<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-15449</id>
	<title>Nabble - CAS Users</title>
	<updated>2008-07-24T11:23:40Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/CAS-Users-f15449.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS-Users-f15449.html" />
	<subtitle type="html"></subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-18637857</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T11:23:40Z</published>
	<updated>2008-07-24T11:23:40Z</updated>
	<author>
		<name>Michael Ströder</name>
	</author>
	<content type="html">Scott Battaglia wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Thu, Jul 24, 2008 at 1:24 PM, Michael Ströder &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637857&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt; 
&lt;br&gt;&amp;gt; &amp;lt;mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637857&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Matthew Jones wrote:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; We already have OpenLDAP installed (although this is another
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; area of non-expertise on my part - just don't ask why I've got
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; this job
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; at all!) and it is set up to be suitable for use by the
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; FastBindLdapAdaptor, i.e. authenticate by binding to LDAP using the
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;gt; users credentials.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; LDAP Fast bind is a proprietary feature of MS AD. It likely won't work
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; with OpenLDAP.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; We've used Fast Bind with Sun's LDAP server. &amp;nbsp;Same name for different 
&lt;br&gt;&amp;gt; things?
&lt;/div&gt;&lt;br&gt;Maybe Sun implemented that too. I can't check at the moment. But it 
&lt;br&gt;makes no sense with OpenLDAP.
&lt;br&gt;&lt;br&gt;AFAIK in MS AD nested group membership is resolved when doing a normal 
&lt;br&gt;simple bind and put into an attribute 'tokenGroups'. This is bad for 
&lt;br&gt;performance, hence the &amp;quot;fast bind&amp;quot;.
&lt;br&gt;&lt;br&gt;Further reading:
&lt;br&gt;&lt;a href=&quot;http://msdn.microsoft.com/en-us/library/aa367028.aspx&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://msdn.microsoft.com/en-us/library/aa367028.aspx&lt;/a&gt;&lt;br&gt;&lt;br&gt;Ciao, Michael.
&lt;br&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637857&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18637857.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18637297</id>
	<title>Re: ldap onto uportal 3.0.1</title>
	<published>2008-07-24T10:54:09Z</published>
	<updated>2008-07-24T10:54:09Z</updated>
	<author>
		<name>Kim, Soo Il</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;In security.properties&lt;br&gt;&lt;br&gt;Comment out &amp;quot;CLogin Channel Login link&amp;quot; to display local login (admin/admin ...)&lt;br&gt;&lt;br&gt;#org.jasig.portal.channels.CLogin.CasLoginUrl=...&lt;br&gt;&lt;br&gt;It should display login form in the left side. So you can login as admin.&lt;br&gt;
&lt;br&gt;SOO&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 1:23 PM, Adnan Tahir &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atahir@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;









&lt;div link=&quot;blue&quot; vlink=&quot;purple&quot; lang=&quot;EN-US&quot;&gt;

&lt;div&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;Hello,&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;Thanks for the info.&amp;nbsp; I am doing exactly that.&amp;nbsp; Now I cant even
log in using admin admin or staff staff.&amp;nbsp; Does that mean my LDAP settings are
incorrect? &lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;Thanks&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;Adnan&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 11pt; color: rgb(31, 73, 125);&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;div style=&quot;border-style: solid none none; border-color: rgb(181, 196, 223) -moz-use-text-color -moz-use-text-color; border-width: 1pt medium medium; padding: 3pt 0in 0in;&quot;&gt;

&lt;p&gt;&lt;b&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style=&quot;font-size: 10pt;&quot;&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas-bounces@...&lt;/a&gt;
[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas-bounces@...&lt;/a&gt;] &lt;b&gt;On Behalf Of &lt;/b&gt;SOO KIM&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Thursday, July 24, 2008 12:42 PM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Yale CAS mailing list&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Re: ldap onto uportal 3.0.1&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;Wj3C7c&quot;&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;div&gt;

&lt;p style=&quot;margin-bottom: 12pt;&quot;&gt;Hi,&lt;br&gt;
&lt;br&gt;
UP3 is now bundled with CAS. You have to configure CAS to authenticate against
your ldap.&lt;br&gt;
&lt;br&gt;
I have setup UP3 (CAS) to authenticate against AD. It works very well.&lt;br&gt;
&lt;br&gt;
In case you miss,&lt;br&gt;
&lt;br&gt;
See &lt;a href=&quot;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
SOO&lt;/p&gt;

&lt;div&gt;

&lt;p&gt;On Thu, Jul 24, 2008 at 12:16 PM, Adnan Tahir &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atahir@...&lt;/a&gt;&amp;gt; wrote:&lt;/p&gt;

&lt;div&gt;

&lt;div&gt;

&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;I am trying to setup LDAP onto uPortal &lt;a href=&quot;http://3.0.1.&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;3.0.1.&lt;/a&gt;&amp;nbsp; for some reason I am unable to do
it.&amp;nbsp;&amp;nbsp;&amp;nbsp; If there is any documentation on this issue, please let
me know.&amp;nbsp; Any help from you in this matter will be highly appreciated.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: teal;&quot;&gt;Adnan Tahir&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;Technical Support Specialist 1&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: teal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 10pt; color: teal;&quot;&gt;Manchester Community College&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;1066 Front Street, Manchester, NH
03102&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;603-396-1360 (Cell)&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;603-668-6706 ext. 380&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: rgb(0, 104, 87);&quot;&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ndhakar@...&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: teal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;Opportunities. For Now … for Life.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: rgb(0, 104, 87); letter-spacing: 1pt;&quot;&gt;&lt;a href=&quot;http://www.manchestercommunitycollege.edu/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span style=&quot;color: rgb(0, 104, 87);&quot;&gt;www.manchestercommunitycollege.edu&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;


&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p style=&quot;margin-bottom: 12pt;&quot;&gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;&lt;br&gt;
&lt;br clear=&quot;all&quot;&gt;
&lt;br&gt;
-- &lt;br&gt;
-----------------&lt;br&gt;
SOO IL KIM&lt;br&gt;
&lt;a href=&quot;http://kimsooil.com&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;kimsooil.com&lt;/a&gt;&lt;br&gt;
-------------------- &lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;

&lt;/div&gt;


&lt;br&gt;_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;-----------------&lt;br&gt;SOO IL KIM&lt;br&gt;&lt;a href=&quot;http://kimsooil.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kimsooil.com&lt;/a&gt;&lt;br&gt;--------------------
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637297&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ldap-onto-uportal-3.0.1-tp18635596p18637297.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18637284</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T10:51:18Z</published>
	<updated>2008-07-24T10:51:18Z</updated>
	<author>
		<name>scott_battaglia</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;You may need &amp;nbsp;to add another environmental property:&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;java.naming.security.protocol=ssl&lt;/div&gt;&lt;div&gt;(similar to the way you have java.naming.security.authentication set up) since you using LDAPS.&lt;/div&gt;
&lt;div&gt;&lt;br&gt;&lt;/div&gt;&lt;div&gt;-Scott&lt;/div&gt;&lt;div&gt;&lt;br clear=&quot;all&quot;&gt;-Scott Battaglia&lt;br&gt;PGP Public Key Id: 0x383733AA&lt;br&gt;LinkedIn: &lt;a href=&quot;http://www.linkedin.com/in/scottbattaglia&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.linkedin.com/in/scottbattaglia&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 11:41 AM, Matthew Jones &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637284&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matthew.jones@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
Welcome to CAS! &amp;nbsp;I&amp;#39;m not an LDAP expert either (we also don&amp;#39;t use Fastbind),&lt;br&gt;
but I&amp;#39;ll try to provide some basic guidance and then our OpenLDAP experts&lt;br&gt;
can chime in (we have a few).&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
Great, I need help.&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
No need to put anything there! &amp;nbsp;The ContextSource is generic so it can be&lt;br&gt;
used for both the FastBind and the other option.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
I tried it without userName and password properties as in the enclosed config file (modified LDAP URL)&lt;br&gt;
&lt;br&gt;
That is no userName or password properties so that sounds correct?&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
The UsernamePasswordCredentialsToPrincipalResolver should actually be&lt;br&gt;
configured already in your deployerConfigContext.xml. &amp;nbsp;Unless you&amp;#39;ve removed&lt;br&gt;
it, there&amp;#39;s no need to do anything with it!&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
No I haven&amp;#39;t removed it and I assumed that part didn&amp;#39;t need changing as it wasn&amp;#39;t mentioned&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
Have you tried starting up your CAS server after configuring it with LDAP?&lt;br&gt;
If you&amp;#39;ve got any Spring configuration issues you&amp;#39;ll see them. &amp;nbsp;If you have&lt;br&gt;
authentication issues you may not see them until you turn your logging level&lt;br&gt;
up (in the WEB-INF/classes/log4j.properties you can set it to DEBUG instead&lt;br&gt;
of INFO or WARN).&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
When I tried with the attached deployer config it refused to start. Let me say here that my Tomcat configuration is challenging as I have to run on Centos and it already had an old JDK installed on it. I had to wrestle with an eel just to get the 1.5 Sun JDK on there and used by Tomcat. I had to manually tweak a link to get it to run at all and I couldn&amp;#39;t get the update-alternatives thing to work. Anyway, I get some &amp;quot;errors&amp;quot; even when starting tomcat without CAS with LDAP :-&lt;br&gt;

