Skip to main content
Version: 5.5

Setting up SSO CAS

This document describes how BlueMind recognizes CAS (Central Authentication Service) authentication.

How CAS authentication works​

For initial authentication :

  1. The user tries to connect to BlueMind, which he opens in his browser.
  2. As it has not yet been authenticated, the BlueMind server redirects it to the CAS server for authentication.
  3. Once authenticated, a CAS cookie is placed in the user's browser, and the user is redirected to BlueMind with a ticket to validate.
  4. The BlueMind server :
    1. sees this ticket,
    2. asks the CAS server if it is valid,
    3. If this is indeed the case, authorise the connection and set a BlueMind cookie in the browser.

On next authentication:

  1. The customer requests access to the BlueMind server again.
  2. As it has the BlueMind cookie, it is automatically authenticated as long as this cookie is valid.

For more information

Installing​

To implement CAS authentication, install the required package:

aptitude install bm-plugin-hps-cas

Then restart BlueMind:

bmctl restart

Configuration​

  1. In the administration console, go to System management > Supervised domains > choose domain > Security tab.

    ℹ️ Administrator account
    As this procedure relates to domain configuration, it is possible and preferable to use a domain administrator account (see Organizational Units and Delegated Administration) rather than the superuser admin0.

  2. Select the CAS authentication mode from the drop-down menu and enterthe CAS server URL:

  3. Click on "Save" to save your changes.

Users will then be automatically redirected to the CAS server when accessing the authentication page.

Known errors​

Error 403: Your user account does not exist in this BlueMind.​

Cause: This error message means that the login details used by the user to authenticate on the CAS do not exist for this domain. This can occur if the user has not yet been created in BlueMind, or deliberately because you do not wish that user to have access to it.

Solutions: There are two possible solutions:

  1. In BlueMind, create the user associated with the CAS login in the correct domain.
  2. Ignore the error if the access denial is intentional.

Error 500: Internal Server Error​

There may be several reasons for this error message. To investigate the cause and find out how to solve it, consult the webserver logs. For further information on the logs, see the Logs page.

Using a self-signed certificate or an unknown certification authority​

Symptoms: If a self-signed certificate is used for the CAS server, or the CAS server's certification authority is not listed, a security error occurs when establishing the https connection to the CAS server.

Solution: To resolve this error, import the self-signed certificate or root CA into the jvm keystore used by BlueMind.

keytool -import -trustcacerts -alias cas -file cert_racine.crt -keystore /usr/lib/jvm/bm-jdk/lib/security/cacerts
Enter keystore password: changeit

For more information, see http://www.sslshopper.com/article-most-common-java-keytool-keystore-commands.html