YubiKey Authentication

Yubico is a cloud-based service that enables strong, easy-to-use and affordable two-factor authentication with one-time passwords through their flagship product, YubiKey. Once Yubico client-id and secret-key are obtained, then the configuration options available to use YubiKey devices as a primary authentication source that CAS server could use to authenticate users.

To configure YubiKey accounts and obtain API keys, refer to the documentation.

YubiKey authentication components are enabled by including the following dependencies in the WAR overlay:

1
2
3
4
5
<dependency>
    <groupId>org.apereo.cas</groupId>
    <artifactId>cas-server-support-yubikey</artifactId>
    <version>${cas.version}</version>
</dependency>
1
implementation "org.apereo.cas:cas-server-support-yubikey:${project.'cas.version'}"
1
2
3
4
5
6
7
8
9
dependencyManagement {
    imports {
        mavenBom "org.apereo.cas:cas-server-support-bom:${project.'cas.version'}"
    }
}

dependencies {
    implementation "org.apereo.cas:cas-server-support-yubikey"
}
1
2
3
4
5
6
7
8
9
10
dependencies {
    /*
        The following platform references are included automatically and are listed for reference only.

        implementation enforcedPlatform("org.apereo.cas:cas-server-support-bom:${project.'cas.version'}")
        implementation platform(org.springframework.boot.gradle.plugin.SpringBootPlugin.BOM_COORDINATES)
        
    */
    implementation "org.apereo.cas:cas-server-support-yubikey"
}

Actuator Endpoints

The following endpoints are provided by CAS:

yubikeyAccountRepository
CAS endpoint6 operationsNot exposed by default
base path /cas/actuator/
1

Turn the endpoint on and expose it over the web. One entry covers every operation. By default only info, health and status are exposed.

1
2
management.endpoint.yubikeyAccountRepository.access=UNRESTRICTED
management.endpoints.web.exposure.include=yubikeyAccountRepository

Endpoints may be mapped to other paths. For example, to serve health at healthcheck:

1
management.endpoints.web.path-mapping.health=healthcheck

Configuration

The following settings and properties are available from the CAS configuration catalog:

cas.authn.mfa.yubikey.bypass.groovy.locationThe location of the resource.
no default
Required

The location of the resource. Resources can be URLs, or files found either on the classpath or outside somewhere in the file system.

In the event the configured resource is a Groovy script, especially if the script is set to reload on changes, you may need to adjust the total number of inotify instances. On Linux, you may need to add the following line to /etc/sysctl.conf: fs.inotify.max_user_instances = 256.

You can check the current value via cat /proc/sys/fs/inotify/max_user_instances.

In situations and scenarios where CAS is able to automatically watch the underlying resource for changes and detect updates and modifications dynamically, you may be able to specify the following setting as either an environment variable or system property with a value of false to disable the resource watcher: org.apereo.cas.util.io.PathWatcherService.

Type
Resource
Default
none
Defined by
GroovyMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.urlThe endpoint URL to contact and retrieve attributes.
no default
RequiredSpEL

The endpoint URL to contact and retrieve attributes.

Type
String
Default
none
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.client-idYubikey client id.
0
Required

Yubikey client id.

Type
Integer
Default
0
Defined by
YubiKeyMultifactorAuthenticationProperties
cas.authn.mfa.yubikey.crypto.encryption.keyThe encryption key is a string whose length is defined by the encryption key size setting.
no default
RequiredSpEL

The encryption key is a string whose length is defined by the encryption key size setting.

Type
String
Default
none
Defined by
EncryptionJwtCryptoProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.crypto.signing.keyThe signing key is a string whose length is defined by the signing key size setting.
no default
RequiredSpEL

The signing key is a string whose length is defined by the signing key size setting.

Type
String
Default
none
Defined by
SigningJwtCryptoProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.dynamo-db.credential-access-keyUse access-key provided by AWS to authenticate.
no default
RequiredSpEL

Use access-key provided by AWS to authenticate.

Type
String
Default
none
Defined by
YubiKeyDynamoDbMultifactorProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.dynamo-db.credential-secret-keyUse secret key provided by AWS to authenticate.
no default
RequiredSpEL

Use secret key provided by AWS to authenticate.

Type
String
Default
none
Defined by
YubiKeyDynamoDbMultifactorProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.dynamo-db.dax.urlCluster url.
no default
Required

Cluster url. For example, dax://my-cluster.l6fzcv.dax-clusters.us-east-1.amazonaws.com.

Type
String
Default
none
Defined by
DynamoDbDaxProperties
cas.authn.mfa.yubikey.dynamo-db.endpointAWS custom endpoint.
no default
Required

AWS custom endpoint.

Type
String
Default
none
Defined by
YubiKeyDynamoDbMultifactorProperties
cas.authn.mfa.yubikey.dynamo-db.regionAWS region used.
no default
Required

AWS region used.

Type
String
Default
none
Defined by
YubiKeyDynamoDbMultifactorProperties
cas.authn.mfa.yubikey.jpa.driver-classThe JDBC driver used to connect to the database.
org.hsqldb.jdbcDriver
Required

The JDBC driver used to connect to the database.

Type
String
Default
org.hsqldb.jdbcDriver
Defined by
YubiKeyJpaMultifactorProperties
cas.authn.mfa.yubikey.jpa.passwordThe database connection password.
no default
Required

The database connection password.

Type
String
Default
none
Defined by
YubiKeyJpaMultifactorProperties
cas.authn.mfa.yubikey.jpa.urlThe database connection URL.
jdbc:hsqldb:mem:cas-hsql-database
RequiredSpEL

The database connection URL.

Type
String
Default
jdbc:hsqldb:mem:cas-hsql-database
Defined by
YubiKeyJpaMultifactorProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.jpa.userThe database user.
sa
Required

The database user.

The database user must have sufficient permissions to be able to handle schema changes and updates, when needed.

Type
String
Default
sa
Defined by
YubiKeyJpaMultifactorProperties
cas.authn.mfa.yubikey.mongo.client-uriThe connection uri to the mongodb instance.
no default
Required

The connection uri to the mongodb instance. This typically takes on the form of mongodb://user:psw@ds135522.somewhere.com:35522/db. If not specified, will fallback onto other individual settings. If specified, takes over all other settings where applicable.

Type
String
Default
none
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.collectionMongoDb database collection name to fetch and/or create.
no default
Required

MongoDb database collection name to fetch and/or create.

Type
String
Default
none
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.database-nameMongoDb database instance name.
no default
Required

MongoDb database instance name.

Type
String
Default
none
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.hostMongoDb database host for authentication.
localhost
Required

MongoDb database host for authentication. Multiple host addresses may be defined, separated by comma. If more than one host is defined, it is assumed that each host contains the port as well, if any. Otherwise the configuration may fallback onto the port defined.

Type
String
Default
localhost
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.passwordMongoDb database password for authentication.
no default
Required

MongoDb database password for authentication.

Type
String
Default
none
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.portMongoDb database port.
27017
Required

MongoDb database port.

Type
Integer
Default
27017
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.mongo.user-idMongoDb database user for authentication.
no default
Required

MongoDb database user for authentication.

Type
String
Default
none
Defined by
YubiKeyMongoDbMultifactorProperties
cas.authn.mfa.yubikey.redis.cluster.nodes[0].hostServer's host address.
no default
Required

Server's host address.

Type
String
Default
none
Defined by
RedisClusterNodeProperties
cas.authn.mfa.yubikey.redis.cluster.nodes[0].portServer's port number.
no default
Required

Server's port number.

Type
int
Default
none
Defined by
RedisClusterNodeProperties
cas.authn.mfa.yubikey.redis.cluster.nodes[0].replica-ofSet the id of the master node.
no default
Required

Set the id of the master node.