&lt;br&gt;
Starting tomcat5: /usr/bin/rebuild-jar-repository: error: JVM_LIBDIR /usr/lib/jvm-exports/java does not exist or is not a directory&lt;br&gt;
/usr/bin/rebuild-jar-repository: error: JVM_LIBDIR&lt;br&gt;
(repeated 3 times)&lt;br&gt;
&lt;br&gt;
catalina.out contains:-&lt;br&gt;
log4j:ERROR setFile(null,true) call failed.&lt;br&gt;
java.io.FileNotFoundException: cas.log (Permission denied)&lt;br&gt;
&lt;br&gt;
But I can log into CAS using the simple authenticator so it&amp;#39;s not completely fatal&lt;br&gt;
&lt;br&gt;
Anyway, I then switch to the attached deployerConfigControl.xml and I lose the CAS login page altogether and just receive a message thus:&lt;br&gt;
&lt;br&gt;
HTTP Status 404 - /cas-server-webapp-3.2.1/index.jsp&lt;br&gt;
&lt;br&gt;
type Status report&lt;br&gt;
&lt;br&gt;
message /cas-server-webapp-3.2.1/index.jsp&lt;br&gt;
&lt;br&gt;
description The requested resource (/cas-server-webapp-3.2.1/index.jsp) is not available.&lt;br&gt;
Apache Tomcat/5.5.23&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex&quot;&gt;
Sun also has some LDAP specific logging stuff.&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
Cheers&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;Wj3C7c&quot;&gt;&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Matthew Jones&lt;br&gt;
Interactive Data Managed Solutions Ltd&lt;br&gt;
-----------------------------------------------------------------------&lt;br&gt;
Registered in England Company Number 3691868&lt;br&gt;
Registered Office: Suite 1101 Eagle Tower | Montpellier Drive | Cheltenham | Gloucestershire | GL50 1TA&lt;br&gt;
Tel: +44 (0)1242 694133 | Fax: +44 (0)1242 694109&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637284&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matthew.jones@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.interactivedata-ms.com/694133&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.interactivedata-ms.com/694133&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637284&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637284&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18637284.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18637187</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T10:46:56Z</published>
	<updated>2008-07-24T10:46:56Z</updated>
	<author>
		<name>scott_battaglia</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 1:24 PM, Michael Ströder &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637187&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;michael@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;Matthew Jones wrote:&lt;br&gt;
&amp;gt; We already have OpenLDAP installed (although this is another&lt;br&gt;
&amp;gt; area of non-expertise on my part - just don&amp;#39;t ask why I&amp;#39;ve got this job&lt;br&gt;
&amp;gt; at all!) and it is set up to be suitable for use by the&lt;br&gt;
&amp;gt; FastBindLdapAdaptor, i.e. authenticate by binding to LDAP using the&lt;br&gt;
&amp;gt; users credentials.&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;LDAP Fast bind is a proprietary feature of MS AD. It likely won&amp;#39;t work&lt;br&gt;
with OpenLDAP.&lt;br&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div&gt;We&amp;#39;ve used Fast Bind with Sun&amp;#39;s LDAP server. &amp;nbsp;Same name for different things?&lt;/div&gt;&lt;div&gt;-Scott&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;&quot;&gt;
&lt;div class=&quot;Ih2E3d&quot;&gt;&lt;br&gt;
&amp;gt; Now, I see that I should have an AuthenticatedLdapContextSource bean&lt;br&gt;
&amp;gt; configured but this has parameters (property) such as userName and&lt;br&gt;
&amp;gt; Password. Given that these values should come from the CAS login screen&lt;br&gt;
&amp;gt; what should I put here?&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;These parameters are for the service user who&amp;#39;s searching for user&lt;br&gt;
entries. That&amp;#39;s not the user name from the CAS login screen. It&amp;#39;s a&lt;br&gt;
bind-DN and the accompanying password. You need that if access control&lt;br&gt;
on the LDAP server is tight and does not allow anonymous searching for&lt;br&gt;
user entries (e.g. that&amp;#39;s the default case for MS AD).&lt;br&gt;
&lt;br&gt;
Ciao, Michael.&lt;br&gt;
&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;Wj3C7c&quot;&gt;_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637187&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18637187&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18637187.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18636808</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T10:24:39Z</published>
	<updated>2008-07-24T10:24:39Z</updated>
	<author>
		<name>Michael Ströder</name>
	</author>
	<content type="html">Matthew Jones wrote:
&lt;br&gt;&amp;gt; We already have OpenLDAP installed (although this is another
&lt;br&gt;&amp;gt; area of non-expertise on my part - just don't ask why I've got this job
&lt;br&gt;&amp;gt; at all!) and it is set up to be suitable for use by the
&lt;br&gt;&amp;gt; FastBindLdapAdaptor, i.e. authenticate by binding to LDAP using the
&lt;br&gt;&amp;gt; users credentials.
&lt;br&gt;&lt;br&gt;LDAP Fast bind is a proprietary feature of MS AD. It likely won't work 
&lt;br&gt;with OpenLDAP.
&lt;br&gt;&lt;br&gt;&amp;gt; Now, I see that I should have an AuthenticatedLdapContextSource bean
&lt;br&gt;&amp;gt; configured but this has parameters (property) such as userName and
&lt;br&gt;&amp;gt; Password. Given that these values should come from the CAS login screen
&lt;br&gt;&amp;gt; what should I put here?
&lt;br&gt;&lt;br&gt;These parameters are for the service user who's searching for user 
&lt;br&gt;entries. That's not the user name from the CAS login screen. It's a 
&lt;br&gt;bind-DN and the accompanying password. You need that if access control 
&lt;br&gt;on the LDAP server is tight and does not allow anonymous searching for 
&lt;br&gt;user entries (e.g. that's the default case for MS AD).
&lt;br&gt;&lt;br&gt;Ciao, Michael.
&lt;br&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636808&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18636808.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18636768</id>
	<title>RE: ldap onto uportal 3.0.1</title>
	<published>2008-07-24T10:23:01Z</published>
	<updated>2008-07-24T10:23:01Z</updated>
	<author>
		<name>Adnan Tahir</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Hello,&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Thanks for the info.&amp;nbsp; I am doing exactly that.&amp;nbsp; Now I cant even
log in using admin admin or staff staff.&amp;nbsp; Does that mean my LDAP settings are
incorrect? &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Thanks&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;Adnan&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:11.0pt;font-family:&quot;Calibri&quot;,&quot;sans-serif&quot;;
color:#1F497D'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;div style='border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt;From:&lt;/span&gt;&lt;/b&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;'&gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas-bounces@...&lt;/a&gt;
[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas-bounces@...&lt;/a&gt;] &lt;b&gt;On Behalf Of &lt;/b&gt;SOO KIM&lt;br&gt;
&lt;b&gt;Sent:&lt;/b&gt; Thursday, July 24, 2008 12:42 PM&lt;br&gt;
&lt;b&gt;To:&lt;/b&gt; Yale CAS mailing list&lt;br&gt;
&lt;b&gt;Subject:&lt;/b&gt; Re: ldap onto uportal 3.0.1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;Hi,&lt;br&gt;
&lt;br&gt;
UP3 is now bundled with CAS. You have to configure CAS to authenticate against
your ldap.&lt;br&gt;
&lt;br&gt;
I have setup UP3 (CAS) to authenticate against AD. It works very well.&lt;br&gt;
&lt;br&gt;
In case you miss,&lt;br&gt;
&lt;br&gt;
See &lt;a href=&quot;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
SOO&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;div&gt;

