<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Share 3.3g with mod_auth_cas in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233868#M186998</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;when accessing CAS with the alf-system cert you are making a https request. The export settings in apache ssl virtual host send the cert data to tomcat.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When alfresco share is accessing the alfresco repo endpoint it should be thrown to the cas service via the url in the auth_cas.conf&amp;nbsp; which is https. So this should be OK.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In your endpoint config try using the https connector. The cert may not be being requested as there is no x509 processing in the initial http exchange (before the throw to CAS).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;https:&lt;/STRONG&gt;&lt;SPAN&gt;//&lt;/SPAN&gt;&lt;A href="http://kocw-vmg-alf-002.kocw.com/alfresco/wcs" rel="nofollow noopener noreferrer"&gt;kocw-vmg-alf-002.kocw.com/alfresco/wcs&lt;/A&gt;&lt;SPAN&gt;&amp;lt;/endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 01 Nov 2010 23:04:39 GMT</pubDate>
    <dc:creator>warren_mcdonald</dc:creator>
    <dc:date>2010-11-01T23:04:39Z</dc:date>
    <item>
      <title>Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233862#M186992</link>
      <description>I am having problems getting Share working with mod_auth_cas according to this guide… http://wiki.alfresco.com/wiki/Alfresco_With_mod_auth_cas(minus the x509 stuff as I have no intention of using client certificates)A few notes:I am using Alfresco 3.3g, and CAS 3.3.5 and 389DS for LDAPCAS and LDAP b</description>
      <pubDate>Thu, 14 Oct 2010 21:10:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233862#M186992</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-10-14T21:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233863#M186993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Come on….. anyone, anyone….. Bueller? Has anybody gotten this to work using the instructions on the wiki?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Oct 2010 16:40:20 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233863#M186993</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-10-25T16:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233864#M186994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Just a hint but you may have missed the point of the x509 stuff.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The certificate part of this config enables the Share web app to connect to the Alfresco repo backend using x509 trusted certs. You must implement the full config! Including enabling the x509 extension bean in CAS webapp deployer context.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Although this config could be the basis of client auth by cert, that is not it's purpose.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 04:35:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233864#M186994</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2010-10-28T04:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233865#M186995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thanks for the reply Warren. I did actually miss the point initially. But I have since gone back and followed the wiki exactly. Building CAS from source, putting everything on one server and all. I still can not get share to function however. Now alfresco explorer still functions, I can use the certificate on my computer to log in and I get the 'alfresco-system' as the remote user in the snoop.jsp test.&amp;nbsp; Looking at my CAS log after remove the cert from my computer and try to go into share using a username/password, it is assigning me a ticket but it also says that there is no cert found. Like you said share uses that certificate to authenticate to alfresco explorer, so should that appear in the CAS logs as well? I am a little confused on this point, but after&amp;nbsp; reading the wiki many, MANY times I am thinking that this is what it is supposed to do. I am at home right now but I will VPN into work in a few and get the relevant logs. Once again thanks for your reply. I really appreciate the help.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*Edit*&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Ok, connected to the office. here are the logs….&lt;/SPAN&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;2010-10-29 00:22:23,925 DEBUG [org.jasig.cas.CentralAuthenticationServiceImpl] - &amp;lt;Attempting to create TicketGrantingTicket for [username: alfuser]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,925 DEBUG [org.jasig.cas.authentication.handler.support.SimpleTestUsernamePasswordAuthenticationHandler] - &amp;lt;User [alfuser] was successfully authenticated.