<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Alfresco 5.2 SSO-CAS question in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17769#M7881</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firstly that's a really old CAS version, and is out of support, you should be looking to move to 5.1.x (shouldn't cause any problems though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do need to edit share-config-custom.xml (although you can build the amp from source using the local profile and appropriate properties) but it's not getting that far. Ref:&amp;nbsp;&lt;A class="link-titled" href="https://github.com/wrighting/alfresco-cas/blob/master/alfresco-cas-share-amp/src/main/resources/META-INF/share-config-custom.xml" title="https://github.com/wrighting/alfresco-cas/blob/master/alfresco-cas-share-amp/src/main/resources/META-INF/share-config-custom.xml" rel="nofollow noopener noreferrer"&gt;alfresco-cas/share-config-custom.xml at master · wrighting/alfresco-cas · GitHub&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said I suspect the problem might be in your CAS configuration - my guess is that the CAS client is failing to parse the CAS server response correctly.(could be an error response of some kind)&lt;/P&gt;&lt;P&gt;It doesn't need any special config other than to have the URL matching a registered service (mine is a bit more complicated using the usernameAttributeProvider but again that shouldn't make any difference)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd start by looking in the CAS server logs, then if that doesn't help, see if I can look at the incoming CAS response by changing logging config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cas30ServiceTicketValidator extends&amp;nbsp;Cas20ServiceTicketValidator so that is why the exception appears to come from an unexpected class.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 31 Aug 2017 07:42:00 GMT</pubDate>
    <dc:creator>idwright</dc:creator>
    <dc:date>2017-08-31T07:42:00Z</dc:date>
    <item>
      <title>Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17763#M7875</link>
      <description>Hi everyone,I am writing this because i want to set up external authentication on my Alfresco app, looking on the official 5.2 documentation there's a section that explains a little on how SSO-CAS can be used, however there are no instructions on how to set it up, i say this because on this link&amp;nbsp;Usi</description>
      <pubDate>Tue, 22 Aug 2017 18:43:01 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17763#M7875</guid>
      <dc:creator>os_cerna</dc:creator>
      <dc:date>2017-08-22T18:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17764#M7876</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have not tried CAS with 5.2, but I know about the&amp;nbsp;following project that I used in the past with an older version of Alfresco.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://github.com/wrighting/alfresco-cas/issues/3" title="https://github.com/wrighting/alfresco-cas/issues/3" rel="nofollow noopener noreferrer"&gt;Not working with 5.2 · Issue #3 · wrighting/alfresco-cas · GitHub&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you can see, the issue says it does not work with 5.2 because of a know bug&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2017 01:03:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17764#M7876</guid>
      <dc:creator>douglascrp</dc:creator>
      <dc:date>2017-08-23T01:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17765#M7877</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should work :&amp;nbsp;&lt;A class="link-titled" href="https://issues.alfresco.com/jira/browse/ACE-5661" title="https://issues.alfresco.com/jira/browse/ACE-5661" rel="nofollow noopener noreferrer"&gt;[ACE-5661] External authentication Problem with CAS - Alfresco JIRA&lt;/A&gt;&amp;nbsp; should have fixed it.&lt;/P&gt;&lt;P&gt;Using CAS is not encouraged, as that authentication scheme is rather unstable, and there are efforts towards implementing other new standards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Aug 2017 10:01:31 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17765#M7877</guid>
      <dc:creator>arebegea</dc:creator>
