Authentication Policy

CAS presents a number of strategies for handling authentication security policies. Policies in general control the following:

  1. Should the authentication chain be stopped after a certain kind of authentication failure?
  2. Given multiple authentication handlers in a chain, what constitutes a successful authentication event?

Policies are typically activated after:

  1. An authentication failure has occurred.
  2. The authentication chain has finished execution.

Typical use cases of authentication policies may include:

  1. Enforce a specific authentication’s successful execution, for the entire authentication event to be considered successful.
  2. Ensure a specific class of failure is not evident in the authentication chain’s execution log.
  3. Ensure that all authentication schemes in the chain are executed successfully, for the entire authentication event to be considered successful.

Actuator Endpoints

The following endpoints are provided by CAS:

authenticationPolicies
CAS endpoint2 operationsNot exposed by defaultcas-server-support-reports
1

Include the module that provides this endpoint in the WAR overlay:

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-support-reports</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-support-reports:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-support-reports"
}
1
2
3
4
5
6
7
8
9
10
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
    */
    implementation "org.apereo.cas:cas-server-support-reports"
}
2

Turn the endpoint on and expose it over the web. One entry covers every operation. By default only info, health and status are exposed.

1
2
management.endpoint.authenticationPolicies.access=UNRESTRICTED
management.endpoints.web.exposure.include=authenticationPolicies

Endpoints may be mapped to other paths. For example, to serve health at healthcheck:

1
management.endpoints.web.path-mapping.health=healthcheck

Policies

Authentication policies can be managed via the following strategies.

Storage Description
All See this guide.
Any See this guide.
Global See this guide.
Groovy See this guide.
Not Prevented See this guide.
Required See this guide.
REST See this guide.
Source Selection See this guide.
Unique Principal See this guide.

Authentication policies may also be defined on a per application basis. See this guide for more info.