simple CAS server based on Apereo CAS
4.3K
A simple SSO CAS container based on the Apereo CAS server
Part of the GUNet simpleidentity suite (includes a CAS SSO server and several SSO protocol testers)
Expects a gunet/simple-ldap container for the user database.
Configuration is in /etc/cas, including /etc/cas/cas.properties (with dynamic environment variables), /etc/cas/services for JSON based services definitions
Listen port: 8443
Features:
Configured service definitions:
serviceId of ^http(|s)://.*. Returned attributes will include cn, sn, displayName, uid, mobileserviceId of ^http(|s)://.*. The metadataLocation points to a dynamically expanded (on startup by the docker entrypoint) value including the SAML_SP environment variable for the gunet/simple-saml-sp based on simpleSAMLPHP (${SAML_SP}/simplesaml/module.php/saml/sp/metadata.php/default-sp)Main endpoints:
/cas/login: Login using the CAS protocol/cas/idp/metadata: SAML2 metadata/cas/idp: SAML endpoints/cas/oidc/.well-known/openid-configuration: OIDC metadata/cas/oidc: OIDC endpointscurl -k https://localhost:8443/cas/v1/users -d "username=test&password=test"/cas/actuator/discoveryProfile: Discovery Profile/cas/account: User account (after login)Returned attributes (CAS protocol):
Certificate:
/etc/cas/thekeystore while the actual certificate is also in /etc/cas/server.crtlocalhost and includes a subjectAltName of host.docker.internal. This can be used to access the /cas/serviceValidate endpoint through another container by including the relevant host (example for Docker compose stack): extra_hosts:
- "host.docker.internal:host-gateway"
Actuators:
/cas/actuator: List of available actuators/cas/actuator/status: General status/car/actuator/casFeatures: List of enabled features/cas/actuator/ssoSessions: SSO sessions stats/list/cas/actuator/registeredServices: List of registered services/cas/actuator/metrics/${metricName}: Various metrics. Accessing the root will return available metrics to query. For instance:
/cas/actuator/metrics/disk.total/cas/actuator/metrics/disk.free/cas/actuator/statistics: Statistics/cas/actuator/resolveAttributes/${uid}: Return resolved user attributes/cas/actuator/multifactorTrustedDevices/{username}: Registered MultiFactor devices/cas/actuator/authenticationHandlers: Authentication handlersA prometheus actuator is available at /car/actuator/prometheus
CONFIG on the web interface. This can be done by passing a parameter authn_method=mfa-gauth in the login page (https://localhost:8443/cas/login?authn_method=mfa-gauth)curl -sLk https://localhost:8443/cas/v1/users -d "username=auser&password=auser&gauthotp=229565". The CAS server response will include an attribute authnContextClass=mfa-gauthMain configuration environment attributes:
CAS_SERVER_NAME which is used to setup the cas.server.name cas property. Default value: https://localhost:8443cas.server.prefix will be equal to ${CAS_SERVER_NAME}/cas. All other relevant endpoints will be below this prefixLDAP_URL which sets the LDAP URL to use. We expect the gunet/simple-ldap container with its data structure and admin username/password. Default value: ldap://ldap:1389SAML_SP_METADATA for the gunet/simple-saml-sp tester container metadata location already setup in the SAML service definition. Default value: http://host.docker.internal:8080/simplesaml/module.php/saml/sp/metadata.php/default-spHow to include in docker-compose.yaml (the gunet/simple-ldap needs to be included in the stack with a service name of ldap):
sso:
image: gunet/simple-cas
depends_on:
- ldap
restart: unless-stopped
ports:
- ${CAS_PORT:-8443}:8443
environment:
- TZ=Europe/Athens
- LDAP_URL=ldap://ldap:1389
- CAS_SERVER_NAME=${CAS_SERVER_NAME:-https://localhost:8443}
- SAML_SP_METADATA=${SAML_SP_METADATA:-http://host.docker.internal:8080}
extra_hosts:
- "host.docker.internal:host-gateway"
Content type
Image
Digest
sha256:2049b4512…
Size
235.5 MB
Last updated
2 months ago
docker pull gunet/simple-cas