      <dc:date>2017-08-23T10:01:31Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17766#M7878</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A few points here:&lt;/P&gt;&lt;P&gt;The issue &lt;B&gt;Douglas C. R. Paes&lt;/B&gt;‌ refers to relates to the wrighting/alfresco-cas project on github which uses the CAS java filters not mod_auth_cas&lt;/P&gt;&lt;P&gt;CAS itself is widely used, well maintained and stable - trying to use it with Alfresco is, shall we say, interesting...&lt;/P&gt;&lt;P&gt;mod_auth_cas is less well maintained, although better than it was (hence the reason for using the java client) (OS repos are out of date so it works better if you build from source)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;wrighting/alfresco-cas can be made to work with 5.2, if you use the ACE-5661 branch, but it requires replacing the share web.xml which is not ideal and is why it hasn't been released as a version (this is done in the amp if you clone the branch and build it) - the master branch/current version will work with 5.1 without changing web.xml&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(I haven't done too much testing with 5.2 in general, or this in particular, but I believe it works)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I am aware this is likely to change in the not too distant future but that's the current state of play as I understand it.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2017 12:33:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17766#M7878</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-08-24T12:33:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17767#M7879</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks a lot, i will try to make it work then&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Aug 2017 15:32:36 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17767#M7879</guid>
      <dc:creator>os_cerna</dc:creator>
      <dc:date>2017-08-24T15:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17768#M7880</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;B&gt;Ian Wright&lt;/B&gt;, here my test with Alfresco 201707GA and CAS Server 3.5.1:&lt;/P&gt;&lt;P&gt;- I cloned&amp;nbsp; ACE-5661 branch and I maven package generating the share AMP. When applying I checked web.xml is being replaced.&lt;/P&gt;&lt;P&gt;- I edited the /etc/java-cas-client.properties according the instructions in Alfresco server as pointed here --&amp;gt;&amp;nbsp;&lt;A class="link-titled" href="https://github.com/wrighting/alfresco-cas/tree/ACE-5661/alfresco-cas-share-amp" title="https://github.com/wrighting/alfresco-cas/tree/ACE-5661/alfresco-cas-share-amp" rel="nofollow noopener noreferrer"&gt;alfresco-cas/alfresco-cas-share-amp at ACE-5661 · wrighting/alfresco-cas · GitHub&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I edited alfresco-global.properties for setting external authentication --&amp;gt;&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/5.2/concepts/auth-external-intro.html" title="http://docs.alfresco.com/5.2/concepts/auth-external-intro.html" rel="nofollow noopener noreferrer"&gt;Configuring external authentication | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- I'm not sure if need to change share-config-custom.xml according --&amp;gt;&amp;nbsp;&lt;A class="link-titled" href="http://docs.alfresco.com/5.2/tasks/auth-alfrescoexternal-sso.html" title="http://docs.alfresco.com/5.2/tasks/auth-alfrescoexternal-sso.html" rel="nofollow noopener noreferrer"&gt;Configuring Alfresco Share to use an external SSO | Alfresco Documentation&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I got this error in catalina.out when redirecting from cas server.&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;GRAVE: El Servlet.service() para el servlet [Spring Surf Dispatcher Servlet] en el contexto con ruta [/share] lanzó la excepción [org.jasig.cas.client.validation.TicketValidationException: No principal was found in the response from the CAS server.] con causa raíz&lt;BR /&gt;org.jasig.cas.client.validation.TicketValidationException: No principal was found in the response from the CAS server at&lt;/P&gt;&lt;P&gt;org.jasig.cas.client.validation.Cas20ServiceTicketValidator.parseResponseFromServer(Cas20ServiceTicketValidator.java:98)&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;2017-08-30 19:07:12,658 ERROR [alfresco.web.site] [http-apr-8080-exec-10] javax.servlet.ServletException: org.jasig.cas.client.validation.TicketValidationException: No principal was found in the response from the CAS server.&lt;BR /&gt; org.jasig.cas.client.validation.TicketValidationException: No principal was found in the response from the CAS server. at org.jasig.cas.client.validation.Cas20ServiceTicketValidator.parseResponseFromServer(Cas20ServiceTicketValidator.java:98)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I missing something ? Shoud be used Cas30ServiceTicketValidator instead&amp;nbsp;&lt;SPAN&gt;Cas20ServiceTicketValidator as configured in&amp;nbsp;&lt;SPAN&gt;/etc/java-cas-client.properties&amp;nbsp;&lt;/SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Aug 2017 17:20:05 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17768#M7880</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-30T17:20:05Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17769#M7881</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firstly that's a really old CAS version, and is out of support, you should be looking to move to 5.1.x (shouldn't cause any problems though)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do