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Calling template URL attribute map.&lt;BR /&gt;09:24:02,333&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Loading custom parameters from configuration.&lt;BR /&gt;09:24:16,020&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Constructing validation url: &lt;A href="https://nih.local:8444/cas/proxyValidate?pgtUrl=https%3A%2F%2Fnih.local%3A8443%2Fshare%2FproxyCallback&amp;amp;ticket=ST-14-UJ16RLSTe4DhnwR3ncUS-cas&amp;amp;service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index" rel="nofollow noopener noreferrer"&gt;https://nih.local:8444/cas/proxyValidate?pgtUrl=https%3A%2F%2Fnih.local%3A8443%2Fshare%2FproxyCallback&amp;amp;ticket=ST-14-UJ16RLSTe4DhnwR3ncUS-cas&amp;amp;service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2Fpage%2Fsite-index&lt;/A&gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;4. CAS redirects user to share with ST&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;09:24:16,020&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Retrieving response from server.&lt;BR /&gt;09:24:21,210&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback&lt;/A&gt;&lt;BR /&gt;09:24:21,212&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] no ticket and no assertion found&lt;BR /&gt;09:24:21,212&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] Constructed service url: &lt;A href="http://nih.local:8080/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback&lt;/A&gt;&lt;BR /&gt;09:24:21,212&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] redirecting to "&lt;A href="https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2FproxyCallback" rel="nofollow noopener noreferrer"&gt;https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2FproxyCallback&lt;/A&gt;"&lt;BR /&gt;09:24:22,074&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas&lt;/A&gt;&lt;BR /&gt;09:24:22,074&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] no ticket and no assertion found&lt;BR /&gt;09:24:22,074&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] Constructed service url: &lt;A href="http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas&lt;/A&gt;&lt;BR /&gt;09:24:22,075&amp;nbsp; DEBUG [client.authentication.AuthenticationFilter] redirecting to "&lt;A href="https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2FproxyCallback%3FpgtIou%3DPGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas%26pgtId%3DTGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas" rel="nofollow noopener noreferrer"&gt;https://nih.local:8444/cas/login?service=http%3A%2F%2Fnih.local%3A8080%2Fshare%2FproxyCallback%3FpgtIou%3DPGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas%26pgtId%3DTGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas&lt;/A&gt;"&lt;BR /&gt;09:24:22,102&amp;nbsp; DEBUG [client.validation.Cas20ProxyTicketValidator] Server response: &amp;lt;cas:serviceResponse xmlns:cas='&lt;A href="http://www.yale.edu/tp/cas" rel="nofollow noopener noreferrer"&gt;http://www.yale.edu/tp/cas&lt;/A&gt;'&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;cas:authenticationSuccess&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;cas:user&amp;gt;admin&amp;lt;/cas:user&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;cas:proxyGrantingTicket&amp;gt;PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;lt;/cas:proxyGrantingTicket&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;lt;/cas:authenticationSuccess&amp;gt;&lt;BR /&gt;&amp;lt;/cas:serviceResponse&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Here CAS has provided a PGTIOU and a pgtId which references a Ticket-Granting-Ticket (TGT…) instead of a PGT. Not sure if this is wrong or if a TGT is equivalent to a PGT.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Share *should* get a ProxyTicket based on the ProxyGrantingTicket (and it fails to find an internal mapping for the PGTIOU):&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;09:24:43,023&amp;nbsp; INFO&amp;nbsp; [client.proxy.ProxyGrantingTicketStorageImpl] No Proxy Ticket found for PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;6. CAS authentication passes, but Share+Alfresco authentication fails:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;09:25:30,151&amp;nbsp; DEBUG [client.validation.Cas20ProxyReceivingTicketValidationFilter] Successfully authenticated user: admin&lt;BR /&gt;09:25:30,170&amp;nbsp; DEBUG [client.validation.Cas20ProxyReceivingTicketValidationFilter] Redirecting after successful ticket validation.&lt;BR /&gt;09:25:30,171&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index;jsessionid=47F57241192E0CBD568B39ECAFE581EC" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index;jsessionid=47F57241192E0CBD568B39ECAFE581EC&lt;/A&gt;&lt;BR /&gt;09:25:35,498&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/page/site-index" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/page/site-index&lt;/A&gt;&lt;BR /&gt;09:26:13,576&amp;nbsp; DEBUG [atolcd.alfresco.CasAuthenticationFilter] Authenticating user: admin against ticket source &lt;A href="http://nih.local:8080/alfresco" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/alfresco&lt;/A&gt;&lt;BR /&gt;09:26:17,862&amp;nbsp; DEBUG [client.authentication.AttributePrincipalImpl] No ProxyGrantingTicket was supplied, so no Proxy Ticket can be retrieved.