Type
String
Default
none
Defined by
RedisClusterNodeProperties
cas.authn.mfa.yubikey.redis.cluster.nodes[0].typeIndicate the type/role of this node.
no default
Required

Indicate the type/role of this node. Accepted values are: MASTER, REPLICA.

Type
String
Default
none
Defined by
RedisClusterNodeProperties
cas.authn.mfa.yubikey.redis.cluster.passwordThe cluster connection's password.
no default
Required

The cluster connection's password.

Type
String
Default
none
Defined by
RedisClusterProperties
cas.authn.mfa.yubikey.redis.cluster.usernameThe cluster connection's username.
no default
Required

The cluster connection's username.

Type
String
Default
none
Defined by
RedisClusterProperties
cas.authn.mfa.yubikey.redis.databaseDatabase index used by the connection factory.
0
Required

Database index used by the connection factory.

Type
Integer
Default
0
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.redis.enabledWhether the module is enabled or not, defaults to true.
true
Required

Whether the module is enabled or not, defaults to true.

Type
Boolean
Default
true
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.redis.hostRedis server host.
localhost
Required

Redis server host.

Type
String
Default
localhost
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.redis.passwordLogin password of the redis server.
no default
Required

Login password of the redis server.

Type
String
Default
none
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.redis.pool.enabledEnable the pooling configuration.
false
Required

Enable the pooling configuration.

Type
Boolean
Default
false
Defined by
RedisPoolProperties
cas.authn.mfa.yubikey.redis.portRedis server port.
6379
Required

Redis server port.

Type
Integer
Default
6379
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.redis.sentinel.masterName of Redis server.
no default
Required

Name of Redis server.

Type
String
Default
none
Defined by
RedisSentinelProperties
cas.authn.mfa.yubikey.redis.usernameLogin username of the redis server.
no default
Required

Login username of the redis server.

Type
String
Default
none
Defined by
YubiKeyRedisMultifactorProperties
cas.authn.mfa.yubikey.rest.urlThe endpoint URL to contact and retrieve attributes.
no default
RequiredSpEL

The endpoint URL to contact and retrieve attributes.

Type
String
Default
none
Defined by
YubiKeyRestfulMultifactorProperties
Supports
Spring Expression Language
cas.authn.mfa.yubikey.secret-keyYubikey secret key.
no default
Required

Yubikey secret key.

Type
String
Default
none
Defined by
YubiKeyMultifactorAuthenticationProperties
cas.authn.mfa.yubikey.allowed-devicesCollection of allowed devices allowed per user.
no default

Collection of allowed devices allowed per user. This is done using a key-value structure where the key is the user the value is the allowed collection of yubikey device ids.

Type
Map<String,String>
Default
none
Defined by
YubiKeyMultifactorAuthenticationProperties
cas.authn.mfa.yubikey.api-urlsYubiKey API urls to contact for verification of credentials.
no default

YubiKey API urls to contact for verification of credentials.

Type
List<String>
Default
none
Defined by
YubiKeyMultifactorAuthenticationProperties
cas.authn.mfa.yubikey.bypass.authentication-attribute-nameSkip multifactor authentication based on designated authentication attribute names.
no default

Skip multifactor authentication based on designated authentication attribute names.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.authentication-attribute-valueOptionally, skip multifactor authentication based on designated authentication attribute values.
no default
Regex

Optionally, skip multifactor authentication based on designated authentication attribute values. Multiple values may be separated by a comma.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.authentication-handler-nameSkip multifactor authentication depending on form of primary authentication execution.
no default
Regex

Skip multifactor authentication depending on form of primary authentication execution. Specifically, skip multifactor if the a particular authentication handler noted by its name successfully is able to authenticate credentials in the primary factor. Multiple values may be separated by a comma.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.authentication-method-nameSkip multifactor authentication depending on method/form of primary authentication execution.
no default
Regex

Skip multifactor authentication depending on method/form of primary authentication execution. Specifically, skip multifactor if the authentication method attribute collected as part of authentication metadata matches a certain value. Multiple values may be separated by a comma.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.credential-class-typeSkip multifactor authentication depending on form of primary credentials.
no default

Skip multifactor authentication depending on form of primary credentials. Value must equal the fully qualified class name of the credential type.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.http-request-headersSkip multifactor authentication if the http request contains the defined header names.
no default
Regex

Skip multifactor authentication if the http request contains the defined header names. Header names may be comma-separated and can be regular expressions; values are ignored.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.http-request-remote-addressSkip multifactor authentication if the http request's remote address or host matches the value defined here.
no default
Regex

Skip multifactor authentication if the http request's remote address or host matches the value defined here. The value may be specified as a regular expression.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.principal-attribute-nameSkip multifactor authentication based on designated principal attribute names.
no default

Skip multifactor authentication based on designated principal attribute names.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.principal-attribute-valueOptionally, skip multifactor authentication based on designated principal attribute values.
no default
Regex

Optionally, skip multifactor authentication based on designated principal attribute values.

Type
String
Default
none
Defined by
MultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.basic-auth-passwordIf REST endpoint is protected via basic authentication, specify the password for authentication.
no default

If REST endpoint is protected via basic authentication, specify the password for authentication.

Type
String
Default
none
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.basic-auth-usernameIf REST endpoint is protected via basic authentication, specify the username for authentication.
no default

If REST endpoint is protected via basic authentication, specify the username for authentication.

Type
String
Default
none
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.headersHeaders, defined as a Map, to include in the request when making the REST call.
no default

Headers, defined as a Map, to include in the request when making the REST call. Will overwrite any header that CAS is pre-defined to send and include in the request. Key in the map should be the header name and the value in the map should be the header value.

Type
Map<String,String>
Default
none
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.maximum-retry-attemptsWhen attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.
3

When attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.

Type
Integer
Default
3
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.bypass.rest.methodHTTP method to use when contacting the rest endpoint.
GET

HTTP method to use when contacting the rest endpoint. Examples include GET, POST, etc.

Type
String
Default
GET
Defined by
RestfulMultifactorAuthenticationProviderBypassProperties
cas.authn.mfa.yubikey.crypto.algThe signing/encryption algorithm to use.
no default

The signing/encryption algorithm to use.

Type
String
Default
none
Defined by
EncryptionJwtSigningJwtCryptographyProperties
cas.authn.mfa.yubikey.crypto.enabledWhether crypto operations are enabled.
true

Whether crypto operations are enabled.

Type
Boolean
Default
true
Defined by
EncryptionJwtSigningJwtCryptographyProperties
cas.authn.mfa.yubikey.crypto.encryption.key-sizeThe encryption key size.
512

The encryption key size.

Type
Integer
Default
512
Defined by
EncryptionJwtCryptoProperties
cas.authn.mfa.yubikey.crypto.signing.key-sizeThe signing key size.
512

The signing key size.

Type
Integer
Default
512
Defined by
SigningJwtCryptoProperties
cas.authn.mfa.yubikey.crypto.strategy-typeControl the cipher sequence of operations.
ENCRYPT_AND_SIGN
Control the cipher sequence of operations. The accepted values are:
  • ENCRYPT_AND_SIGN: Encrypt the value first, and then sign.
  • SIGN_AND_ENCRYPT: Sign the value first, and then encrypt.
Type
String
Default
ENCRYPT_AND_SIGN
Defined by
EncryptionJwtSigningJwtCryptographyProperties
cas.authn.mfa.yubikey.dynamo-db.billing-modeBilling mode specifies how you are charged for read and write throughput and how you manage capacity.
PROVISIONED
Billing mode specifies how you are charged for read and write throughput and how you manage capacity. Available values are as follows:
  • PROVISIONED: Provisioned mode means that you specify the number of reads and writes per second that you expect your application to use. Provisioned mode is a good option if any of the following are true:
    • You have predictable application traffic.
    • You run applications whose traffic is consistent or ramps gradually.
    • You can forecast capacity requirements to control costs.
    You can use auto scaling to automatically adjust capacity based on the specified utilization rate to ensure application performance while reducing costs.
  • PAY_PER_REQUEST: Pay-per-request or on-demand billing means that you're charged for only the read/write requests that you use. On-demand mode is a good option if any of the following are true:
    • You create new tables with unknown workloads.
    • You have unpredictable application traffic.
    • You prefer the ease of paying for only what you use.
    • Tables using on-demand mode support all DynamoDB features (such as encryption at rest, point-in-time recovery, global tables, and so on) with the exception of auto scaling, which is not applicable with this mode.
      Type
      AbstractDynamoDbProperties.BillingMode
      Default
      PROVISIONED
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.client-execution-timeoutClient execution timeout.
      10000
      Duration

      Client execution timeout.