&lt;p class=MsoNormal&gt;On Thu, Jul 24, 2008 at 12:16 PM, Adnan Tahir &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atahir@...&lt;/a&gt;&amp;gt; wrote:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;div&gt;

&lt;div&gt;

&lt;p&gt;Hello,&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;I am trying to setup LDAP onto uPortal &lt;a href=&quot;http://3.0.1.&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;3.0.1.&lt;/a&gt;&amp;nbsp; for some reason I am unable to do
it.&amp;nbsp;&amp;nbsp;&amp;nbsp; If there is any documentation on this issue, please let
me know.&amp;nbsp; Any help from you in this matter will be highly appreciated.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;Thanks&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;&lt;span style='color:teal'&gt;Adnan Tahir&lt;/span&gt;&lt;/b&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:black'&gt;Technical Support Specialist 1&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:teal'&gt;&amp;nbsp;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:10.0pt;color:teal'&gt;Manchester Community College&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:black'&gt;1066 Front Street, Manchester, NH
03102&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:black'&gt;603-396-1360 (Cell)&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:black'&gt;603-668-6706 ext. 380&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:#006857'&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ndhakar@...&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:teal'&gt;&amp;nbsp;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:black'&gt;Opportunities. For Now &amp;#8230; for Life.&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style='font-size:9.0pt;color:#006857;letter-spacing:1.0pt'&gt;&lt;a href=&quot;http://www.manchestercommunitycollege.edu/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span style='color:#006857'&gt;www.manchestercommunitycollege.edu&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;p class=MsoNormal style='margin-bottom:12.0pt'&gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;p class=MsoNormal&gt;&lt;br&gt;
&lt;br clear=all&gt;
&lt;br&gt;
-- &lt;br&gt;
-----------------&lt;br&gt;
SOO IL KIM&lt;br&gt;
&lt;a href=&quot;http://kimsooil.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kimsooil.com&lt;/a&gt;&lt;br&gt;
-------------------- &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636768&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ldap-onto-uportal-3.0.1-tp18635596p18636768.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18636033</id>
	<title>Re: ldap onto uportal 3.0.1</title>
	<published>2008-07-24T09:41:57Z</published>
	<updated>2008-07-24T09:41:57Z</updated>
	<author>
		<name>Kim, Soo Il</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;Hi,&lt;br&gt;&lt;br&gt;UP3 is now bundled with CAS. You have to configure CAS to authenticate against your ldap.&lt;br&gt;&lt;br&gt;I have setup UP3 (CAS) to authenticate against AD. It works very well.&lt;br&gt;&lt;br&gt;In case you miss,&lt;br&gt;
&lt;br&gt;See &lt;a href=&quot;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.ja-sig.org/wiki/display/UPM30/04+Authenticating+Against+LDAP&lt;/a&gt;&lt;br&gt;&lt;br&gt;SOO&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 12:16 PM, Adnan Tahir &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636033&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;atahir@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;








&lt;div link=&quot;blue&quot; vlink=&quot;purple&quot; lang=&quot;EN-US&quot;&gt;

&lt;div&gt;

&lt;p&gt;Hello,&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;I am trying to setup LDAP onto uPortal &lt;a href=&quot;http://3.0.1.&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;3.0.1.&lt;/a&gt;&amp;nbsp; for some
reason I am unable to do it.&amp;nbsp;&amp;nbsp;&amp;nbsp; If there is any documentation on this issue,
please let me know.&amp;nbsp; Any help from you in this matter will be highly
appreciated.&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: teal;&quot;&gt;Adnan Tahir&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;Technical Support Specialist 1&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: teal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 10pt; color: teal;&quot;&gt;Manchester Community College&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;1066 Front Street, Manchester, NH 03102&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;603-396-1360 (Cell)&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;603-668-6706 ext. 380&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: rgb(0, 104, 87);&quot;&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636033&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ndhakar@...&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 9pt; color: rgb(0, 104, 87);&quot;&gt;&lt;/span&gt;&lt;/p&gt;


&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: teal;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: black;&quot;&gt;Opportunities. For Now … for Life.&lt;/span&gt;&lt;/p&gt;

&lt;p&gt;&lt;span style=&quot;font-size: 9pt; color: rgb(0, 104, 87); letter-spacing: 1pt;&quot;&gt;&lt;a href=&quot;http://www.manchestercommunitycollege.edu/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;&lt;span style=&quot;color: rgb(0, 104, 87);&quot;&gt;www.manchestercommunitycollege.edu&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;font-size: 9pt; color: maroon;&quot;&gt;&lt;/span&gt;&lt;/p&gt;


&lt;p&gt;&amp;nbsp;&lt;/p&gt;

&lt;/div&gt;

&lt;/div&gt;


&lt;br&gt;_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636033&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;-----------------&lt;br&gt;SOO IL KIM&lt;br&gt;&lt;a href=&quot;http://kimsooil.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;kimsooil.com&lt;/a&gt;&lt;br&gt;--------------------
&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18636033&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ldap-onto-uportal-3.0.1-tp18635596p18636033.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18635596</id>
	<title>ldap onto uportal 3.0.1</title>
	<published>2008-07-24T09:16:28Z</published>
	<updated>2008-07-24T09:16:28Z</updated>
	<author>
		<name>Adnan Tahir</name>
	</author>
	<content type="html">&lt;html xmlns:v=&quot;urn:schemas-microsoft-com:vml&quot; xmlns:o=&quot;urn:schemas-microsoft-com:office:office&quot; xmlns:w=&quot;urn:schemas-microsoft-com:office:word&quot; xmlns:m=&quot;http://schemas.microsoft.com/office/2004/12/omml&quot; xmlns=&quot;http://www.w3.org/TR/REC-html40&quot;&gt;

&lt;head&gt;
&lt;META HTTP-EQUIV=&quot;Content-Type&quot; CONTENT=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;meta name=Generator content=&quot;Microsoft Word 12 (filtered medium)&quot;&gt;

&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapedefaults v:ext=&quot;edit&quot; spidmax=&quot;1026&quot; /&gt;
&lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;
 &lt;o:shapelayout v:ext=&quot;edit&quot;&gt;
  &lt;o:idmap v:ext=&quot;edit&quot; data=&quot;1&quot; /&gt;
 &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;
&lt;/head&gt;

&lt;body lang=EN-US link=blue vlink=purple&gt;

&lt;div class=Section1&gt;

&lt;p class=MsoNormal&gt;Hello,&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;I am trying to setup LDAP onto uPortal 3.0.1.&amp;nbsp; for some
reason I am unable to do it.&amp;nbsp;&amp;nbsp;&amp;nbsp; If there is any documentation on this issue,
please let me know.&amp;nbsp; Any help from you in this matter will be highly
appreciated.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;Thanks&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;b&gt;&lt;span style='font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:teal'&gt;Adnan Tahir&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:black'&gt;Technical Support Specialist 1&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Copperplate Gothic Bold&quot;,&quot;sans-serif&quot;;
color:teal'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:10.0pt;font-family:&quot;Copperplate Gothic Bold&quot;,&quot;sans-serif&quot;;
color:teal'&gt;Manchester Community College&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:black'&gt;1066 Front Street, Manchester, NH 03102&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:black'&gt;603-396-1360 (Cell)&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:black'&gt;603-668-6706 ext. 380&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:#006857'&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635596&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ndhakar@...&lt;/a&gt;&lt;/span&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;color:#006857'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:teal'&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:black'&gt;Opportunities. For Now &amp;#8230; for Life.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;span style='font-size:9.0pt;font-family:&quot;Gill Sans MT&quot;,&quot;sans-serif&quot;;
color:#006857;letter-spacing:1.0pt'&gt;&lt;a href=&quot;http://www.manchestercommunitycollege.edu/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;&lt;span style='color:#006857'&gt;www.manchestercommunitycollege.edu&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;span style='font-size:9.0pt;color:maroon'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;