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,925 INFO [org.jasig.cas.authentication.AuthenticationManagerImpl] - &amp;lt;AuthenticationHandler: org.jasig.cas.authentication.handler.support.SimpleTestUsernamePasswordAuthenticationHandler successfully authenticated the user which provided the following credentials: [username: alfuser]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,925 DEBUG [org.jasig.cas.authentication.principal.UsernamePasswordCredentialsToPrincipalResolver] - &amp;lt;Attempting to resolve a principal…&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,925 DEBUG [org.jasig.cas.authentication.principal.UsernamePasswordCredentialsToPrincipalResolver] - &amp;lt;Creating SimplePrincipal for [alfuser]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,926 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Added ticket [TGT-3-ukx59RFr0Fw3IgG7pf61UyDk5EGtHhEeOXe29P1ekdpPHE0Buu-cas] to registry.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,926 DEBUG [org.jasig.cas.web.support.CookieRetrievingCookieGenerator] - &amp;lt;Removed cookie with name [CASPRIVACY]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,926 DEBUG [org.jasig.cas.web.support.CookieRetrievingCookieGenerator] - &amp;lt;Added cookie with name [CASTGC] and value [TGT-3-ukx59RFr0Fw3IgG7pf61UyDk5EGtHhEeOXe29P1ekdpPHE0Buu-cas]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,926 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Attempting to retrieve ticket [TGT-3-ukx59RFr0Fw3IgG7pf61UyDk5EGtHhEeOXe29P1ekdpPHE0Buu-cas]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,926 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Ticket [TGT-3-ukx59RFr0Fw3IgG7pf61UyDk5EGtHhEeOXe29P1ekdpPHE0Buu-cas] found in registry.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,927 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Added ticket [ST-3-HwJd5MRIdwqXDytAjVtv-cas] to registry.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:23,927 INFO [org.jasig.cas.CentralAuthenticationServiceImpl] - &amp;lt;Granted service ticket [ST-3-HwJd5MRIdwqXDytAjVtv-cas] for service [&lt;A href="https://kocw-vmg-alf-002.kocw.com:443/share/" rel="nofollow noopener noreferrer"&gt;https://kocw-vmg-alf-002.kocw.com:443/share/&lt;/A&gt;] for user [alfuser]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:24,289 DEBUG [org.jasig.cas.web.support.CasArgumentExtractor] - &amp;lt;Extractor generated service for: &lt;A href="https://kocw-vmg-alf-002.kocw.com:443/share/" rel="nofollow noopener noreferrer"&gt;https://kocw-vmg-alf-002.kocw.com:443/share/&lt;/A&gt;&amp;gt;&lt;BR /&gt;2010-10-29 00:22:24,289 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Attempting to retrieve ticket [ST-3-HwJd5MRIdwqXDytAjVtv-cas]&amp;gt;&lt;BR /&gt;2010-10-29 00:22:24,289 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Ticket [ST-3-HwJd5MRIdwqXDytAjVtv-cas] found in registry.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:24,289 DEBUG [org.jasig.cas.ticket.registry.DefaultTicketRegistry] - &amp;lt;Removing ticket [ST-3-HwJd5MRIdwqXDytAjVtv-cas] from registry&amp;gt;&lt;BR /&gt;2010-10-29 00:22:25,316 DEBUG [org.jasig.cas.web.support.CasArgumentExtractor] - &amp;lt;Extractor generated service for: &lt;A href="http://kocw-vmg-alf-002.kocw.com/alfresco/wcs/webframework/content/metadata?user=alfuser" rel="nofollow noopener noreferrer"&gt;http://kocw-vmg-alf-002.kocw.com/alfresco/wcs/webframework/content/metadata?user=alfuser&lt;/A&gt;&amp;gt;&lt;BR /&gt;2010-10-29 00:22:25,317 DEBUG [org.jasig.cas.adaptors.x509.web.flow.X509CertificateCredentialsNonInteractiveAction] - &amp;lt;Action 'X509CertificateCredentialsNonInteractiveAction' beginning execution&amp;gt;&lt;BR /&gt;2010-10-29 00:22:25,317 DEBUG [org.jasig.cas.adaptors.x509.web.flow.X509CertificateCredentialsNonInteractiveAction] - &amp;lt;Certificates not found in request.&amp;gt;&lt;BR /&gt;2010-10-29 00:22:25,317 DEBUG [org.jasig.cas.adaptors.x509.web.flow.X509CertificateCredentialsNonInteractiveAction] - &amp;lt;Action 'X509CertificateCredentialsNonInteractiveAction' completed execution; result is 'error'&amp;gt;&lt;BR /&gt;Oct 29, 2010 12:22:25 AM org.apache.catalina.core.StandardWrapperValve invoke&lt;BR /&gt;SEVERE: Servlet.service() for servlet Spring Surf Dispatcher Servlet threw exception&lt;BR /&gt;org.json.JSONException: A JSONObject text must begin with '{' at character 9&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.json.JSONTokener.syntaxError(JSONTokener.java:413)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.json.JSONObject.&amp;lt;init&amp;gt;(JSONObject.java:180)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.json.JSONObject.&amp;lt;init&amp;gt;(JSONObject.java:420)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.support.AlfrescoUserFactory.loadUser(AlfrescoUserFactory.java:173)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.support.AbstractUserFactory.initialiseUser(AbstractUserFactory.java:165)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.support.AbstractUserFactory.initialiseUser(AbstractUserFactory.java:99)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.RequestContextUtil.initialiseUser(RequestContextUtil.java:202)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.RequestContextUtil.initRequestContext(RequestContextUtil.java:106)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.RequestContextUtil.initRequestContext(RequestContextUtil.java:53)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.SlingshotPageViewResolver.lookupPage(SlingshotPageViewResolver.java:57)