Skip to Content.
Sympa Menu

grouper-users - Re: [grouper-users] Grouper UI authentication with CAS

Subject: Grouper Users - Open Discussion List

List archive

Re: [grouper-users] Grouper UI authentication with CAS


Chronological Thread 
  • From: Robert Bradley <>
  • To:
  • Subject: Re: [grouper-users] Grouper UI authentication with CAS
  • Date: Fri, 21 Aug 2015 16:20:13 +0100

On 21/08/15 14:07, Waldbieser, Carl wrote:
> Baron,
>
> We just ended up placing an authenticating CAS proxy in front of the
> Grouper UI. I had success with both mod_auth_cas [1] and txcasproxy
> [2] in development. We are currently using mod_auth_cas in
> production.
>
> Basically, you can use any authenticating proxy that either sets
> "REMOTE_USER" as an environment variable in the Grouper process or
> sets "REMOTE_USER" as an HTTP header. Grouper must explicitly be
> configured to accept the authenticated user as a header. The name is
> configurable, too.
>


I think if you go down that route, you need the web.xml modifications
from
https://spaces.internet2.edu/display/Grouper/Newcastle+University+-+Protecting+UI+With+Shib,
but otherwise I would suggest that method too. We are using Apache and
mod_webauth in a similar setup and it works well.

--
Dr Robert Bradley
Identity and Access Management, IT Services, University of Oxford

Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.16.

Top of Page