January 27, 2006

Single Sign-On Eases Headaches, Especially on February 15

Posted at January 27, 2006 12:31 PM in CAS , CAS , Case IT , SSO .

Hopefully by now you are acquainted with the university's single sign-on service, CAS. You appreciate how much easier it makes your day. You get to work in the morning, sign on, and don't worry about specifying your password again and again and again. Well, that isn't accurate. There are still numerous services that haven't been converted to CAS. Some are for political reasons. Some are for technical reasons. Although ITS has internally tested CAS with the portal, webmail, the web Oracle calendar, and even Blackboard, these services haven't been converted chiefly because the current CAS server won't let users with passwords older than September 1999 log in.

The next version of the CAS service (which is due for deployment any day now) corrects this issue. It also looks branded and even allows special users defined in LDAP to log in. For service deployers, this should be enough to convince you to convert your service. If not, you will pay dearly come February 15.

The upgraded CAS service features something no other current login method at Case will: friendly integration with the new password policies. When your password expires, your account is disabled. You will not be able to log in from anywhere. The only thing you can do with your old password is use it to change your password. However, when you log in to CAS with your expired password, CAS will say "Your password has expired. Please use the Password Change Page to change your password." SITES NOT USING CAS WILL NOT BE ABLE TO DISTINGUISH BETWEEN A BAD PASSWORD AND AN EXPIRED ONE. Users will visit these non-CASified sites and enter their password over and over, confident it is correct. Frustration builds up. These services aren't programmed to check for an expired account. They just check whether the password works, which the password policies dictate it won't. People will get upset they can't use your service. They have no idea why. They file trouble tickets with the Help Desk. They call you. They e-mail you. Loss of productivity ensues.

CAS exists for user convenience and for peace-of-mind with information security. I HATE typing in my password to access a site. After all, that password is available to that site to do what they want. There is nothing stopping a web site operator from putting up a site that requires my password, then takes that password and logs in to the the e-mail server as myself and downloads all my mail. They can bind to the LDAP as me and obtain my personal information. They can log in to other services as me. Your Case ID password should be yours and yours only. You should only need as few times as possible. CAS makes that possible.

For all the system administrators out there who haven't deployed CAS yet, I implore you to do so. You will be conveniencing the users of your services as well as securing some peace-of-mind come February 15.

Trackback

You can ping this entry by using http://blog.case.edu/gps10/mt-tb.cgi/5548 .

Comments

Mentioned this in the post The Benefits of Single Sign On

for the case of a person's account whose password has expired and they need to renew it. On a system using it's own authentication form (even if it is against our Kerberos or LDAP services), it must be configured separately to give out such helpful links and information. Obviously, with n apps all doing their own authentication, all of them need to be configured to do this themselves – duplication of work. Or, even worse, having the external apps not configured at all and they just say, "your password sucks; go away!" with no helpful information.

Posted by jms18 at January 27, 2006 03:12 PM

So does an expiring password mean that someone hasn't changed their password before the Feb 15 only, or because they are going to be expiring regularly from now on? I haven't seen any confirmation of regular expiration, and the fact that you could reuse your previous password would seem to imply that this was a one-time event...

Posted by Joel Kraft at January 30, 2006 02:11 PM

It is my understanding that people will have to change their password every N months. Unfortunately, I cannot find any information about that policy. I'm not sure if Feb 15 is "let's eliminate the need for Kerberos 4" or "the new policy is in full effect" Day. I am pretty sure the end goal is instituting a system where passwords routinely expire.

Posted by Gregory Szorc at January 30, 2006 02:18 PM

After talking with someone in the know, February is simply a flag day when all the passwords will expire. There is no policy in place that says these new passwords will expire after a period of time. I wouldn't count it out for the future, however...

Posted by Gregory Szorc at January 30, 2006 03:06 PM

I love the concept, but a few practical drawbacks hold me up from using CAS:


  • seems like a monster to get it working under IIS (I know I know, but even ITS has a few applications that require IIS).

  • being redirected to the CAS login page doesn't provide a seamless user experience within an application. So I can authenticate a user and but then have to display an error message on a subsequent page if their credentials don't meet what I'm looking for beyond just a valid ID (not to mention the time and money spent converting to the web templates).

  • one size doesn't always fit all. sometimes an application needs to provide "helpful links" beyond what might be on the CAS login page (for example, incoming students should mention they aren't students yet when they contact the Help Desk with ID/password problems).