&lt;p class=MsoNormal&gt;&lt;o:p&gt;&amp;nbsp;&lt;/o:p&gt;&lt;/p&gt;

&lt;/div&gt;

&lt;/body&gt;

&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635596&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ldap-onto-uportal-3.0.1-tp18635596p18635596.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18635475</id>
	<title>Re: Why mod_jk ?</title>
	<published>2008-07-24T09:07:53Z</published>
	<updated>2008-07-24T09:07:53Z</updated>
	<author>
		<name>Romain Bourgue</name>
	</author>
	<content type="html">Ooops... I forgot THE major feature of mod_jk : the load-balancer/cluster manager :
&lt;br&gt;With mod_jk, you can very easily balance your web load to a cluster of tomcat.
&lt;br&gt;It's safe, easy and highly scalable...! another reason to put an apache httpd 
&lt;br&gt;frontend in front of your tomcat(s)...
&lt;br&gt;&lt;br&gt;&lt;br&gt;-Romain
&lt;br&gt;&lt;br&gt;Romain BOURGUE a écrit :
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Provided you add this mod_ssl directive to your apache configuration
&lt;br&gt;&amp;gt; &amp;nbsp; SSLOptions +ExportCertData
&lt;br&gt;&amp;gt; mod_jk does forward the certData to the tomcat backend server.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I add my 2 cents to the debate : Apache httpd is a an http server. Tomcat is an 
&lt;br&gt;&amp;gt; application server with an http connector : It's not tomcat's main objectiv to 
&lt;br&gt;&amp;gt; serve http static resources, it's Apache httpd's. Therefore, you'll have much 
&lt;br&gt;&amp;gt; more possibilities handling and securing http requests on Apache httpd than 
&lt;br&gt;&amp;gt; you'll have with Tomcat.
&lt;br&gt;&amp;gt; Furthermore, with heavy web traffic you need to lighten the load on your Tomcat, 
&lt;br&gt;&amp;gt; so it's good pratice to have your static files (html, images, css...) served by 
&lt;br&gt;&amp;gt; the Apache httpd and have only the dynamic resources forwarded to the tomcat.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; In development environment though, a standalone tomcat is perfect...
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -Romain
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt; a écrit :
&lt;br&gt;&amp;gt;&amp;gt; Thank you for you answers.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; As you are speaking about SSL, do you know if client certificats are
&lt;br&gt;&amp;gt;&amp;gt; forwarded to CAS X509 handler when Tomecat is behind the Apache/mod_jk
&lt;br&gt;&amp;gt;&amp;gt; or Apache/mod_proxy_ajp ?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Stéphane
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On 7/24/08, Andrew Ralph Feller, afelle1 &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;afelle1@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; For those who need to support Java applications along with PHP / Perl
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; applications, they could host both from the same machine by having Apache
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; httpd front-end Apache Tomcat. &amp;nbsp;There is a another reason why some people
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; use mod_jk + Tomcat: inexperience in managing Tomcat. &amp;nbsp;When I was starting
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; out, I hated working with keystores as it wasn¹t nearly as straight forward
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; as Apache httpd¹s mod_ssl configuration. &amp;nbsp;Once I found how to setup the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Apache Portable Runtime in Tomcat, then I felt comfortable not having Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; front-ended as the APR configuration is extremely similar to mod_ssl.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On a tangential note, there is an alternative to mod_jk called
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; mod_proxy_ajp, which comes with Apache httpd 2.2 and works in a similar
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; manner.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On 7/24/08 6:12 AM, &amp;quot;Siegfried Puchbauer&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;siegfried.puchbauer@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; You can gain a lot of flexibility when you choose to use Apache in front
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; your Tomcat backend. For example a very flexible way to perform name-based
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; virtual hosting. Also mod_rewrite is great to perform dynamic redirects
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; using
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; regexes. And the reverse-proxy capabilities by mod_proxy are also very
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; useful
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; - especially when using other application in the same url-space. You can
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; also
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; use it to display a service unavailibilty information when you
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; upgrade/restart
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; you tomcat. If you do not have the need of rewriteing urls, perform
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; virtual-hosting there is IMHO no reason to not choose a standalone tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Cheers, sigi
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Siegfried Puchbauer
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://siegfried.puchbauer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://siegfried.puchbauer.com/&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Jul 24, 2008 at 11:55, Stéphane Gully &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is a generic question, not directly related to CAS. I'm sorry for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; that.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Google didn't helped me so I try here.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; When I installed CAS, I had the choice to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; or in Apache/mod_jk+Tomcat. I chosed to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; because I needed X509 authentication handler and it just looked more
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; easy to configure directly in Tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I often read that mod_jk should be used but I never know why ? could
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; someone tell me the reason(s) ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; regards,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Stéphane GULLY
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Andrew R. Feller, Analyst
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Information Technology Services
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 200 Fred Frey Building
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Louisiana State University
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Baton Rouge, LA 70803
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (225) 578-3737 (Office)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; (225) 578-6400 (Fax)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;/div&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635475&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Why-mod_jk---tp18628722p18635475.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18635183</id>
	<title>Re: Why mod_jk ?</title>
	<published>2008-07-24T08:44:40Z</published>
	<updated>2008-07-24T08:44:40Z</updated>
	<author>
		<name>Romain Bourgue</name>
	</author>
	<content type="html">Provided you add this mod_ssl directive to your apache configuration
&lt;br&gt;&amp;nbsp; SSLOptions +ExportCertData
&lt;br&gt;mod_jk does forward the certData to the tomcat backend server.
&lt;br&gt;&lt;br&gt;I add my 2 cents to the debate : Apache httpd is a an http server. Tomcat is an 
&lt;br&gt;application server with an http connector : It's not tomcat's main objectiv to 
&lt;br&gt;serve http static resources, it's Apache httpd's. Therefore, you'll have much 
&lt;br&gt;more possibilities handling and securing http requests on Apache httpd than 
&lt;br&gt;you'll have with Tomcat.
&lt;br&gt;Furthermore, with heavy web traffic you need to lighten the load on your Tomcat, 
&lt;br&gt;so it's good pratice to have your static files (html, images, css...) served by 
&lt;br&gt;the Apache httpd and have only the dynamic resources forwarded to the tomcat.
&lt;br&gt;&lt;br&gt;In development environment though, a standalone tomcat is perfect...
&lt;br&gt;&lt;br&gt;-Romain
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt; a écrit :
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thank you for you answers.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; As you are speaking about SSL, do you know if client certificats are
&lt;br&gt;&amp;gt; forwarded to CAS X509 handler when Tomecat is behind the Apache/mod_jk
&lt;br&gt;&amp;gt; or Apache/mod_proxy_ajp ?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Stéphane
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On 7/24/08, Andrew Ralph Feller, afelle1 &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;afelle1@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; For those who need to support Java applications along with PHP / Perl
&lt;br&gt;&amp;gt;&amp;gt; applications, they could host both from the same machine by having Apache
&lt;br&gt;&amp;gt;&amp;gt; httpd front-end Apache Tomcat. &amp;nbsp;There is a another reason why some people
&lt;br&gt;&amp;gt;&amp;gt; use mod_jk + Tomcat: inexperience in managing Tomcat. &amp;nbsp;When I was starting
&lt;br&gt;&amp;gt;&amp;gt; out, I hated working with keystores as it wasn¹t nearly as straight forward
&lt;br&gt;&amp;gt;&amp;gt; as Apache httpd¹s mod_ssl configuration. &amp;nbsp;Once I found how to setup the
&lt;br&gt;&amp;gt;&amp;gt; Apache Portable Runtime in Tomcat, then I felt comfortable not having Tomcat