      Type
      String
      Default
      10000
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.connection-timeoutConnection timeout.
      5000
      Duration

      Connection timeout.

      Type
      String
      Default
      5000
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.connect-timeoutConnection timeout, calculated in milliseconds.
      PT5S
      Duration

      Connection timeout, calculated in milliseconds.

      Type
      String
      Default
      PT5S
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.connection-ttlHow long should connections be kept alive, calculated in milliseconds.
      PT0S
      Duration

      How long should connections be kept alive, calculated in milliseconds.

      Type
      String
      Default
      PT0S
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.idle-timeoutConnection idle timeout, calculated in milliseconds.
      PT15S
      Duration

      Connection idle timeout, calculated in milliseconds.

      Type
      String
      Default
      PT15S
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.max-concurrencyDetermines the maximum number of concurrent requests that can be made to the DAX cluster.
      1000

      Determines the maximum number of concurrent requests that can be made to the DAX cluster.

      Type
      Integer
      Default
      1000
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.read-retriesNumber of read retry attempts.
      2

      Number of read retry attempts.

      Type
      Integer
      Default
      2
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.request-timeoutRequest execution timeout, calculated in milliseconds.
      PT5S
      Duration

      Request execution timeout, calculated in milliseconds.

      Type
      String
      Default
      PT5S
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.dax.write-retriesNumber of write retry attempts.
      2

      Number of write retry attempts.

      Type
      Integer
      Default
      2
      Defined by
      DynamoDbDaxProperties
      cas.authn.mfa.yubikey.dynamo-db.drop-tables-on-startupFlag that indicates whether to drop tables on start up.
      false

      Flag that indicates whether to drop tables on start up.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.local-addressLocal address.
      no default

      Local address.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.local-instanceIndicates that the database instance is local to the deployment that does not require or use any credentials or other configuration other than host and region.
      false

      Indicates that the database instance is local to the deployment that does not require or use any credentials or other configuration other than host and region. This is mostly used during development and testing.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.max-connectionsMaximum connections setting.
      10

      Maximum connections setting.

      Type
      Integer
      Default
      10
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.prevent-table-creation-on-startupFlag that indicates whether to prevent CAS from creating tables.
      false

      Flag that indicates whether to prevent CAS from creating tables.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.profile-nameProfile name to use.
      no default

      Profile name to use.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.profile-pathProfile path.
      no default

      Profile path.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.proxy-hostOptionally specifies the proxy host to connect through.
      no default

      Optionally specifies the proxy host to connect through.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.proxy-passwordOptionally specifies the proxy password to connect through.
      no default

      Optionally specifies the proxy password to connect through.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.proxy-usernameOptionally specifies the proxy username to connect through.
      no default

      Optionally specifies the proxy username to connect through.

      Type
      String
      Default
      none
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.read-capacityRead capacity.
      10

      Read capacity.

      Type
      Long
      Default
      10
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.retry-modeOutline the requested retry mode.
      STANDARD

      Outline the requested retry mode. Accepted values are STANDARD, LEGACY.

      Type
      String
      Default
      STANDARD
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.socket-timeoutSocket timeout.
      5000
      Duration

      Socket timeout.

      Type
      String
      Default
      5000
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.table-nameThe table name used and created by CAS to hold devices in DynamoDb.
      DynamoDbYubiKeyDevices

      The table name used and created by CAS to hold devices in DynamoDb.

      Type
      String
      Default
      DynamoDbYubiKeyDevices
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.time-offsetTime offset.
      0

      Time offset.

      Type
      Integer
      Default
      0
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.use-reaperFlag that indicates whether to use reaper.
      false

      Flag that indicates whether to use reaper.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.dynamo-db.write-capacityWrite capacity.
      10

      Write capacity.

      Type
      Long
      Default
      10
      Defined by
      YubiKeyDynamoDbMultifactorProperties
      cas.authn.mfa.yubikey.failure-modeThe failure mode policy for this MFA provider.
      CLOSED
      The failure mode policy for this MFA provider. The authentication policy by default supports fail-closed mode, which means that if you attempt to exercise a particular provider available to CAS and the provider cannot be reached, authentication will be stopped and an error will be displayed. You can of course change this behavior so that authentication proceeds without exercising the provider functionality, if that provider cannot respond. Each defined multifactor authentication provider can set its own failure mode policy. Failure modes set at this location will override the global failure mode, but defer to any failure mode set by the registered service. Available values are as follows:
      • OPEN: Disallow MFA, proceed with authentication but don't communicate MFA to the RP.
      • CLOSED: Disallow MFA, block with authentication.
      • PHANTOM: Disallow MFA, proceed with authentication and communicate MFA to the RP.
      • NONE: Do not check for failure at all.
      • UNDEFINED: The default one indicating that no failure mode is set at all.
      Type
      BaseMultifactorAuthenticationProviderProperties.MultifactorAuthenticationProviderFailureModes
      Default
      CLOSED
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.idThe identifier for the multifactor provider.
      no default

      The identifier for the multifactor provider. In most cases, this need not be configured explicitly, unless multiple instances of the same provider type are configured in CAS.

      Type
      String
      Default
      none
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.jpa.autocommitThe default auto-commit behavior of connections in the pool.
      false

      The default auto-commit behavior of connections in the pool. Determined whether queries such as update/insert should be immediately executed without waiting for an underlying transaction.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.batch-sizeA non-zero value enables use of JDBC2 batch updates by Hibernate. e.g. recommended values between 5 and 30.
      100

      A non-zero value enables use of JDBC2 batch updates by Hibernate. e.g. recommended values between 5 and 30.

      Type
      Integer
      Default
      100
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.connection-timeoutIndicates the maximum number of milliseconds that the service can wait to obtain a connection.
      PT30S
      Duration

      Indicates the maximum number of milliseconds that the service can wait to obtain a connection.

      Type
      String
      Default
      PT30S
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.data-source-nameAttempts to do a JNDI data source look up for the data source name specified.
      no default

      Attempts to do a JNDI data source look up for the data source name specified. Will attempt to locate the data source object as is.

      Type
      String
      Default
      none
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.ddl-autoHibernate feature to automatically validate and exports DDL to the schema.
      update
      Hibernate feature to automatically validate and exports DDL to the schema. By default, creates and drops the schema automatically when a session is starts and ends. Setting the value to validate or none may be more desirable for production, but any of the following options can be used:
      • validate: Validate the schema, but make no changes to the database.
      • update: Update the schema.
      • create: Create the schema, destroying previous data.
      • create-drop: Drop the schema at the end of the session.
      • none: Do nothing.

      Note that during a version migration where any schema has changed create-drop will result in the loss of all data as soon as CAS is started. For transient data like tickets this is probably not an issue, but in cases like the audit table important data could be lost. Using `update`, while safe for data, is confirmed to result in invalid database state. validate or none settings are likely the only safe options for production use.

      For more info, see this.

      Type
      String
      Default
      update
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.default-catalogQualifies unqualified table names with the given catalog in generated SQL.
      no default

      Qualifies unqualified table names with the given catalog in generated SQL.