But I'll make you a deal, Greg: you figure out how to do it using classic ASP and I'll implement it. ;P

Posted by jonathan wehner at January 30, 2006 10:20 PM

https://opensource.case.edu/projects/CAS/wiki/CASP is an ASP library written by someone at Case to do the CAS login. The CAS protocol is very simple to program. The complexities arise when doing proxied authentication, which 99% of the time you don't need to do.

Regarding the seamless user experience, CAS 3 (which will be deployed before Feb 15) supports different skins depending on the service accessed. However, implementing has been decided against b/c we want a user to know when he or she logs in to CAS. Imagine, "I didn't know I logged into the SSO service and someone could use my account."

If you have suggestions about what information needs to be provided on the CAS login page, please e-mail sso-admin@case.edu with them. We want CAS to be as easy to use as possible.

Posted by Gregory Szorc at January 30, 2006 10:41 PM

But wait, if their password wouldn't work, why wouldn't they go to the help web page? I mean, they can't be so damn certain it should work, since they haven't used it for months or whatever, and since it doesn't work for any other services, right?

+C

Posted by Christopher Hesse at February 14, 2006 03:55 AM

Greg,

Have you heard of anyone on campus using CAS with RT? We use RT for our internal ticket tracking, and I think other departments (EECS?) uses it for a few things as well.

Posted by mgh at February 18, 2006 12:07 PM

How do you think. If I quit using internet... No, CAN I quit?

Posted by Major Pain at October 11, 2006 11:40 AM

I know, ask me. Also some interesting sites.

Posted by Rogue Jago at October 21, 2006 04:12 PM

I present to you this cool site about Tramadol
May be its help you to find him...

Posted by Blobequ at December 25, 2006 01:46 PM

Best price for:
prom dress [url=http://www.blogsharing.com/prom/2241/]prom dress[/url]
http://www.blogsharing.com/prom/2241/ prom dress

Posted by Best regards at January 4, 2007 07:51 PM

Best price for:
prom dress [url=http://www.blogsharing.com/prom/2241/]prom dress[/url]
http://www.blogsharing.com/prom/2241/ prom dress

Posted by Best regards at January 4, 2007 07:52 PM

paxil side effects [url=http://www.oiepmis.bia.edu/_disc2/000017d0.htm]paxil side effects[/url]

Posted by aksolwad at January 5, 2007 05:29 AM

paxil side effects [url=http://www.oiepmis.bia.edu/_disc2/000017d0.htm]paxil side effects[/url]

Posted by aksolwad at January 5, 2007 05:29 AM

paxil withdrawal [url=http://www.siena.edu/boswell/_disc10/00000261.htm]paxil withdrawal[/url]

Posted by ranols2u at January 5, 2007 11:37 AM

carisoprodol online [url=http://farmweb.jrc.cec.eu.int/CRELL/_kbas/000001bc.htm]carisoprodol online[/url]

Posted by waaasdi at January 7, 2007 06:37 AM

carisoprodol online [url=http://farmweb.jrc.cec.eu.int/CRELL/_kbas/000001bc.htm]carisoprodol online[/url]

Posted by waaasdi at January 7, 2007 06:37 AM

buy carisoprodol [url=http://www.socwel.ku.edu/discussions/SW981/_disc1/0000414b.htm]buy carisoprodol[/url]

Posted by ssssa2v at January 7, 2007 02:21 PM

buy carisoprodol [url=http://www.socwel.ku.edu/discussions/SW981/_disc1/0000414b.htm]buy carisoprodol[/url]

Posted by ssssa2v at January 7, 2007 02:21 PM

order carisoprodol [url=http://www.etsu.edu/ptfaculty/_kbas/0000125d.htm]order carisoprodol[/url]

Posted by saouash at January 7, 2007 10:09 PM

buy carisoprodol online [url=http://facweb.cs.depaul.edu/mobeirne/_kbas/00000159.htm]buy carisoprodol online[/url]

Posted by ss223t3a at January 8, 2007 10:22 AM

Girls, have fun, not boys

Posted by Zarba Barba at January 8, 2007 10:19 PM

oebdnzg lqvo kreumo zdelymq jhcm zhtro abms

Posted by xngzlawv uvwyoei at January 11, 2007 04:47 AM

I present to you this site:
carisoprodol
[url=http://ecarisoprodol.org][/url]
http://ecarisoprodol.org