&lt;br&gt;&amp;gt;&amp;gt; front-ended as the APR configuration is extremely similar to mod_ssl.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On a tangential note, there is an alternative to mod_jk called
&lt;br&gt;&amp;gt;&amp;gt; mod_proxy_ajp, which comes with Apache httpd 2.2 and works in a similar
&lt;br&gt;&amp;gt;&amp;gt; manner.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On 7/24/08 6:12 AM, &amp;quot;Siegfried Puchbauer&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;siegfried.puchbauer@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; You can gain a lot of flexibility when you choose to use Apache in front
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; your Tomcat backend. For example a very flexible way to perform name-based
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; virtual hosting. Also mod_rewrite is great to perform dynamic redirects
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; using
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; regexes. And the reverse-proxy capabilities by mod_proxy are also very
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; useful
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; - especially when using other application in the same url-space. You can
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; also
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; use it to display a service unavailibilty information when you
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; upgrade/restart
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; you tomcat. If you do not have the need of rewriteing urls, perform
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; virtual-hosting there is IMHO no reason to not choose a standalone tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Cheers, sigi
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Siegfried Puchbauer
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://siegfried.puchbauer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://siegfried.puchbauer.com/&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Jul 24, 2008 at 11:55, Stéphane Gully &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is a generic question, not directly related to CAS. I'm sorry for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; that.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Google didn't helped me so I try here.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; When I installed CAS, I had the choice to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; or in Apache/mod_jk+Tomcat. I chosed to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; because I needed X509 authentication handler and it just looked more
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; easy to configure directly in Tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I often read that mod_jk should be used but I never know why ? could
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; someone tell me the reason(s) ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; regards,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Stéphane GULLY
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Andrew R. Feller, Analyst
&lt;br&gt;&amp;gt;&amp;gt; Information Technology Services
&lt;br&gt;&amp;gt;&amp;gt; 200 Fred Frey Building
&lt;br&gt;&amp;gt;&amp;gt; Louisiana State University
&lt;br&gt;&amp;gt;&amp;gt; Baton Rouge, LA 70803
&lt;br&gt;&amp;gt;&amp;gt; (225) 578-3737 (Office)
&lt;br&gt;&amp;gt;&amp;gt; (225) 578-6400 (Fax)
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;/div&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635183&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Why-mod_jk---tp18628722p18635183.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18635213</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T08:41:27Z</published>
	<updated>2008-07-24T08:41:27Z</updated>
	<author>
		<name>Matthew Jones-7</name>
	</author>
	<content type="html">&amp;gt; Welcome to CAS! &amp;nbsp;I'm not an LDAP expert either (we also don't use Fastbind),
&lt;br&gt;&amp;gt; but I'll try to provide some basic guidance and then our OpenLDAP experts
&lt;br&gt;&amp;gt; can chime in (we have a few).
&lt;br&gt;&lt;br&gt;Great, I need help.
&lt;br&gt;&lt;br&gt;&amp;gt; No need to put anything there! &amp;nbsp;The ContextSource is generic so it can be
&lt;br&gt;&amp;gt; used for both the FastBind and the other option.
&lt;br&gt;&lt;br&gt;I tried it without userName and password properties as in the enclosed 
&lt;br&gt;config file (modified LDAP URL)
&lt;br&gt;&lt;br&gt;That is no userName or password properties so that sounds correct?
&lt;br&gt;&lt;br&gt;&amp;gt; The UsernamePasswordCredentialsToPrincipalResolver should actually be
&lt;br&gt;&amp;gt; configured already in your deployerConfigContext.xml. &amp;nbsp;Unless you've removed
&lt;br&gt;&amp;gt; it, there's no need to do anything with it!
&lt;br&gt;&lt;br&gt;No I haven't removed it and I assumed that part didn't need changing as 
&lt;br&gt;it wasn't mentioned
&lt;br&gt;&lt;br&gt;&amp;gt; Have you tried starting up your CAS server after configuring it with LDAP?
&lt;br&gt;&amp;gt; If you've got any Spring configuration issues you'll see them. &amp;nbsp;If you have
&lt;br&gt;&amp;gt; authentication issues you may not see them until you turn your logging level
&lt;br&gt;&amp;gt; up (in the WEB-INF/classes/log4j.properties you can set it to DEBUG instead
&lt;br&gt;&amp;gt; of INFO or WARN).
&lt;br&gt;&lt;br&gt;When I tried with the attached deployer config it refused to start. Let 
&lt;br&gt;me say here that my Tomcat configuration is challenging as I have to run 
&lt;br&gt;on Centos and it already had an old JDK installed on it. I had to 
&lt;br&gt;wrestle with an eel just to get the 1.5 Sun JDK on there and used by 
&lt;br&gt;Tomcat. I had to manually tweak a link to get it to run at all and I 
&lt;br&gt;couldn't get the update-alternatives thing to work. Anyway, I get some 
&lt;br&gt;&amp;quot;errors&amp;quot; even when starting tomcat without CAS with LDAP :-
&lt;br&gt;&lt;br&gt;Starting tomcat5: /usr/bin/rebuild-jar-repository: error: JVM_LIBDIR 
&lt;br&gt;/usr/lib/jvm-exports/java does not exist or is not a directory
&lt;br&gt;/usr/bin/rebuild-jar-repository: error: JVM_LIBDIR
&lt;br&gt;(repeated 3 times)
&lt;br&gt;&lt;br&gt;catalina.out contains:-
&lt;br&gt;log4j:ERROR setFile(null,true) call failed.
&lt;br&gt;java.io.FileNotFoundException: cas.log (Permission denied)
&lt;br&gt;&lt;br&gt;But I can log into CAS using the simple authenticator so it's not 
&lt;br&gt;completely fatal
&lt;br&gt;&lt;br&gt;Anyway, I then switch to the attached deployerConfigControl.xml and I 
&lt;br&gt;lose the CAS login page altogether and just receive a message thus:
&lt;br&gt;&lt;br&gt;HTTP Status 404 - /cas-server-webapp-3.2.1/index.jsp
&lt;br&gt;&lt;br&gt;type Status report
&lt;br&gt;&lt;br&gt;message /cas-server-webapp-3.2.1/index.jsp
&lt;br&gt;&lt;br&gt;description The requested resource (/cas-server-webapp-3.2.1/index.jsp) 
&lt;br&gt;is not available.
&lt;br&gt;Apache Tomcat/5.5.23
&lt;br&gt;&lt;br&gt;&amp;gt; Sun also has some LDAP specific logging stuff.
&lt;br&gt;&lt;br&gt;Cheers
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Matthew Jones
&lt;br&gt;Interactive Data Managed Solutions Ltd
&lt;br&gt;-----------------------------------------------------------------------
&lt;br&gt;Registered in England Company Number 3691868
&lt;br&gt;Registered Office: Suite 1101 Eagle Tower | Montpellier Drive | 
&lt;br&gt;Cheltenham | Gloucestershire | GL50 1TA
&lt;br&gt;Tel: +44 (0)1242 694133 | Fax: +44 (0)1242 694109
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635213&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matthew.jones@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.interactivedata-ms.com/694133&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.interactivedata-ms.com/694133&lt;/a&gt;&lt;br&gt;&lt;br /&gt;&amp;lt;?xml version=&amp;quot;1.0&amp;quot; encoding=&amp;quot;UTF-8&amp;quot;?&amp;gt;
&lt;br&gt;&amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | deployerConfigContext.xml centralizes into one file some of the declarative configuration that
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | all CAS deployers will need to modify.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This file declares some of the Spring-managed JavaBeans that make up a CAS deployment. &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | The beans declared in this file are instantiated at context initialization time by the Spring 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | ContextLoaderListener declared in web.xml. &amp;nbsp;It finds this file because this
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | file is among those declared in the context parameter &amp;quot;contextConfigLocation&amp;quot;.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | By far the most common change you will need to make in this file is to change the last bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | declaration to replace the default SimpleTestUsernamePasswordAuthenticationHandler with
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | one implementing your approach for authenticating usernames and passwords.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;lt;beans xmlns=&amp;quot;&lt;a href=&quot;http://www.springframework.org/schema/beans&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springframework.org/schema/beans&lt;/a&gt;&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;xmlns:xsi=&amp;quot;&lt;a href=&quot;http://www.w3.org/2001/XMLSchema-instance&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.w3.org/2001/XMLSchema-instance&lt;/a&gt;&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;xmlns:p=&amp;quot;&lt;a href=&quot;http://www.springframework.org/schema/p&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springframework.org/schema/p&lt;/a&gt;&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;xsi:schemaLocation=&amp;quot;&lt;a href=&quot;http://www.springframework.org/schema/beans&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springframework.org/schema/beans&lt;/a&gt;&amp;nbsp;&lt;a href=&quot;http://www.springframework.org/schema/beans/spring-beans-2.0.xsd&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.springframework.org/schema/beans/spring-beans-2.0.xsd&lt;/a&gt;&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This bean declares our AuthenticationManager. &amp;nbsp;The CentralAuthenticationService service bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | declared in applicationContext.xml picks up this AuthenticationManager by reference to its id, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;quot;authenticationManager&amp;quot;. &amp;nbsp;Most deployers will be able to use the default AuthenticationManager