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.extensions.surf.mvc.PageViewResolver.canHandle(PageViewResolver.java:71)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.view.UrlBasedViewResolver.createView(UrlBasedViewResolver.java:370)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.view.AbstractCachingViewResolver.resolveViewName(AbstractCachingViewResolver.java:77)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.DispatcherServlet.resolveViewName(DispatcherServlet.java:1091)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.DispatcherServlet.render(DispatcherServlet.java:1040)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:798)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:716)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:647)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.springframework.web.servlet.FrameworkServlet.doGet(FrameworkServlet.java:552)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at javax.servlet.http.HttpServlet.service(HttpServlet.java:617)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.alfresco.web.site.servlet.MTAuthenticationFilter.doFilter(MTAuthenticationFilter.java:67)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:298)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.jk.server.JkCoyoteHandler.invoke(JkCoyoteHandler.java:190)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.jk.common.HandlerRequest.invoke(HandlerRequest.java:291)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.jk.common.ChannelSocket.invoke(ChannelSocket.java:769)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.jk.common.ChannelSocket.processConnection(ChannelSocket.java:698)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.jk.common.ChannelSocket$SocketConnection.runIt(ChannelSocket.java:891)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at org.apache.tomcat.util.threads.ThreadPool$ControlRunnable.run(ThreadPool.java:690)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;at java.lang.Thread.run(Thread.java:636)&lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;BR /&gt;&lt;SPAN&gt;and the relevant section of my share-config-custom.xml …&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;PRE class="language-none line-numbers"&gt;&lt;CODE&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;config evaluator="string-compare" condition="Remote"&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;remote&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;!– SSL client certificate + trusted CAs. Optionally used to authenticate share to an external SSO system such as CAS –&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;keystore&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;path&amp;gt;/opt/alfresco/tomcat/shared/classes/alfresco/web-extension/alfresco-system.p12&amp;lt;/path&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;type&amp;gt;pkcs12&amp;lt;/type&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;password&amp;gt;********&amp;lt;/password&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/keystore&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;connector&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;id&amp;gt;alfrescoCookie&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;name&amp;gt;Alfresco Connector&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;description&amp;gt;Connects to an Alfresco instance using cookie-based authentication&amp;lt;/description&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;class&amp;gt;org.springframework.extensions.webscripts.connector.AlfrescoConnector&amp;lt;/class&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/connector&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;id&amp;gt;alfresco&amp;lt;/id&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;name&amp;gt;Alfresco - user access&amp;lt;/name&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;description&amp;gt;Access to Alfresco Repository WebScripts that require user authentication&amp;lt;/description&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;connector-id&amp;gt;alfrescoCookie&amp;lt;/connector-id&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-url&amp;gt;&lt;A href="http://kocw-vmg-alf-002.kocw.com/alfresco/wcs" rel="nofollow noopener noreferrer"&gt;http://kocw-vmg-alf-002.kocw.com/alfresco/wcs&lt;/A&gt;&amp;lt;/endpoint-url&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;identity&amp;gt;user&amp;lt;/identity&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;external-auth&amp;gt;true&amp;lt;/external-auth&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/endpoint&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;/remote&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &amp;lt;/config&amp;gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&lt;SPAN class="line-numbers-rows"&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;SPAN&gt;‍&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Oct 2010 04:15:15 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233865#M186995</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-10-29T04:15:15Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233866#M186996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Have you checked the CAS SSO logs?