&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;My CAS-server logs don't show any problems either:&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;2009-10-29 09:24:16,359 DEBUG [org.jasig.cas.authentication.handler.support.HttpBasedServiceCredentialsAuthenticationHandler] - &amp;lt;Attempting to resolve credentials for [callbackUrl: &lt;A href="https://nih.local:8443/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;https://nih.local:8443/share/proxyCallback&lt;/A&gt;]&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,222 DEBUG [org.jasig.cas.web.support.CasArgumentExtractor] - &amp;lt;Extractor generated service for: &lt;A href="http://nih.local:8080/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback&lt;/A&gt;&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,233 DEBUG [org.jasig.cas.util.HttpClient] - &amp;lt;Response code from server matched 200.&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,235 INFO [org.jasig.cas.authentication.AuthenticationManagerImpl] - &amp;lt;AuthenticationHandler: org.jasig.cas.authentication.handler.support.HttpBasedServiceCredentialsAuthenticationHandler successfully authenticated the user which provided the following credentials: [callbackUrl: &lt;A href="https://nih.local:8443/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;https://nih.local:8443/share/proxyCallback&lt;/A&gt;]&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,235 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Attempting to retrieve ticket [ST-14-UJ16RLSTe4DhnwR3ncUS-cas]&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,235 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Ticket [ST-14-UJ16RLSTe4DhnwR3ncUS-cas] found in registry.&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,236 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Added ticket [TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas] to registry.&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,236 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Attempting to retrieve ticket [ST-14-UJ16RLSTe4DhnwR3ncUS-cas]&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,236 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Ticket [ST-14-UJ16RLSTe4DhnwR3ncUS-cas] found in registry.&amp;gt;&lt;BR /&gt;2009-10-29 09:24:21,236 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Removing ticket [ST-14-UJ16RLSTe4DhnwR3ncUS-cas] from registry&amp;gt;&lt;BR /&gt;2009-10-29 09:24:22,085 DEBUG [org.jasig.cas.web.support.CasArgumentExtractor] - &amp;lt;Extractor generated service for: &lt;A href="http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas&lt;/A&gt;&amp;gt;&lt;BR /&gt;2009-10-29 09:24:22,094 DEBUG [org.jasig.cas.util.HttpClient] - &amp;lt;Response code from server matched 200.&amp;gt;&lt;BR /&gt;2009-10-29 09:24:22,095 DEBUG [org.jasig.cas.ticket.proxy.support.Cas20ProxyHandler] - &amp;lt;Sent ProxyIou of PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas for service: [callbackUrl: &lt;A href="https://nih.local:8443/share/proxyCallback" rel="nofollow noopener noreferrer"&gt;https://nih.local:8443/share/proxyCallback&lt;/A&gt;]&amp;gt;&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;Can anyone shed some light on why exactly I'm not getting the PGT from the PGTIOU? My web.xml is pretty much exactly as Laurent described.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2009 12:20:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176971#M130101</guid>
      <dc:creator>cybertoast</dc:creator>
      <dc:date>2009-10-30T12:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176972#M130102</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;4. CAS redirects user to share with ST&lt;BR /&gt;09:24:22,074&amp;nbsp; DEBUG [client.util.CommonUtils] serviceUrl generated: &lt;A href="http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas" rel="nofollow noopener noreferrer"&gt;http://nih.local:8080/share/proxyCallback?pgtIou=PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&amp;amp;pgtId=TGT-23-l5KbudOXAGGoekG0gxFdPLOdzxcnQwlqocdf4ajTMKtXAeXa2Z-cas&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here CAS has provided a PGTIOU and a pgtId which references a Ticket-Granting-Ticket (TGT…) instead of a PGT. Not sure if this is wrong or if a TGT is equivalent to a PGT.&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt;Yes, it's PGT&lt;/SPAN&gt;&lt;BR /&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;5. Share *should* get a ProxyTicket based on the ProxyGrantingTicket (and it fails to find an internal mapping for the PGTIOU):&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;09:24:43,023&amp;nbsp; INFO&amp;nbsp; [client.proxy.ProxyGrantingTicketStorageImpl] No Proxy Ticket found for PGTIOU-10-rrO5TMttIfOmXr9cXR2L-cas&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;SPAN&gt;If you setup the proxyCallback servlet correctly, you should able to get it with ProxyTicketReceptor.getProxyTicket(String pgtIou, String target)&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Dec 2009 12:27:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176972#M130102</guid>
      <dc:creator>hoaivan</dc:creator>
      <dc:date>2009-12-19T12:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco Share SSO using CAS</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176973#M130103</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have also been using the solution posted &lt;/SPAN&gt;&lt;A href="http://translate.google.com/translate?u=http://blog.atolcd.com/%3Fp%3D115&amp;amp;sl=fr&amp;amp;tl=en" rel="nofollow noopener noreferrer"&gt;here&lt;/A&gt;&lt;SPAN&gt;. For Alfresco 3.3 I have changed the code slightly and now it works fine with CAS for Alfresco and Alfresco Share.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;See my solution &lt;/SPAN&gt;&lt;A href="http://akselsarchitecture.blogspot.com/" rel="nofollow noopener noreferrer"&gt;here&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Sep 2010 12:45:59 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/alfresco-share-sso-using-cas/m-p/176973#M130103</guid>
      <dc:creator>akselb</dc:creator>
      <dc:date>2010-09-02T12:45:59Z</dc:date>
    </item>
  </channel>
</rss>