Posted by SysAdmin at January 22, 2007 12:39 AM

cialis soft


generic cialis

[url=http://z.la/g6v4m ]
cheap cialis
[/url]

Posted by cheapest cialis at January 30, 2007 11:45 AM

cialis soft


generic cialis

[url=http://z.la/g6v4m ]
cheap cialis
[/url]

Posted by cheapest cialis at January 30, 2007 11:45 AM

cialis sale


cialis impotence drug eli lilly co

[url=http://kat.cc/019c26 ]
cialis free sample
[/url]

Posted by cialis 20mg at January 31, 2007 12:57 PM

cialis sale


cialis impotence drug eli lilly co

[url=http://kat.cc/019c26 ]
cialis free sample
[/url]

Posted by cialis 20mg at January 31, 2007 12:57 PM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/culos-gratis.html]culos gratis cheap order online[/url] [url=http://www.dreipage.de/userdaten/79068443/html/el-telefono.html]cheap online culos gratis[/url] [url=http://www.dreipage.de/userdaten/79068443/html/horoscopo-chino-gratis.html]horoscopo chino gratis order discounts[/url]

Posted by Best regards at February 1, 2007 12:10 PM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/culos-gratis.html]culos gratis cheap order online[/url] [url=http://www.dreipage.de/userdaten/79068443/html/el-telefono.html]cheap online culos gratis[/url] [url=http://www.dreipage.de/userdaten/79068443/html/horoscopo-chino-gratis.html]horoscopo chino gratis order discounts[/url]

Posted by Best regards at February 1, 2007 12:11 PM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/culos-gratis.html]culos gratis cheap order online[/url] [url=http://www.dreipage.de/userdaten/79068443/html/el-telefono.html]cheap online culos gratis[/url] [url=http://www.dreipage.de/userdaten/79068443/html/horoscopo-chino-gratis.html]horoscopo chino gratis order discounts[/url]

Posted by Best regards at February 1, 2007 12:11 PM

jenna jameson naked


jenna jameson blowjob

[url=http://kuso.cc/1cn@ ]
fucking jenna jameson
[/url]

Posted by jenna jameson anal at February 2, 2007 08:32 AM

jenna jameson clips


jenna jameson lesbian

[url=http://kuso.cc/1cn@ ]
jenna jameson movies
[/url]

Posted by jenna jameson nude at February 2, 2007 08:32 AM

jenna jameson clips


jenna jameson lesbian

[url=http://kuso.cc/1cn@ ]
jenna jameson movies
[/url]

Posted by jenna jameson nude at February 2, 2007 08:32 AM

jenna jameson clips


jenna jameson lesbian

[url=http://kuso.cc/1cn@ ]
jenna jameson movies
[/url]

Posted by jenna jameson nude at February 2, 2007 08:32 AM

jenna jameson sex


jenna jameson blowjob

[url=http://kuso.cc/1cn@ ]
jenna jameson sex
[/url]

Posted by jenna jameson hardcore at February 2, 2007 08:32 AM

jenna jameson sex


jenna jameson blowjob

[url=http://kuso.cc/1cn@ ]
jenna jameson sex
[/url]

Posted by jenna jameson hardcore at February 2, 2007 08:32 AM

jenna jameson sex


jenna jameson blowjob

[url=http://kuso.cc/1cn@ ]
jenna jameson sex
[/url]

Posted by jenna jameson hardcore at February 2, 2007 08:33 AM

Check this:
el telefono buy online no prescription online no prescription mujeres desnudas gratis

Posted by Best regards at February 2, 2007 11:54 AM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/mujeres-desnudas-gratis.html]order online lowest price el telefono[/url] [url=http://www.dreipage.de/userdaten/79068443/html/musica-gratis-stratovarius.html]culos gratis lowest price order online[/url]

Posted by Best regards at February 2, 2007 11:54 AM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/mujeres-desnudas-gratis.html]order online lowest price el telefono[/url] [url=http://www.dreipage.de/userdaten/79068443/html/musica-gratis-stratovarius.html]culos gratis lowest price order online[/url]

Posted by Best regards at February 2, 2007 11:54 AM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/mujeres-desnudas-gratis.html]order online lowest price el telefono[/url] [url=http://www.dreipage.de/userdaten/79068443/html/musica-gratis-stratovarius.html]culos gratis lowest price order online[/url]