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | implementation and so do not need to change the class of this bean. &amp;nbsp;We include the whole
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | AuthenticationManager here in the userConfigContext.xml so that you can see the things you will
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | need to change in context.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean id=&amp;quot;authenticationManager&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.authentication.AuthenticationManagerImpl&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This is the List of CredentialToPrincipalResolvers that identify what Principal is trying to authenticate.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | The AuthenticationManagerImpl considers them in order, finding a CredentialToPrincipalResolver which 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | supports the presented credentials.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | AuthenticationManagerImpl uses these resolvers for two purposes. &amp;nbsp;First, it uses them to identify the Principal
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | attempting to authenticate to CAS /login . &amp;nbsp;In the default configuration, it is the DefaultCredentialsToPrincipalResolver
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | that fills this role. &amp;nbsp;If you are using some other kind of credentials than UsernamePasswordCredentials, you will need to replace
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | DefaultCredentialsToPrincipalResolver with a CredentialsToPrincipalResolver that supports the credentials you are
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | using.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Second, AuthenticationManagerImpl uses these resolvers to identify a service requesting a proxy granting ticket. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | In the default configuration, it is the HttpBasedServiceCredentialsToPrincipalResolver that serves this purpose. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | You will need to change this list if you are identifying services by something more or other than their callback URL.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;credentialsToPrincipalResolvers&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | UsernamePasswordCredentialsToPrincipalResolver supports the UsernamePasswordCredentials that we use for /login 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | by default and produces SimplePrincipal instances conveying the username from the credentials.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | If you've changed your LoginFormAction to use credentials other than UsernamePasswordCredentials then you will also
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | need to change this bean declaration (or add additional declarations) to declare a CredentialsToPrincipalResolver that supports the
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Credentials you are using.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.authentication.principal.UsernamePasswordCredentialsToPrincipalResolver&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | HttpBasedServiceCredentialsToPrincipalResolver supports HttpBasedCredentials. &amp;nbsp;It supports the CAS 2.0 approach of
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | authenticating services by SSL callback, extracting the callback URL from the Credentials and representing it as a
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | SimpleService identified by that callback URL.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | If you are representing services by something more or other than an HTTPS URL whereat they are able to
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | receive a proxy callback, you will need to change this bean declaration (or add additional declarations).
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.authentication.principal.HttpBasedServiceCredentialsToPrincipalResolver&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Whereas CredentialsToPrincipalResolvers identify who it is some Credentials might authenticate, 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | AuthenticationHandlers actually authenticate credentials. &amp;nbsp;Here we declare the AuthenticationHandlers that
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | authenticate the Principals that the CredentialsToPrincipalResolvers identified. &amp;nbsp;CAS will try these handlers in turn
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | until it finds one that both supports the Credentials presented and succeeds in authenticating.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;authenticationHandlers&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This is the authentication handler that authenticates services by means of callback via SSL, thereby validating
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | a server side SSL certificate.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean class=&amp;quot;org.jasig.cas.authentication.handler.support.HttpBasedServiceCredentialsAuthenticationHandler&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; p:httpClient-ref=&amp;quot;httpClient&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This is the authentication handler declaration that every CAS deployer will need to change before deploying CAS
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | into production. &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | With this configuration you'll be using LDAP FastBind authentication.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.adaptors.ldap.FastBindLdapAuthenticationHandler&amp;quot; &amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;filter&amp;quot; value=&amp;quot;uid=%u,ou=idms,dc=interactivedata,dc=com&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;contextSource&amp;quot; ref=&amp;quot;contextSource&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/bean&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | This is the authentication handler declaration that every CAS deployer will need to change before deploying CAS 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | into production. &amp;nbsp;The default SimpleTestUsernamePasswordAuthenticationHandler authenticates UsernamePasswordCredentials
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | where the username equals the password. &amp;nbsp;You will need to replace this with an AuthenticationHandler that implements your
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | local authentication strategy. &amp;nbsp;You might accomplish this by coding a new such handler and declaring
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | edu.someschool.its.cas.MySpecialHandler here, or you might use one of the handlers provided in the adaptors modules.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.authentication.handler.support.SimpleTestUsernamePasswordAuthenticationHandler&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/bean&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!-- &amp;nbsp;LDAP settings
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Host: our-ldap-server
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Base DN: &amp;quot;dc=interactivedata,dc=com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Port number: 636
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Bind DN: &amp;quot;uid=&amp;lt;your userid&amp;gt;,ou=idms,dc=interactivedata,dc=com&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Bind Password: &amp;lt;your password&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; | Use SSL: Yes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; +--&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean id=&amp;quot;contextSource&amp;quot; class=&amp;quot;org.jasig.cas.adaptors.ldap.util.AuthenticatedLdapContextSource&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;pooled&amp;quot; value=&amp;quot;true&amp;quot;/&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;urls&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;value&amp;gt;ldaps://our-ldap-server/&amp;lt;/value&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/list&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;baseEnvironmentProperties&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;map&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;entry&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;key&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;value&amp;gt;java.naming.security.authentication&amp;lt;/value&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/key&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;value&amp;gt;simple&amp;lt;/value&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/entry&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/map&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/bean&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!--
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; This bean defines the security roles for the Services Management application. &amp;nbsp;Simple deployments can use the in-memory version.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; More robust deployments will want to use another option, such as the Jdbc version.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The name of this should remain &amp;quot;userDetailsService&amp;quot; in order for Acegi to find it. 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; To use this, you should add an entry similar to the following between the two value tags:
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; battags=notused,ROLE_ADMIN
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; where battags is the username you want to grant access to. &amp;nbsp;You can put one entry per line.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--&amp;gt;	
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean id=&amp;quot;userDetailsService&amp;quot; class=&amp;quot;org.acegisecurity.userdetails.memory.InMemoryDaoImpl&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;userMap&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;value&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/value&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/bean&amp;gt; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Bean that defines the attributes that a service may return. &amp;nbsp;This example uses the Stub/Mock version. &amp;nbsp;A real implementation
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; may go against a database or LDAP server. &amp;nbsp;The id should remain &amp;quot;attributeRepository&amp;quot; though.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean id=&amp;quot;attributeRepository&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.services.persondir.support.StubPersonAttributeDao&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;property name=&amp;quot;backingMap&amp;quot;&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;map&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;entry key=&amp;quot;uid&amp;quot; value=&amp;quot;uid&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;entry key=&amp;quot;eduPersonAffiliation&amp;quot; value=&amp;quot;eduPersonAffiliation&amp;quot; /&amp;gt; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;entry key=&amp;quot;groupMembership&amp;quot; value=&amp;quot;groupMembership&amp;quot; /&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/map&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/property&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;/bean&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;!-- 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Sample, in-memory data store for the ServiceRegistry. A real implementation
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; would probably want to replace this with the JPA-backed ServiceRegistry DAO
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; The name of this bean should remain &amp;quot;serviceRegistryDao&amp;quot;.
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;bean
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; id=&amp;quot;serviceRegistryDao&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; class=&amp;quot;org.jasig.cas.services.InMemoryServiceRegistryDaoImpl&amp;quot; /&amp;gt;
&lt;br&gt;&amp;lt;/beans&amp;gt;
&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18635213&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://www.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;smime.p7s&lt;/strong&gt; (3K) &lt;a href=&quot;http://www.nabble.com/attachment/18635213/0/smime.p7s&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18635213.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18633820</id>
	<title>JDK 1.5.0_8, AD and Debian</title>
	<published>2008-07-24T07:48:54Z</published>
	<updated>2008-07-24T07:48:54Z</updated>
	<author>
		<name>Martin Lamprechter</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;i tested CAS 3.2.1.1 successful under Ubuntu 8.04 with JDK 1.6 - now I 
&lt;br&gt;try under Debian etch width JDK 1.5.0_8 and i can Login with 
&lt;br&gt;ldap-connect - but not with ldaps!
&lt;br&gt;&lt;br&gt;The Logfiles just say that the User with ID xy could not be verified...
&lt;br&gt;&lt;br&gt;Configuration is the same as on the Ubuntu-Server - only different is 
&lt;br&gt;the JDK-Version...
&lt;br&gt;&lt;br&gt;Any ideas?!?
&lt;br&gt;&lt;br&gt;Best regards,
&lt;br&gt;M.L.
&lt;br&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633820&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/JDK-1.5.0_8%2C-AD-and-Debian-tp18633820p18633820.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18633638</id>
	<title>Re: Why mod_jk ?</title>
	<published>2008-07-24T07:45:23Z</published>
	<updated>2008-07-24T07:45:23Z</updated>
	<author>
		<name>Siegfried Puchbauer</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;I think so. It is mentioned in the AJP Protocol Reference for AJP 1.3...&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://tomcat.apache.org/connectors-doc/ajp/ajpv13a.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tomcat.apache.org/connectors-doc/ajp/ajpv13a.html&lt;/a&gt;&lt;br&gt;
&lt;br&gt;hth, cheers&lt;br clear=&quot;all&quot;&gt;_______________________&lt;br&gt;Siegfried Puchbauer&lt;br&gt;&lt;a href=&quot;http://siegfried.puchbauer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://siegfried.puchbauer.com/&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 15:09,  &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
Thank you for you answers.&lt;br&gt;
&lt;br&gt;
As you are speaking about SSL, do you know if client certificats are&lt;br&gt;
forwarded to CAS X509 handler when Tomecat is behind the Apache/mod_jk&lt;br&gt;
or Apache/mod_proxy_ajp ?&lt;br&gt;
&lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
Stéphane&lt;br&gt;
&lt;/font&gt;&lt;div&gt;&lt;div&gt;&lt;/div&gt;&lt;div class=&quot;Wj3C7c&quot;&gt;&lt;br&gt;
On 7/24/08, Andrew Ralph Feller, afelle1 &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;afelle1@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&amp;gt; For those who need to support Java applications along with PHP / Perl&lt;br&gt;
&amp;gt; applications, they could host both from the same machine by having Apache&lt;br&gt;
&amp;gt; httpd front-end Apache Tomcat. &amp;nbsp;There is a another reason why some people&lt;br&gt;
&amp;gt; use mod_jk + Tomcat: inexperience in managing Tomcat. &amp;nbsp;When I was starting&lt;br&gt;
&amp;gt; out, I hated working with keystores as it wasn¹t nearly as straight forward&lt;br&gt;
&amp;gt; as Apache httpd¹s mod_ssl configuration. &amp;nbsp;Once I found how to setup the&lt;br&gt;
&amp;gt; Apache Portable Runtime in Tomcat, then I felt comfortable not having Tomcat&lt;br&gt;
&amp;gt; front-ended as the APR configuration is extremely similar to mod_ssl.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; On a tangential note, there is an alternative to mod_jk called&lt;br&gt;
&amp;gt; mod_proxy_ajp, which comes with Apache httpd 2.2 and works in a similar&lt;br&gt;
&amp;gt; manner.&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; On 7/24/08 6:12 AM, &amp;quot;Siegfried Puchbauer&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;siegfried.puchbauer@...&lt;/a&gt;&amp;gt;&lt;br&gt;
&amp;gt; wrote:&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt; You can gain a lot of flexibility when you choose to use Apache in front&lt;br&gt;
&amp;gt;&amp;gt; of&lt;br&gt;
&amp;gt;&amp;gt; your Tomcat backend. For example a very flexible way to perform name-based&lt;br&gt;
&amp;gt;&amp;gt; virtual hosting. Also mod_rewrite is great to perform dynamic redirects&lt;br&gt;
&amp;gt;&amp;gt; using&lt;br&gt;
&amp;gt;&amp;gt; regexes. And the reverse-proxy capabilities by mod_proxy are also very&lt;br&gt;
&amp;gt;&amp;gt; useful&lt;br&gt;
&amp;gt;&amp;gt; - especially when using other application in the same url-space. You can&lt;br&gt;
&amp;gt;&amp;gt; also&lt;br&gt;
&amp;gt;&amp;gt; use it to display a service unavailibilty information when you&lt;br&gt;
&amp;gt;&amp;gt; upgrade/restart&lt;br&gt;
&amp;gt;&amp;gt; you tomcat. If you do not have the need of rewriteing urls, perform&lt;br&gt;
&amp;gt;&amp;gt; virtual-hosting there is IMHO no reason to not choose a standalone tomcat.&lt;br&gt;
&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt; Cheers, sigi&lt;br&gt;
&amp;gt;&amp;gt; _______________________&lt;br&gt;
&amp;gt;&amp;gt; Siegfried Puchbauer&lt;br&gt;
&amp;gt;&amp;gt; &lt;a href=&quot;http://siegfried.puchbauer.com/&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://siegfried.puchbauer.com/&lt;/a&gt;&lt;br&gt;
&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt; On Thu, Jul 24, 2008 at 11:55, Stéphane Gully &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt; wrote:&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; Hello,&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; This is a generic question, not directly related to CAS. I&amp;#39;m sorry for&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; that.&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; Google didn&amp;#39;t helped me so I try here.&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; When I installed CAS, I had the choice to deploy it directly in Tomcat&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; or in Apache/mod_jk+Tomcat. I chosed to deploy it directly in Tomcat&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; because I needed X509 authentication handler and it just looked more&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; easy to configure directly in Tomcat.&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; I often read that mod_jk should be used but I never know why ? could&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; someone tell me the reason(s) ?&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; regards,&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; --&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; Stéphane GULLY&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; _______________________________________________&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt;&lt;br&gt;
&amp;gt;&amp;gt; _______________________________________________&lt;br&gt;
&amp;gt;&amp;gt; Yale CAS mailing list&lt;br&gt;
&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt; --&lt;br&gt;
&amp;gt; Andrew R. Feller, Analyst&lt;br&gt;
&amp;gt; Information Technology Services&lt;br&gt;
&amp;gt; 200 Fred Frey Building&lt;br&gt;
&amp;gt; Louisiana State University&lt;br&gt;
&amp;gt; Baton Rouge, LA 70803&lt;br&gt;
&amp;gt; (225) 578-3737 (Office)&lt;br&gt;
&amp;gt; (225) 578-6400 (Fax)&lt;br&gt;