need to edit share-config-custom.xml (although you can build the amp from source using the local profile and appropriate properties) but it's not getting that far. Ref:&amp;nbsp;&lt;A class="link-titled" href="https://github.com/wrighting/alfresco-cas/blob/master/alfresco-cas-share-amp/src/main/resources/META-INF/share-config-custom.xml" title="https://github.com/wrighting/alfresco-cas/blob/master/alfresco-cas-share-amp/src/main/resources/META-INF/share-config-custom.xml" rel="nofollow noopener noreferrer"&gt;alfresco-cas/share-config-custom.xml at master · wrighting/alfresco-cas · GitHub&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That being said I suspect the problem might be in your CAS configuration - my guess is that the CAS client is failing to parse the CAS server response correctly.(could be an error response of some kind)&lt;/P&gt;&lt;P&gt;It doesn't need any special config other than to have the URL matching a registered service (mine is a bit more complicated using the usernameAttributeProvider but again that shouldn't make any difference)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd start by looking in the CAS server logs, then if that doesn't help, see if I can look at the incoming CAS response by changing logging config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cas30ServiceTicketValidator extends&amp;nbsp;Cas20ServiceTicketValidator so that is why the exception appears to come from an unexpected class.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 07:42:00 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17769#M7881</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-08-31T07:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17770#M7882</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your message and detailed answer @Ian Wright&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, it is a quite old CAS for dev and testing purposes. I configured&amp;nbsp;CAS&amp;nbsp;with Alfresco 4.0 and Alfresco 4.2 in the past. &amp;nbsp;The CAS server logs show that authentication succeeded, the ticket is sent and there are no obvious errors or communication problems.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe the CAS&amp;nbsp;client jar included in the AMP is too new for this CAS server version. Will be possible to change CAS client version ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From your message, I did not understand this part. May you clarify it a little bit more ?&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;It doesn't need any special config other than to have the URL matching a registered service (mine is a bit more complicated using the usernameAttributeProvider but again that shouldn't make any difference)&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards and thanks in advance.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 08:26:07 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17770#M7882</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2017-08-31T08:26:07Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17771#M7883</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should be possible to just change the cas client jar if you want to try that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use email address to login but use uid as the alfresco username so CAS is configured to return the uid instead of mail as the principal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CAS client github page might help&amp;nbsp;&lt;A class="link-titled" href="https://github.com/apereo/java-cas-client" title="https://github.com/apereo/java-cas-client" rel="nofollow noopener noreferrer"&gt;GitHub - apereo/java-cas-client: Apereo Java CAS Client&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Aug 2017 08:32:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17771#M7883</guid>
      <dc:creator>idwright</dc:creator>
      <dc:date>2017-08-31T08:32:33Z</dc:date>
    </item>
    <item>
      <title>Re: Alfresco 5.2 SSO-CAS question</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17772#M7884</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We use mod_auth_cas. We've just upgraded from 5.1.3 to 5.2.3. We followed the instructions at &lt;A class="link-titled" href="https://docs.alfresco.com/community5.0/concepts/alf-modauthcas-home.html" title="https://docs.alfresco.com/community5.0/concepts/alf-modauthcas-home.html" rel="nofollow noopener noreferrer"&gt;Using Alfresco with CAS authentication through Apache mod_auth_cas | Alfresco Documentation&lt;/A&gt; .&lt;/P&gt;&lt;P&gt;We use the Apereo CAS 5.2.4 server and have found it to be reliable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 May 2018 03:59:41 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/alfresco-5-2-sso-cas-question/m-p/17772#M7884</guid>
      <dc:creator>pcharsle</dc:creator>
      <dc:date>2018-05-28T03:59:41Z</dc:date>
    </item>
  </channel>
</rss>