      Type
      String
      Default
      none
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.default-schemaQualify unqualified table names with the given schema/tablespace in generated SQL.
      no default

      Qualify unqualified table names with the given schema/tablespace in generated SQL.

      Type
      String
      Default
      none
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.dialectThe database dialect is a configuration setting for platform independent software (JPA, Hibernate, etc) which allows such software to translate its generic SQL statements into vendor specific DDL, DML.
      org.hibernate.dialect.HSQLDialect

      The database dialect is a configuration setting for platform independent software (JPA, Hibernate, etc) which allows such software to translate its generic SQL statements into vendor specific DDL, DML.

      Type
      String
      Default
      org.hibernate.dialect.HSQLDialect
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.fail-fast-timeoutSet the pool initialization failure timeout.
      1
      Set the pool initialization failure timeout.
      • Any value greater than zero will be treated as a timeout for pool initialization. The calling thread will be blocked from continuing until a successful connection to the database, or until the timeout is reached. If the timeout is reached, then a PoolInitializationException will be thrown.
      • A value of zero will not prevent the pool from starting in the case that a connection cannot be obtained. However, upon start the pool will attempt to obtain a connection and validate that the connectionTestQuery and connectionInitSql are valid. If those validations fail, an exception will be thrown. If a connection cannot be obtained, the validation is skipped and the pool will start and continue to try to obtain connections in the background. This can mean that callers to DataSource#getConnection() may encounter exceptions.
      • A value less than zero will not bypass any connection attempt and validation during startup, and therefore the pool will start immediately. The pool will continue to try to obtain connections in the background. This can mean that callers to DataSource#getConnection() may encounter exceptions.
      Note that if this timeout value is greater than or equal to zero (0), and therefore an initial connection validation is performed, this timeout does not override the connectionTimeout or validationTimeout; they will be honored before this timeout is applied. The default value is one millisecond.
      Type
      Long
      Default
      1
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.fetch-sizeUsed to specify number of rows to be fetched in a select query.
      100

      Used to specify number of rows to be fetched in a select query.

      Type
      Integer
      Default
      100
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.generate-statisticsAllow hibernate to generate query statistics.
      false

      Allow hibernate to generate query statistics.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.health-queryThe SQL query to be executed to test the validity of connections.
      no default

      The SQL query to be executed to test the validity of connections. This is for "legacy" databases that do not support the JDBC4 Connection.isValid() API.

      Type
      String
      Default
      none
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.idle-timeoutControls the maximum amount of time that a connection is allowed to sit idle in the pool.
      PT10M
      Duration

      Controls the maximum amount of time that a connection is allowed to sit idle in the pool.

      Type
      String
      Default
      PT10M
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.isolate-internal-queriesThis property determines whether data source isolates internal pool queries, such as the connection alive test, in their own transaction.
      false

      This property determines whether data source isolates internal pool queries, such as the connection alive test, in their own transaction.

      Since these are typically read-only queries, it is rarely necessary to encapsulate them in their own transaction. This property only applies if #autocommit is disabled.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.isolation-level-nameDefines the isolation level for transactions.
      ISOLATION_READ_COMMITTED

      Defines the isolation level for transactions. @see org.springframework.transaction.TransactionDefinition

      Type
      String
      Default
      ISOLATION_READ_COMMITTED
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.leak-thresholdControls the amount of time that a connection can be out of the pool before a message is logged indicating a possible connection leak.
      PT6S
      Duration

      Controls the amount of time that a connection can be out of the pool before a message is logged indicating a possible connection leak.

      Type
      String
      Default
      PT6S
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.physical-naming-strategy-class-nameFully-qualified name of the class that can control the physical naming strategy of hibernate.
      org.apereo.cas.hibernate.CasHibernatePhysicalNamingStrategy

      Fully-qualified name of the class that can control the physical naming strategy of hibernate.

      Type
      String
      Default
      org.apereo.cas.hibernate.CasHibernatePhysicalNamingStrategy
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.pool.keep-alive-timeThis property controls the keepalive interval for a connection in the pool.
      0
      Duration

      This property controls the keepalive interval for a connection in the pool. An in-use connection will never be tested by the keepalive thread, only when it is idle will it be tested. Default is zero, which disables this feature.

      Type
      String
      Default
      0
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.max-sizeControls the maximum number of connections to keep in the pool, including both idle and in-use connections.
      18

      Controls the maximum number of connections to keep in the pool, including both idle and in-use connections.

      Type
      Integer
      Default
      18
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.max-waitSets the maximum time in seconds that this data source will wait while attempting to connect to a database.
      PT2S
      Duration

      Sets the maximum time in seconds that this data source will wait while attempting to connect to a database.

      A value of zero specifies that the timeout is the default system timeout if there is one; otherwise, it specifies that there is no timeout.

      Type
      String
      Default
      PT2S
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.maximum-lifetimeThis property controls the maximum lifetime of a connection in the pool.
      PT10M
      Duration

      This property controls the maximum lifetime of a connection in the pool. When a connection reaches this timeout, even if recently used, it will be retired from the pool. An in-use connection will never be retired, only when it is idle will it be removed.

      Type
      String
      Default
      PT10M
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.min-sizeControls the minimum size that the pool is allowed to reach, including both idle and in-use connections.
      6

      Controls the minimum size that the pool is allowed to reach, including both idle and in-use connections.

      Type
      Integer
      Default
      6
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.nameSet the name of the connection pool.
      no default

      Set the name of the connection pool. This is primarily used for the MBean to uniquely identify the pool configuration.

      Type
      String
      Default
      none
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.suspensionWhether or not pool suspension is allowed.
      false

      Whether or not pool suspension is allowed.

      There is a performance impact when pool suspension is enabled. Unless you need it (for a redundancy system for example) do not enable it.

      Type
      Boolean
      Default
      false
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.pool.timeout-millisThe maximum number of milliseconds that the pool will wait for a connection to be validated as alive.
      1000

      The maximum number of milliseconds that the pool will wait for a connection to be validated as alive.

      Type
      Long
      Default
      1000
      Defined by
      ConnectionPoolingProperties
      cas.authn.mfa.yubikey.jpa.propagation-behavior-nameDefines the propagation behavior for transactions.
      PROPAGATION_REQUIRED

      Defines the propagation behavior for transactions. @see org.springframework.transaction.TransactionDefinition

      Type
      String
      Default
      PROPAGATION_REQUIRED
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.propertiesAdditional settings provided by Hibernate (or the connection provider) in form of key-value pairs.
      no default

      Additional settings provided by Hibernate (or the connection provider) in form of key-value pairs.

      Type
      Map<String,String>
      Default
      none
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jpa.read-onlyConfigures the Connections to be added to the pool as read-only Connections.
      false

      Configures the Connections to be added to the pool as read-only Connections.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyJpaMultifactorProperties
      cas.authn.mfa.yubikey.jsonKeep device registration records inside a static JSON resource.
      no default
      SpEL

      Keep device registration records inside a static JSON resource.

      Type
      YubiKeyJsonMultifactorProperties
      Default
      none
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      Supports
      Spring Expression Language
      cas.authn.mfa.yubikey.mongo.authentication-database-nameName of the database to use for authentication.
      no default

      Name of the database to use for authentication.

      Type
      String
      Default
      none
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.drop-collectionWhether collections should be dropped on startup and re-created.
      false

      Whether collections should be dropped on startup and re-created.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.pool.idle-timeThe maximum idle time of a pooled connection.
      PT30S
      Duration

      The maximum idle time of a pooled connection. A zero value indicates no limit to the idle time. A pooled connection that has exceeded its idle time will be closed and replaced when necessary by a new connection.

      Type
      String
      Default
      PT30S
      Defined by
      MongoDbConnectionPoolProperties
      cas.authn.mfa.yubikey.mongo.pool.life-timeThe maximum time a pooled connection can live for.
      PT60S
      Duration

      The maximum time a pooled connection can live for. A zero value indicates no limit to the life time. A pooled connection that has exceeded its life time will be closed and replaced when necessary by a new connection.