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Are you definitely getting the certificate passed in to the tomcat server (hosting cas) from the fronting httpd. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;You may have to add the specific directive in the virtual host for cas or in the common ssl.conf&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;CAS log will tell you (very briefly) if the cert is missing from the request. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Nov 2010 04:09:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233866#M186996</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2010-11-01T04:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233867#M186997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;if I import the certificate into the browser on my computer I get through CAS w/o being prompted for a login. The snoop.jsp page also shows 'alfresco-system' as the remote user. However there seems to be a point where Share should authenticate with Alfresco using the certificate.This seems to be where the problem lies. I think for some reason Share is not using the certificate. I get the 'no certificate found in request' error. I have the alfresco-system certificate specified in the &amp;lt;keystore&amp;gt; section of share-config-custom.xml. Is there anywhere else the certificate needs to be called out?&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Nov 2010 17:32:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233867#M186997</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-11-01T17:32:31Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233868#M186998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;when accessing CAS with the alf-system cert you are making a https request. The export settings in apache ssl virtual host send the cert data to tomcat.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;When alfresco share is accessing the alfresco repo endpoint it should be thrown to the cas service via the url in the auth_cas.conf&amp;nbsp; which is https. So this should be OK.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;In your endpoint config try using the https connector. The cert may not be being requested as there is no x509 processing in the initial http exchange (before the throw to CAS).&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;STRONG&gt;https:&lt;/STRONG&gt;&lt;SPAN&gt;//&lt;/SPAN&gt;&lt;A href="http://kocw-vmg-alf-002.kocw.com/alfresco/wcs" rel="nofollow noopener noreferrer"&gt;kocw-vmg-alf-002.kocw.com/alfresco/wcs&lt;/A&gt;&lt;SPAN&gt;&amp;lt;/endpoint-url&amp;gt;&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 01 Nov 2010 23:04:39 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233868#M186998</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2010-11-01T23:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233869#M186999</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Warren,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have tried switching the endpoint to https with the same result. Is there any additional logging you could recommend turning on to debug the problem? For some reason it seems share is not sending the cert to CAS. Thanks again. Additional information, I am using Fedora 12 for my OS.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 03:54:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233869#M186999</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-11-02T03:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233870#M187000</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;ah ha - So we are not going mad.&amp;nbsp; See &lt;/SPAN&gt;&lt;A href="http://issues.alfresco.com/jira/browse/ALF-2788" rel="nofollow noopener noreferrer"&gt;http://issues.alfresco.com/jira/browse/ALF-2788&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;This Jira spells out that 3.3 no longer responds to the "endpoint connector with keystore" config we are trying to use. This worked in 3.2 but is no longer relevant in 3.3 &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;There is a work around to edit shares web.xml to remove SSO filter in favour of the new external-auth enabled global filter. &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;It is not clear however if this is actually going to work in 3.3 or only in 3.4. The explanation of the config work around is very bad and contradicts itself.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I will give it a go anyway. Whats to lose.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;For the wiki to have specific references to 3.3 config and this to be known to be obsolete is pretty bad. I sense community support to starting to slip badly.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 06:40:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233870#M187000</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2010-11-02T06:40:00Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233871#M187001</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Wow, I am such an idiot….. I saw that bug when I first started working on this and I ignored it because at the time I thought I did not need x509 auth. Then I went back and configured everything as per the kiki and forgot about it. This is one of the reasons why I thought the cert was not needed in the first place. At least that verified one of the things I was trying to determine, which is if the wiki was correct. Which is it not.