Posted by Best regards at February 2, 2007 11:54 AM

big tits


tit fucking

[url=http://ttu.cc/3690 ]
huge tits
[/url]

Posted by tit fuck at February 2, 2007 07:23 PM

teen tits


tit

[url=http://ttu.cc/3690 ]
tit
[/url]

Posted by teen tits at February 2, 2007 07:24 PM

teen tits


tit

[url=http://ttu.cc/3690 ]
tit
[/url]

Posted by teen tits at February 2, 2007 07:24 PM

young tits


tiny tits

[url=http://ttu.cc/3690 ]
huge tits
[/url]

Posted by perfect tits at February 2, 2007 07:24 PM

young tits


tiny tits

[url=http://ttu.cc/3690 ]
huge tits
[/url]

Posted by perfect tits at February 2, 2007 07:25 PM

nice tits


big black tits

[url=http://s-url.net/0q8f/ ]
black tits
[/url]

Posted by big black tits at February 3, 2007 09:09 PM

nice tits


big black tits

[url=http://s-url.net/0q8f/ ]
black tits
[/url]

Posted by big black tits at February 3, 2007 09:09 PM


Check this:
[url=http://www.dreipage.de/userdaten/79068443/html/office-xp-manuales-free-gratis.html]discounts buy musica gratis stratovarius[/url] [url=http://www.dreipage.de/userdaten/79068443/html/sexo-gratis.html]gratis order online discounts[/url]

Posted by Best regards at February 4, 2007 02:44 AM

small tits


perfect tits

[url=http://shrinkurl.us/tiny-tits ]
huge tits
[/url]

Posted by tiny tits at February 6, 2007 05:51 AM

teen tits


tit

[url=http://shrinkurl.us/tiny-tits ]
small tits
[/url]

Posted by big tits round asses at February 6, 2007 05:51 AM

young tits


young tits

[url=http://shrinkurl.us/tiny-tits ]
perfect tits
[/url]

Posted by young tits at February 6, 2007 05:52 AM

young tits


young tits

[url=http://shrinkurl.us/tiny-tits ]
perfect tits
[/url]

Posted by young tits at February 6, 2007 05:52 AM

cialis forum


buy cialis

[url=http://atk.jp/qpyo ]
cialis
[/url]

Posted by cialis 20mg at February 6, 2007 03:19 PM

cialis forum


buy cialis

[url=http://atk.jp/qpyo ]
cialis
[/url]

Posted by cialis 20mg at February 6, 2007 03:19 PM

big tits


young tits

[url=http://atk.jp/vsod ]
perfect tits
[/url]

Posted by big tits at February 6, 2007 03:25 PM

big tits


young tits

[url=http://atk.jp/vsod ]
perfect tits
[/url]

Posted by big tits at February 6, 2007 03:25 PM

tit


perfect tits

[url=http://atk.jp/vsod ]
tits
[/url]

Posted by tit at February 6, 2007 03:25 PM

As for me, I like dress shoes womens

Posted by dress shoes womens at February 7, 2007 07:59 PM

cialis impotence drug eli lilly co


cialis online

[url=http://rubyurl.com/8Av ]
buy cialis online
[/url]

Posted by generic cialis at February 8, 2007 04:15 AM

cheap cialis


cheap cialis

[url=http://rubyurl.com/8Av ]
cialis drug
[/url]

Posted by cialis forum at February 8, 2007 04:15 AM

cialis online


buy cialis

[url=http://rubyurl.com/8Av ]
cialis online
[/url]

Posted by cialis impotence drug eli lilly co at February 8, 2007 06:05 AM

cialis online


buy cialis

[url=http://rubyurl.com/8Av ]
cialis online
[/url]

Posted by cialis impotence drug eli lilly co at February 8, 2007 06:05 AM

cialis online


buy cialis

[url=http://rubyurl.com/8Av ]
cialis online
[/url]

Posted by cialis impotence drug eli lilly co at February 8, 2007 06:06 AM

Kindzmarauli vs conyaq, or some...

Posted by Taomy Oemb at February 8, 2007 06:35 AM

generic cialis


cialis drug

[url=http://url.vg/sxxxx/a9482d/cialisgenericcialisbuyci ]
cheapest cialis
[/url]

Posted by cialis drug at February 9, 2007 09:27 AM

Post a comment










Remember personal info?