&amp;gt;&lt;br&gt;
&amp;gt;&lt;br&gt;
_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;/div&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633638&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Why-mod_jk---tp18628722p18633638.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18633335</id>
	<title>Re: CAS &amp; LDAP</title>
	<published>2008-07-24T07:31:28Z</published>
	<updated>2008-07-24T07:31:28Z</updated>
	<author>
		<name>scott_battaglia</name>
	</author>
	<content type="html">&lt;div dir=&quot;ltr&quot;&gt;Hi,&lt;br&gt;&lt;br&gt;Welcome to CAS!&amp;nbsp; I&amp;#39;m not an LDAP expert either (we also don&amp;#39;t use Fastbind), but I&amp;#39;ll try to provide some basic guidance and then our OpenLDAP experts can chime in (we have a few).&lt;br&gt;
&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Thu, Jul 24, 2008 at 10:07 AM, Matthew Jones &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633335&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matthew.jones@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&amp;lt;snip /&amp;gt;&lt;br&gt;
&lt;br&gt;
Now, I see that I should have an AuthenticatedLdapContextSource bean&lt;br&gt;
configured but this has parameters (property) such as userName and&lt;br&gt;
Password. Given that these values should come from the CAS login screen&lt;br&gt;
what should I put here?&lt;/blockquote&gt;&lt;div&gt;&lt;br&gt;No need to put anything there!&amp;nbsp; The ContextSource is generic so it can be used for both the FastBind and the other option. &lt;br&gt;&lt;/div&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
&lt;br&gt;
&lt;br&gt;
&amp;lt;snip /&amp;gt;&lt;br&gt;
&lt;br&gt;
Maybe I have got the wrong end of the stick altogether but I thought&lt;br&gt;
that using the bind directly to LDAP ought to be the simplest form of&lt;br&gt;
LDAP authentication. However, when username &amp;amp; password are mentioned I&lt;br&gt;
get confused. The configuration file (and some posts) mention the&lt;br&gt;
UsernamePasswordCredentialsToPrincipalResolver &amp;nbsp;and a produced&lt;br&gt;
SimplePrincipal instance. Should I be making use of these and if so how?&lt;/blockquote&gt;&lt;div&gt;&lt;br&gt;The UsernamePasswordCredentialsToPrincipalResolver should actually be configured already in your deployerConfigContext.xml.&amp;nbsp; Unless you&amp;#39;ve removed it, there&amp;#39;s no need to do anything with it!&lt;br&gt;
&lt;br&gt;Have you tried starting up your CAS server after configuring it with LDAP?&amp;nbsp; If you&amp;#39;ve got any Spring configuration issues you&amp;#39;ll see them.&amp;nbsp; If you have authentication issues you may not see them until you turn your logging level up (in the WEB-INF/classes/log4j.properties you can set it to DEBUG instead of INFO or WARN).&lt;br&gt;
&lt;br&gt;Sun also has some LDAP specific logging stuff.&lt;br&gt;&lt;br&gt;-Scott&lt;br&gt;&amp;nbsp;&lt;br&gt;&lt;/div&gt;&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;br&gt;
&lt;br&gt;
Sorry for the very basic nature of these questions but it isn&amp;#39;t obvious&lt;br&gt;
to me what I should be trying to do.&lt;br&gt;
&lt;br&gt;
Thanks&lt;br&gt;
&lt;br&gt;
-- &lt;br&gt;
Matthew Jones&lt;br&gt;
Interactive Data Managed Solutions Ltd&lt;br&gt;
-----------------------------------------------------------------------&lt;br&gt;
Registered in England Company Number 3691868&lt;br&gt;
Registered Office: Suite 1101 Eagle Tower | Montpellier Drive |&lt;br&gt;
Cheltenham | Gloucestershire | GL50 1TA&lt;br&gt;
Tel: +44 (0)1242 694133 | Fax: +44 (0)1242 694109&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633335&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;matthew.jones@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.interactivedata-ms.com/694133&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.interactivedata-ms.com/694133&lt;/a&gt;&lt;br&gt;
&lt;/font&gt;&lt;br&gt;_______________________________________________&lt;br&gt;
Yale CAS mailing list&lt;br&gt;
&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633335&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;
&lt;br&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;/div&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;Yale CAS mailing list
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633335&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/CAS---LDAP-tp18632931p18633335.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18633429</id>
	<title>Re: Why mod_jk ?</title>
	<published>2008-07-24T07:27:53Z</published>
	<updated>2008-07-24T07:27:53Z</updated>
	<author>
		<name>Andrew R Feller</name>
	</author>
	<content type="html">Unfortunately, I have no experience with that.
&lt;br&gt;&lt;br&gt;&lt;br&gt;On 7/24/08 8:09 AM, &amp;quot;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt;
&lt;br&gt;wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thank you for you answers.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; As you are speaking about SSL, do you know if client certificats are
&lt;br&gt;&amp;gt; forwarded to CAS X509 handler when Tomecat is behind the Apache/mod_jk
&lt;br&gt;&amp;gt; or Apache/mod_proxy_ajp ?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Stéphane
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On 7/24/08, Andrew Ralph Feller, afelle1 &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;afelle1@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; For those who need to support Java applications along with PHP / Perl
&lt;br&gt;&amp;gt;&amp;gt; applications, they could host both from the same machine by having Apache
&lt;br&gt;&amp;gt;&amp;gt; httpd front-end Apache Tomcat. &amp;nbsp;There is a another reason why some people
&lt;br&gt;&amp;gt;&amp;gt; use mod_jk + Tomcat: inexperience in managing Tomcat. &amp;nbsp;When I was starting
&lt;br&gt;&amp;gt;&amp;gt; out, I hated working with keystores as it wasn¹t nearly as straight forward
&lt;br&gt;&amp;gt;&amp;gt; as Apache httpd¹s mod_ssl configuration. &amp;nbsp;Once I found how to setup the
&lt;br&gt;&amp;gt;&amp;gt; Apache Portable Runtime in Tomcat, then I felt comfortable not having Tomcat
&lt;br&gt;&amp;gt;&amp;gt; front-ended as the APR configuration is extremely similar to mod_ssl.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; On a tangential note, there is an alternative to mod_jk called
&lt;br&gt;&amp;gt;&amp;gt; mod_proxy_ajp, which comes with Apache httpd 2.2 and works in a similar
&lt;br&gt;&amp;gt;&amp;gt; manner.
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; On 7/24/08 6:12 AM, &amp;quot;Siegfried Puchbauer&amp;quot; &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;siegfried.puchbauer@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; You can gain a lot of flexibility when you choose to use Apache in front
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; of
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; your Tomcat backend. For example a very flexible way to perform name-based
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; virtual hosting. Also mod_rewrite is great to perform dynamic redirects
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; using
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; regexes. And the reverse-proxy capabilities by mod_proxy are also very
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; useful
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; - especially when using other application in the same url-space. You can
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; also
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; use it to display a service unavailibilty information when you
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; upgrade/restart
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; you tomcat. If you do not have the need of rewriteing urls, perform
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; virtual-hosting there is IMHO no reason to not choose a standalone tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Cheers, sigi
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Siegfried Puchbauer
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://siegfried.puchbauer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://siegfried.puchbauer.com/&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; On Thu, Jul 24, 2008 at 11:55, Stéphane Gully &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;stephane.gully@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This is a generic question, not directly related to CAS. I'm sorry for
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; that.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Google didn't helped me so I try here.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; When I installed CAS, I had the choice to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; or in Apache/mod_jk+Tomcat. I chosed to deploy it directly in Tomcat
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; because I needed X509 authentication handler and it just looked more
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; easy to configure directly in Tomcat.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I often read that mod_jk should be used but I never know why ? could
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; someone tell me the reason(s) ?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; regards,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Stéphane GULLY
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Andrew R. Feller, Analyst
&lt;br&gt;&amp;gt;&amp;gt; Information Technology Services
&lt;br&gt;&amp;gt;&amp;gt; 200 Fred Frey Building
&lt;br&gt;&amp;gt;&amp;gt; Louisiana State University
&lt;br&gt;&amp;gt;&amp;gt; Baton Rouge, LA 70803
&lt;br&gt;&amp;gt;&amp;gt; (225) 578-3737 (Office)
&lt;br&gt;&amp;gt;&amp;gt; (225) 578-6400 (Fax)
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; Yale CAS mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18633429&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;cas@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://tp.its.yale.edu/mailman/listinfo/cas&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://tp.its.yale.edu/mailman/listinfo/cas&lt;/a&gt;&