      Type
      String
      Default
      PT60S
      Defined by
      MongoDbConnectionPoolProperties
      cas.authn.mfa.yubikey.mongo.pool.max-sizeMaximum number of connections to keep around.
      10

      Maximum number of connections to keep around.

      Type
      Integer
      Default
      10
      Defined by
      MongoDbConnectionPoolProperties
      cas.authn.mfa.yubikey.mongo.pool.max-wait-timeThe maximum time that a thread may wait for a connection to become available.
      PT60S
      Duration

      The maximum time that a thread may wait for a connection to become available.

      Type
      String
      Default
      PT60S
      Defined by
      MongoDbConnectionPoolProperties
      cas.authn.mfa.yubikey.mongo.pool.min-sizeMinimum number of connections to keep around.
      1

      Minimum number of connections to keep around.

      Type
      Integer
      Default
      1
      Defined by
      MongoDbConnectionPoolProperties
      cas.authn.mfa.yubikey.mongo.read-concernRead concern.
      AVAILABLE
      Read concern. Accepted values are:
      • LOCAL
      • MAJORITY
      • LINEARIZABLE
      • SNAPSHOT
      • AVAILABLE
      Type
      String
      Default
      AVAILABLE
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.read-preferenceRead preference.
      PRIMARY
      Read preference. Accepted values are:
      • PRIMARY
      • SECONDARY
      • SECONDARY_PREFERRED
      • PRIMARY_PREFERRED
      • NEAREST
      Type
      String
      Default
      PRIMARY
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.replica-setA replica set in MongoDB is a group of mongod processes that maintain the same data set.
      no default

      A replica set in MongoDB is a group of mongod processes that maintain the same data set. Replica sets provide redundancy and high availability, and are the basis for all production deployments.

      Type
      String
      Default
      none
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.retry-writesSets whether writes should be retried if they fail due to a network error.
      false

      Sets whether writes should be retried if they fail due to a network error.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.ssl-enabledWhether connections require SSL.
      false

      Whether connections require SSL.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.timeoutMongoDb database connection timeout.
      PT5S
      Duration

      MongoDb database connection timeout.

      Type
      String
      Default
      PT5S
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.mongo.write-concernWrite concern describes the level of acknowledgement requested from MongoDB for write operations to a standalone mongo db or to replica sets or to sharded clusters.
      ACKNOWLEDGED

      Write concern describes the level of acknowledgement requested from MongoDB for write operations to a standalone mongo db or to replica sets or to sharded clusters. In sharded clusters, mongo db instances will pass the write concern on to the shards.

      Type
      String
      Default
      ACKNOWLEDGED
      Defined by
      YubiKeyMongoDbMultifactorProperties
      cas.authn.mfa.yubikey.multiple-device-registration-enabledWhen enabled, allows the user/system to accept multiple accounts and device registrations per user, allowing one to switch between or register new devices/accounts automatically.
      false

      When enabled, allows the user/system to accept multiple accounts and device registrations per user, allowing one to switch between or register new devices/accounts automatically.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.nameThe name of the authentication handler used to verify credentials in MFA.
      no default

      The name of the authentication handler used to verify credentials in MFA. Remember that if you have more than one authentication handler of the same type, the names must be defined uniquely for each authentication scheme. Failing to do so may force CAS to not register authentication handlers with a duplicate name.

      Type
      String
      Default
      none
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.orderThe order of the authentication handler in the chain.
      no default

      The order of the authentication handler in the chain.

      Type
      Integer
      Default
      none
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.rankAt times, CAS needs to determine the correct provider when step-up authentication is required.
      0
      At times, CAS needs to determine the correct provider when step-up authentication is required. Consider for a moment that CAS already has established an SSO session with/without a provider and has reached a level of authentication. Another incoming request attempts to exercise that SSO session with a different and often competing authentication requirement that may differ from the authentication level CAS has already established. Concretely, examples may be:
      • CAS has achieved an SSO session, but a separate request now requires step-up authentication with DuoSecurity.
      • CAS has achieved an SSO session with an authentication level satisfied by DuoSecurity, but a separate request now requires step-up authentication with YubiKey.
      In certain scenarios, CAS will attempt to rank authentication levels and compare them with each other. If CAS already has achieved a level that is higher than what the incoming request requires, no step-up authentication will be performed. If the opposite is true, CAS will route the authentication flow to the required authentication level and upon success, will adjust the SSO session with the new higher authentication level now satisfied. Ranking of authentication methods is done per provider via specific properties for each. Note that the higher the rank value is, the higher on the security scale it remains. A provider that ranks higher with a larger weight value trumps and override others with a lower value.
      Type
      Integer
      Default
      0
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.redis.certificate-fileMay be used when making SSL connections to build the trust manager.
      no default

      May be used when making SSL connections to build the trust manager. Sets the certificate file to use for client authentication. This is typically an X.509 certificate file (or chain file) in PEM format.

      Type
      File
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.cluster.dynamic-refresh-sourcesWhether to discover and query all cluster nodes for obtaining the cluster topology.
      true

      Whether to discover and query all cluster nodes for obtaining the cluster topology. When set to false, only the initial seed nodes are used as sources for topology discovery.

      Type
      Boolean
      Default
      true
      Defined by
      RedisClusterProperties
      cas.authn.mfa.yubikey.redis.cluster.max-redirectsThe max number of redirects to follow.
      0

      The max number of redirects to follow.

      Type
      Integer
      Default
      0
      Defined by
      RedisClusterProperties
      cas.authn.mfa.yubikey.redis.cluster.nodesList of nodes available in the redis cluster.
      no default

      List of nodes available in the redis cluster.

      Type
      List<RedisClusterNodeProperties>
      Default
      none
      Defined by
      RedisClusterProperties
      cas.authn.mfa.yubikey.redis.cluster.nodes[0].idIdentifier of this node.
      no default

      Identifier of this node.

      Type
      String
      Default
      none
      Defined by
      RedisClusterNodeProperties
      cas.authn.mfa.yubikey.redis.cluster.nodes[0].nameName of this node.
      no default

      Name of this node.

      Type
      String
      Default
      none
      Defined by
      RedisClusterNodeProperties
      cas.authn.mfa.yubikey.redis.cluster.topology-refresh-periodEnables periodic refresh of cluster topology and sets the refresh period.
      no default
      Duration

      Enables periodic refresh of cluster topology and sets the refresh period.

      Type
      String
      Default
      none
      Defined by
      RedisClusterProperties
      cas.authn.mfa.yubikey.redis.connect-timeoutConnection timeout.
      PT10S
      Duration

      Connection timeout.

      Type
      String
      Default
      PT10S
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.keep-alive-countThe maximum number of keepalive probes TCP should send before dropping the connection.
      0

      The maximum number of keepalive probes TCP should send before dropping the connection. By default, leaving this number at zero disables keepalive.

      Type
      Integer
      Default
      0
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.keep-alive-idle-timeoutThe time the connection needs to remain idle before TCP starts sending keepalive probes if keepalive is enabled.
      PT2H
      Duration

      The time the connection needs to remain idle before TCP starts sending keepalive probes if keepalive is enabled.

      Type
      String
      Default
      PT2H
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.keep-alive-intervalThe time the connection needs to remain idle before TCP starts sending keepalive probes.
      PT60S
      Duration

      The time the connection needs to remain idle before TCP starts sending keepalive probes.

      Type
      String
      Default
      PT60S
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.key-certificate-chain-fileMay be used when making SSL connections to build the key manager.
      no default

      May be used when making SSL connections to build the key manager. Sets the key certificate file to use for client authentication. This is typically an X.509 certificate file (or chain file) in PEM format.

