Skip to content
This repository was archived by the owner on Oct 23, 2018. It is now read-only.

adfs casification

Dmitriy Kopylenko edited this page Jul 27, 2015 · 11 revisions

The CASifying ADFS method uses CAS's ClearPass module to pass the user's password into the ADFS login function.

Implementer note: These are general implementation steps and there will likely need to be adaptions made to it. Please submit changes as issues.

1. Download the .NET CAS Client library (v1.0.1)

If you want to download the client without Nuget, download http://packages.nuget.org/v1/Package/Download/DotNetCasClient/1.0.1. Rename the file to .zip and unpack. The client library is in the lib folder. v1.0.2 is preferred, but is not yet on Nuget. It can be found at https://wiki.jasig.org/display/casc/.net+cas+client.

Add the DotNetCasClient.dll file to ADFS's bin directory.

2. Update the web.config using the instructions found at: https://wiki.jasig.org/display/CASC/.Net+Cas+Client.

3. Modify the ADFS's FormsSignIn.aspx.cs:

protected void Page_Load(object sender, EventArgs e)
    {
        // Retrieve a Proxy Ticket for ClearPass
        string clearPassUrl = "http://example.org/cas/clearPass";
        string clearPassUri = new Uri(clearPassUrl);
        string proxyTicket = CasAuthentication.GetProxyTicketIdFor(clearPassUri);
        string clearPassRequest = ClearPassUrl + "?ticket=" + proxyTicket + "&service=" + clearPassUrl;
        string clearPassResponse;

        try
        {
            using (StreamReader reader = new StreamReader(new WebClient().OpenRead(clearPassRequest))) {
                clearPassResponse = reader.ReadToEnd();
            }
        }
        catch (Exception ex)
        {
            throw new HttpException(500, "Error getting response from clearPass at URL: " + clearPassRequest + ". " + ex.Message, ex);
        }

        string clearPass = XmlUtils.GetTextForElement(clearPassResponse, "cas:credentials");
        if (String.IsNullOrEmpty(clearPass))
            throw new HttpException(500, "Received response from " + clearPassRequest + ", but cas:credientials IsNullOrEmpty.  Check CAS server logs for errors.  Make sure SSL certs are trusted.");

        try
        {
            SignIn(user.Identity.Name, HttpUtility.UrlEncode(clearPass, Encoding.ASCII));
        }
        catch (AuthenticationFailedException ex)
        {
            HandleError(ex.Message);
        }
    }

Clone this wiki locally