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;BTW, I tried setting it up as per that bug in 3.4a as well and had no luck.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Well. this may not work for everyone but we are only using Share, not Alfresco Explorer. So what I did this morning was I removed Alfresco from being protected by CAS. Meaning I took out the &amp;lt;Location /alfresco&amp;gt; section in mod_auth_cas.conf and I can now log into Share using CAS.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Of course this means we can not log into Alfresco now. But I wonder if some sort of rewrite or proxy configuration would allow access to Alfresco Explorer through CAS for instance have a CAS protected version at &lt;/SPAN&gt;&lt;A href="http://someserver.com/alfresco" rel="nofollow noopener noreferrer"&gt;http://someserver.com/alfresco&lt;/A&gt;&lt;SPAN&gt; and a proxied version, not protected by CAS that Share authenticates to at &lt;/SPAN&gt;&lt;A href="http://someserver.com/otheralfresco" rel="nofollow noopener noreferrer"&gt;http://someserver.com/otheralfresco&lt;/A&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks for all the help on this matter Warren. I am going to continue doing some tests to make sure that nothing in Share is broken by this and will post back. Right now I am trying to disable the flash uploader which does not work woth CAS auth either.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 02 Nov 2010 18:38:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233871#M187001</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-11-02T18:38:52Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233872#M187002</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hey, &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;glad you found a solution.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;I have been thinking about a proxy solutions for some of our needs too. We need webdav protected by CAS for one purpose but also for hosting podcast xml files which need basic auth for iTunes. So multiple proxy directives may work (you will need rewriting as well).&amp;nbsp; One possible way may be to use a more specific set of locations in the mod_auth_cas.conf file. Perhaps protecting only some /alfresco/&amp;lt;subdirs&amp;gt; will do the trick and leave others for normal auth. This will require bit of fiddling with a lot more directives, but there are not that many possible paths.&amp;nbsp; &lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;The 3.4.a solution requires a new class file. I have extracted this from a 3.4.a jar and packed it up in a jar to supplement my 3.3 install. I now have the error mentioned in the above Jira, but should be able to configure around it. I do like the aim of this solution which is the same generic external_auth handling for share as already exists for alfresco. It is unfortunate is only half baked for community as yet.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Cheers,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Warren&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 03 Nov 2010 12:43:32 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233872#M187002</guid>
      <dc:creator>warren_mcdonald</dc:creator>
      <dc:date>2010-11-03T12:43:32Z</dc:date>
    </item>
    <item>
      <title>Re: Share 3.3g with mod_auth_cas</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233873#M187003</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;So is it pretty much confirmed that the wiki is wrong? Why would they go through all the time and effort to create that if the information is not accurate. Someone on the team should correct that page, or at the very least post specifically what platform those instructions run on. I am using Fedora 12 in my implementation with OpenJDK1.6 and CAS 3.3.5. I did test it with Sun JDK as well to ensure it was not some weird thing w/ OpenJDK. A few other notes…. Since the x509 portion does not function in 3.3g there is no need to build CAS from source. After x509 failed and I used the solution I described earlier I went back to using my original CAS server which was just the WAR file I downloaded from jasig. Also my solution seems to have broken task actions in the My Tasks dashlet when using a secure site. Tasks work under HTTP but does not function under HTTPS. When trying to accept a task on a secure site I get the 'failed to action task' message. I think this may be related to an active bug that has something to do with using tasks while working through a proxy.&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 06 Nov 2010 07:23:22 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/share-3-3g-with-mod-auth-cas/m-p/233873#M187003</guid>
      <dc:creator>forsetiavatar</dc:creator>
      <dc:date>2010-11-06T07:23:22Z</dc:date>
    </item>
  </channel>
</rss>