      Type
      File
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.key-fileMay be used when making SSL connections.
      no default

      May be used when making SSL connections. Sets the key file for client authentication. The key is reloaded on each connection attempt that allows CAS to replace certificates during runtime. This is typically a PKCS#8 private key file in PEM format.

      Type
      File
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.key-passwordThe password of the #keyFile , or null if it's not password-protected.
      no default

      The password of the #keyFile, or null if it's not password-protected.

      Type
      String
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.pool.fairnessReturns whether or not the pool serves threads waiting to borrow objects fairly.
      false

      Returns whether or not the pool serves threads waiting to borrow objects fairly. True means that waiting threads are served as if waiting in a FIFO queue.

      Type
      Boolean
      Default
      false
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.lifoReturns whether the pool has LIFO (last in, first out) behaviour with respect to idle objects - always returning the most recently used object from the pool, or as a FIFO (first in, first out) queue, where the pool al...
      true

      Returns whether the pool has LIFO (last in, first out) behaviour with respect to idle objects - always returning the most recently used object from the pool, or as a FIFO (first in, first out) queue, where the pool always returns the oldest object in the idle object pool.

      Type
      Boolean
      Default
      true
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.max-activeMax number of connections that can be allocated by the pool at a given time.
      8

      Max number of connections that can be allocated by the pool at a given time. Use a negative value for no limit.

      Type
      Integer
      Default
      8
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.max-idleMax number of "idle" connections in the pool.
      8

      Max number of "idle" connections in the pool. Use a negative value to indicate an unlimited number of idle connections.

      Type
      Integer
      Default
      8
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.max-waitMaximum amount of time (in milliseconds) a connection allocation should block before throwing an exception when the pool is exhausted.
      PT5S
      Duration

      Maximum amount of time (in milliseconds) a connection allocation should block before throwing an exception when the pool is exhausted. Use a negative value to block indefinitely.

      Type
      String
      Default
      PT5S
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.min-evictable-idle-time-millisSets the minimum amount of time an object may sit idle in the pool before it is eligible for eviction by the idle object evictor (if any - see setTimeBetweenEvictionRunsMillis(long)).
      0

      Sets the minimum amount of time an object may sit idle in the pool before it is eligible for eviction by the idle object evictor (if any - see setTimeBetweenEvictionRunsMillis(long)). When non-positive, no objects will be evicted from the pool due to idle time alone.

      Type
      Long
      Default
      0
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.min-idleTarget for the minimum number of idle connections to maintain in the pool.
      0

      Target for the minimum number of idle connections to maintain in the pool. This setting only has an effect if it is positive.

      Type
      Integer
      Default
      0
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.num-tests-per-eviction-runSets the maximum number of objects to examine during each run (if any) of the idle object evictor thread.
      0

      Sets the maximum number of objects to examine during each run (if any) of the idle object evictor thread. When positive, the number of tests performed for a run will be the minimum of the configured value and the number of idle instances in the pool. When negative, the number of tests performed will be ceil(getNumIdle()/ abs(getNumTestsPerEvictionRun())) which means that when the value is -n roughly one nth of the idle objects will be tested per run.

      Type
      Integer
      Default
      0
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.soft-min-evictable-idle-time-millisSets the minimum amount of time an object may sit idle in the pool before it is eligible for eviction by the idle object evictor (if any - see setTimeBetweenEvictionRunsMillis(long)), with the extra condition that at...
      0

      Sets the minimum amount of time an object may sit idle in the pool before it is eligible for eviction by the idle object evictor (if any - see setTimeBetweenEvictionRunsMillis(long)), with the extra condition that at least minIdle object instances remain in the pool. This setting is overridden by getMinEvictableIdleTimeMillis() (that is, if getMinEvictableIdleTimeMillis() is positive, then getSoftMinEvictableIdleTimeMillis() is ignored).

      Type
      Long
      Default
      0
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.test-on-borrowReturns whether objects borrowed from the pool will be validated before being returned from the borrowObject() method.
      false

      Returns whether objects borrowed from the pool will be validated before being returned from the borrowObject() method. Validation is performed by the validateObject() method of the factory associated with the pool. If the object fails to validate, it will be removed from the pool and destroyed, and a new attempt will be made to borrow an object from the pool.

      Type
      Boolean
      Default
      false
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.test-on-createReturns whether objects created for the pool will be validated before being returned from the borrowObject() method.
      false

      Returns whether objects created for the pool will be validated before being returned from the borrowObject() method. Validation is performed by the validateObject() method of the factory associated with the pool. If the object fails to validate, then borrowObject() will fail.

      Type
      Boolean
      Default
      false
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.test-on-returnReturns whether objects borrowed from the pool will be validated when they are returned to the pool via the returnObject() method.
      false

      Returns whether objects borrowed from the pool will be validated when they are returned to the pool via the returnObject() method. Validation is performed by the validateObject() method of the factory associated with the pool. Returning objects that fail validation are destroyed rather then being returned the pool.

      Type
      Boolean
      Default
      false
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.test-while-idleReturns whether objects sitting idle in the pool will be validated by the idle object evictor ( if any - see setTimeBetweenEvictionRunsMillis(long)).
      false

      Returns whether objects sitting idle in the pool will be validated by the idle object evictor ( if any - see setTimeBetweenEvictionRunsMillis(long)). Validation is performed by the validateObject() method of the factory associated with the pool. If the object fails to validate, it will be removed from the pool and destroyed.

      Type
      Boolean
      Default
      false
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.pool.time-between-eviction-runs-millisSets the amount of time (in milliseconds) between runs of the idle object evictor thread.
      -1

      Sets the amount of time (in milliseconds) between runs of the idle object evictor thread. When non-positive, no idle object evictor thread will be run. If positive, the idle object evictor thread will run at least once every timeBetweenEvictionRunsMillis milliseconds, and will attempt to evict objects from the pool that are idle longer than getMinEvictableIdleTimeMillis() (if positive) or getSoftMinEvictableIdleTimeMillis() (if positive).

      Type
      Long
      Default
      -1
      Defined by
      RedisPoolProperties
      cas.authn.mfa.yubikey.redis.protocol-versionRedis protocol version.
      RESP3

      Redis protocol version.

      Type
      String
      Default
      RESP3
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.read-fromSetting that describes how Lettuce routes read operations to replica nodes.
      no default
      Setting that describes how Lettuce routes read operations to replica nodes. Note that modes referencing MASTER/SLAVE are deprecated (but still supported) in the Lettuce redis client dependency so migrate config to UPSTREAM/REPLICA. Available values are as follows:
      • UPSTREAM: Read from the current upstream node.
      • UPSTREAMPREFERRED: Read from the upstream node, but if it is unavailable, read from replica nodes.
      • MASTER: Read from the current upstream node.
      • MASTERPREFERRED: Read from the upstream node, but if it is unavailable, read from replica nodes.
      • SLAVE: Read from replica nodes.
      • SLAVEPREFERRED: Read from the replica nodes, but if none is unavailable, read from the upstream node.
      • REPLICA: Read from replica nodes.
      • REPLICAPREFERRED: Read from the replica nodes, but if none is unavailable, read from the upstream node.
      • ANY: Read from any node of the cluster.
      • ANYREPLICA: Read from any replica node of the cluster.
      • NEAREST: Read from the nearest node.
      Type
      BaseRedisProperties.RedisReadFromTypes
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.sentinel.nodelist of host:port pairs.
      no default

      list of host:port pairs.

      Type
      List<String>
      Default
      none
      Defined by
      RedisSentinelProperties
      cas.authn.mfa.yubikey.redis.sentinel.passwordLogin password of the sentinel server.
      no default

      Login password of the sentinel server.

      Type
      String
      Default
      none
      Defined by
      RedisSentinelProperties
      cas.authn.mfa.yubikey.redis.share-native-connectionsThe shared native connection is never closed by Lettuce connection, therefore it is not validated by default when connections are retrieved.
      no default

      The shared native connection is never closed by Lettuce connection, therefore it is not validated by default when connections are retrieved. If this setting is true, a shared connection will be used for regular operations and a connection provider will be used to select a connection for blocking and tx operations only, which should not share a connection. If native connection sharing is disabled, new (or pooled) connections will be used for all operations. By default, multiple connections share a single thread-safe native connection. If you enable connection pooling, then native connection sharing will be disabled and the connection pool will be used for all operations. You may however explicitly control connection sharing via this setting as an override.

      Type
      Boolean
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.start-tlsStart mutual TLS.
      false

      Start mutual TLS. In order to support TLS, Redis should be configured with a X.509 certificate and a private key. In addition, it is necessary to specify a CA certificate bundle file or path to be used as a trusted root when validating certificates.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.timeoutCommand timeout.
      PT60S
      Duration

      Command timeout.

      Type
      String
      Default
      PT60S
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.uriDatabase URI.
      no default

      Database URI.

      Type
      String
      Default
      none
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.use-sslWhether or not to use SSL for connection factory.
      false

      Whether or not to use SSL for connection factory.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.redis.verify-peerControl how peer verification is handled with redis connections.
      true

      Control how peer verification is handled with redis connections. Peer verification is a security feature that checks if the host you're connecting to is who it says it is. This is often done by checking a digital certificate.

      Type
      Boolean
      Default
      true
      Defined by
      YubiKeyRedisMultifactorProperties
      cas.authn.mfa.yubikey.rest.basic-auth-passwordIf REST endpoint is protected via basic authentication, specify the password for authentication.
      no default

      If REST endpoint is protected via basic authentication, specify the password for authentication.

      Type
      String
      Default
      none
      Defined by
      YubiKeyRestfulMultifactorProperties
      cas.authn.mfa.yubikey.rest.basic-auth-usernameIf REST endpoint is protected via basic authentication, specify the username for authentication.
      no default

      If REST endpoint is protected via basic authentication, specify the username for authentication.

      Type
      String
      Default
      none
      Defined by
      YubiKeyRestfulMultifactorProperties
      cas.authn.mfa.yubikey.rest.headersHeaders, defined as a Map, to include in the request when making the REST call.
      no default

      Headers, defined as a Map, to include in the request when making the REST call. Will overwrite any header that CAS is pre-defined to send and include in the request. Key in the map should be the header name and the value in the map should be the header value.

      Type
      Map<String,String>
      Default
      none
      Defined by
      YubiKeyRestfulMultifactorProperties
      cas.authn.mfa.yubikey.rest.maximum-retry-attemptsWhen attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.
      3

      When attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.

      Type
      Integer
      Default
      3
      Defined by
      YubiKeyRestfulMultifactorProperties
      cas.authn.mfa.yubikey.rest.methodHTTP method to use when contacting the rest endpoint.
      GET

      HTTP method to use when contacting the rest endpoint. Examples include GET, POST, etc.

      Type
      String
      Default
      GET
      Defined by
      YubiKeyRestfulMultifactorProperties
      cas.authn.mfa.yubikey.trusted-device-enabledIndicates whether this provider should support trusted devices.
      false

      Indicates whether this provider should support trusted devices.

      Type
      Boolean
      Default
      false
      Defined by
      YubiKeyMultifactorAuthenticationProperties
      cas.authn.mfa.yubikey.validatorDefine the strategy that controls how devices should be validated.
      VERIFY
      Define the strategy that controls how devices should be validated. Available values are as follows:
      • VERIFY: Verify yubikey devices via YubiKey APIs.
      • SKIP: Skip all validations checks and accept all devices.
      • REJECT: Reject all devices.
      Type
      YubiKeyMultifactorAuthenticationProperties.YubiKeyDeviceValidationOptions
      Default
      VERIFY
      Defined by
      YubiKeyMultifactorAuthenticationProperties

      Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

      Signing & encryption

      This CAS feature is able to accept signing and encryption crypto keys. In most scenarios if keys are not provided, CAS will auto-generate them. The following instructions apply if you wish to manually and beforehand create the signing and encryption keys.

      Note that if you are asked to create a JWK of a certain size for the key, you are to use the following set of commands to generate the token:

      1
      2
      
      wget https://raw.githubusercontent.com/apereo/cas/master/etc/jwk-gen.jar
      java -jar jwk-gen.jar -t oct -s [size]
      

      The outcome would be similar to:

      1
      2
      3
      4
      5
      
      {
        "kty": "oct",
        "kid": "...",
        "k": "..."
      }
      

      The generated value for k needs to be assigned to the relevant CAS settings. Note that keys generated via the above algorithm are processed by CAS using the Advanced Encryption Standard (AES) algorithm which is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology.


      Hibernate & JDBC

      Control global properties that are relevant to Hibernate, when CAS attempts to employ and utilize database resources, connections and queries.

      cas.jdbc.gen-ddlWhether to generate DDL after the EntityManagerFactory has been initialized creating/updating all relevant tables.
      true

      Whether to generate DDL after the EntityManagerFactory has been initialized creating/updating all relevant tables.

      Type
      Boolean
      Default
      true
      Defined by
      DatabaseProperties
      cas.jdbc.physical-table-namesIndicate a physical table name to be used by the hibernate naming strategy in case table names need to be customized for the specific type of database.
      no default

      Indicate a physical table name to be used by the hibernate naming strategy in case table names need to be customized for the specific type of database. The key here indicates the CAS-provided table name and the value is the translate physical name for the database. If a match is not found for the CAS-provided table name, then that name will be used by default.

      Type
      Map<String,String>
      Default
      none
      Defined by
      DatabaseProperties
      cas.jdbc.show-sqlWhether SQL queries should be displayed in the console/logs.
      false

      Whether SQL queries should be displayed in the console/logs.

      Type
      Boolean
      Default
      false
      Defined by
      DatabaseProperties
      Groovy scripting

      CAS takes advantage of Apache Groovy in forms of either embedded or external scripts that allow one to, by default, dynamically build constructs, attributes, access strategies and a lot more. To activate the functionality described here, you may need to prepare CAS to support and integrate with Apache Groovy.

      Please review this guide to configure your build.

      Notes on configuration

      Configuration Metadata

      The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

      Be Selective

      This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

      YAGNI

      Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

      Naming Convention

      Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

      :information_source: Note

      When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

      Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

      Validation

      Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

      Indexed Settings

      CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

      By default, all YubiKey accounts for users are allowed to authenticate. Devices that need to be authorized for authentication need to have followed an out-of-band registration process where the record for them is found in one of the following storage backends. Upon authentication, CAS will begin to search the configured registration database for matching record for the authenticated user and device in order to allow for a successful authentication event.

      Storage Description
      JSON See this guide.
      REST See this guide.
      Permissive See this guide.
      JPA See this guide.
      Redis See this guide.
      DynamoDb See this guide.
      MongoDb See this guide.
      Custom See this guide.

      Bypass

      The following settings and properties are available from the CAS configuration catalog:

      cas.authn.mfa.yubikey.bypass.groovy.locationThe location of the resource.
      no default
      Required

      The location of the resource. Resources can be URLs, or files found either on the classpath or outside somewhere in the file system.

      In the event the configured resource is a Groovy script, especially if the script is set to reload on changes, you may need to adjust the total number of inotify instances. On Linux, you may need to add the following line to /etc/sysctl.conf: fs.inotify.max_user_instances = 256.

      You can check the current value via cat /proc/sys/fs/inotify/max_user_instances.

      In situations and scenarios where CAS is able to automatically watch the underlying resource for changes and detect updates and modifications dynamically, you may be able to specify the following setting as either an environment variable or system property with a value of false to disable the resource watcher: org.apereo.cas.util.io.PathWatcherService.

      Type
      Resource
      Default
      none
      Defined by
      GroovyMultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.urlThe endpoint URL to contact and retrieve attributes.
      no default
      RequiredSpEL

      The endpoint URL to contact and retrieve attributes.

      Type
      String
      Default
      none
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties
      Supports
      Spring Expression Language
      cas.authn.mfa.yubikey.bypass.authentication-attribute-nameSkip multifactor authentication based on designated authentication attribute names.
      no default

      Skip multifactor authentication based on designated authentication attribute names.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.authentication-attribute-valueOptionally, skip multifactor authentication based on designated authentication attribute values.
      no default
      Regex

      Optionally, skip multifactor authentication based on designated authentication attribute values. Multiple values may be separated by a comma.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.authentication-handler-nameSkip multifactor authentication depending on form of primary authentication execution.
      no default
      Regex

      Skip multifactor authentication depending on form of primary authentication execution. Specifically, skip multifactor if the a particular authentication handler noted by its name successfully is able to authenticate credentials in the primary factor. Multiple values may be separated by a comma.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.authentication-method-nameSkip multifactor authentication depending on method/form of primary authentication execution.
      no default
      Regex

      Skip multifactor authentication depending on method/form of primary authentication execution. Specifically, skip multifactor if the authentication method attribute collected as part of authentication metadata matches a certain value. Multiple values may be separated by a comma.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.credential-class-typeSkip multifactor authentication depending on form of primary credentials.
      no default

      Skip multifactor authentication depending on form of primary credentials. Value must equal the fully qualified class name of the credential type.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.http-request-headersSkip multifactor authentication if the http request contains the defined header names.
      no default
      Regex

      Skip multifactor authentication if the http request contains the defined header names. Header names may be comma-separated and can be regular expressions; values are ignored.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.http-request-remote-addressSkip multifactor authentication if the http request's remote address or host matches the value defined here.
      no default
      Regex

      Skip multifactor authentication if the http request's remote address or host matches the value defined here. The value may be specified as a regular expression.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.principal-attribute-nameSkip multifactor authentication based on designated principal attribute names.
      no default

      Skip multifactor authentication based on designated principal attribute names.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.principal-attribute-valueOptionally, skip multifactor authentication based on designated principal attribute values.
      no default
      Regex

      Optionally, skip multifactor authentication based on designated principal attribute values.

      Type
      String
      Default
      none
      Defined by
      MultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.basic-auth-passwordIf REST endpoint is protected via basic authentication, specify the password for authentication.
      no default

      If REST endpoint is protected via basic authentication, specify the password for authentication.

      Type
      String
      Default
      none
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.basic-auth-usernameIf REST endpoint is protected via basic authentication, specify the username for authentication.
      no default

      If REST endpoint is protected via basic authentication, specify the username for authentication.

      Type
      String
      Default
      none
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.headersHeaders, defined as a Map, to include in the request when making the REST call.
      no default

      Headers, defined as a Map, to include in the request when making the REST call. Will overwrite any header that CAS is pre-defined to send and include in the request. Key in the map should be the header name and the value in the map should be the header value.

      Type
      Map<String,String>
      Default
      none
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.maximum-retry-attemptsWhen attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.
      3

      When attempting to reach the endpoint, this setting controls the number of retry attempts that CAS should execute Setting this value to a zero or negative value will disable the retry policy.

      Type
      Integer
      Default
      3
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties
      cas.authn.mfa.yubikey.bypass.rest.methodHTTP method to use when contacting the rest endpoint.
      GET

      HTTP method to use when contacting the rest endpoint. Examples include GET, POST, etc.

      Type
      String
      Default
      GET
      Defined by
      RestfulMultifactorAuthenticationProviderBypassProperties

      Required settings may be needed to activate or affect the feature; review them even when they have a default. Optional settings only need to be set to change a default or to turn on the behavior they control. Third party settings belong to libraries such as Spring Boot that CAS builds on; their own documentation may have more detail.

      Groovy scripting

      CAS takes advantage of Apache Groovy in forms of either embedded or external scripts that allow one to, by default, dynamically build constructs, attributes, access strategies and a lot more. To activate the functionality described here, you may need to prepare CAS to support and integrate with Apache Groovy.

      Please review this guide to configure your build.

      Notes on configuration

      Configuration Metadata

      The collection of configuration properties listed in this section are automatically generated from the CAS source and components that contain the actual field definitions, types, descriptions, modules, etc. This metadata may not always be 100% accurate, or could be lacking details and sufficient explanations.

      Be Selective

      This section is meant as a guide only. Do NOT copy/paste the entire collection of settings into your CAS configuration; rather pick only the properties that you need. Do NOT enable settings unless you are certain of their purpose and do NOT copy settings into your configuration only to keep them as reference. All these ideas lead to upgrade headaches, maintenance nightmares and premature aging.

      YAGNI

      Note that for nearly ALL use cases, declaring and configuring properties listed here is sufficient. You should NOT have to explicitly massage a CAS XML/Java/etc configuration file to design an authentication handler, create attribute release policies, etc. CAS at runtime will auto-configure all required changes for you. If you are unsure about the meaning of a given CAS setting, do NOT turn it on without hesitation. Review the codebase or better yet, ask questions to clarify the intended behavior.

      Naming Convention

      Property names can be specified in very relaxed terms. For instance cas.someProperty, cas.some-property, cas.some_property are all valid names. While all forms are accepted by CAS, there are certain components (in CAS and other frameworks used) whose activation at runtime is conditional on a property value, where this property is required to have been specified in CAS configuration using kebab case. This is both true for properties that are owned by CAS as well as those that might be presented to the system via an external library or framework such as Spring Boot, etc.

      :information_source: Note

      When possible, properties should be stored in lower-case kebab format, such as cas.property-name=value. The only possible exception to this rule is when naming actuator endpoints; The name of the actuator endpoints (i.e. ssoSessions) MUST remain in camelCase mode.

      Settings and properties that are controlled by the CAS platform directly always begin with the prefix cas. All other settings are controlled and provided to CAS via other underlying frameworks and may have their own schemas and syntax. BE CAREFUL with the distinction. Unrecognized properties are rejected by CAS and/or frameworks upon which CAS depends. This means if you somehow misspell a property definition or fail to adhere to the dot-notation syntax and such, your setting is entirely refused by CAS and likely the feature it controls will never be activated in the way you intend.

      Validation

      Configuration properties are automatically validated on CAS startup to report issues with configuration binding, especially if defined CAS settings cannot be recognized or validated by the configuration schema. Additional validation processes are also handled via Configuration Metadata and property migrations applied automatically on startup by Spring Boot and family.

      Indexed Settings

      CAS settings able to accept multiple values are typically documented with an index, such as cas.some.setting[0]=value. The index [0] is meant to be incremented by the adopter to allow for distinct multiple configuration blocks.

      Device/Account Validation

      In the event that a new YubiKey should be registered, it may be desirable to execute additional validation processes before the account is registered with the underlying store. By default, the device registration step only verifies the device token. If you wish to extend this behavior, you can design your own validator that cross-checks the account against alternative sources and databases for validity and authorization:

      1
      2
      3
      4
      5
      6
      7
      8
      9
      10
      11
      
      package org.apereo.cas.support.yubikey;
      
      @AutoConfiguration
      @EnableConfigurationProperties(CasConfigurationProperties.class)
      public class MyYubiKeyConfiguration {
      
        @Bean
        public YubiKeyAccountValidator yubiKeyAccountValidator() {
            ...
        }
      }
      

      See this guide to learn more about how to register configurations into the CAS runtime.

      REST Protocol Credential Extraction

      In the event that the CAS REST Protocol is turned on, a special credential extractor is injected into the REST authentication engine in order to recognize YubiKey credentials and authenticate them as part of the REST request. The expected parameter name in the request body is yubikeyotp.