« JA-SIG Keynote on Digital Identity | Main | In Denver With a Free Evening »

CAS: Simple Authentication

Ken McCrery, from Virginia Tech gave a presentation at JA-SIG on their experience using Central Authentication Service (CAS) to provide single sign-on and single sign-off for their campus systems. CAS is an authentication system originally created by Yale University to provide a trusted way for an application to authenticate a user. It’s freely available for download.

VT orginally used a home grown system called AuthPortal but their middleware group couldn’t keep up with the portal groups requirements. They determined to move to something that was more widely used.

They found that

  • CAS 2.0 was easy to deploy
  • Previous AuthPortal clients were simple to convert
  • Small footprint—fast and efficient
  • System has been very stable and reliable over the last two years.

According to the JA-SIG CAS Web site, CAS has

  • An open and well-documented protocol
  • An open-source Java server component
  • A library of clients for Java, .Net, PHP, Perl, Apache, uPortal, and others
  • Integrates with uPortal, BlueSocket, TikiWiki, Mule, Liferay, Moodle and others
  • Community documentation and implementation support
  • An extensive community of adopters

CAS is similar to OpenID in goals and overall effect. The academic IT community has largely gone it’s own way in solving lot of problems like authentication. That’s not necessarily because they’re out of touch. In fact, quite the opposite. They have a better traditional of cooperation because they’re aren’t really competing with each other and so they get together and scratch the itches before the commercial side is induce to cooperate by market forces. SSO was one such itch.

The problem is that now, they have a choice (or several) in OpenID, CardSpace, and others. There are several possible routes:

  1. Ignore outside project and continue to roll their own. Clearly they will miss out on the ability to integrate with products and services based on the more widely used protocols.
  2. Change over to a more widely used solution once the winners are more apparent. This is painful, but is often done.
  3. Integrate the ability to use these other systems with CAS so that CAS deployments begin to take advantage of the more widely deployed code base of the other systems.

I’ guess that the last option is the one academic institutions will follow.

Posted by on June 25, 2007 11:47 AM

See related posts:

4 Comments

I think there's a fourth option for academia that's better than the rest.

4. Join in and collaborate with the other non-academic communities that were mentioned in order to create a smooth transition to "an identity layer for the Internet".

Comment from William G. Thompson, Jr. at June 26, 2007 8:07 AM

The CAS project team is keenly aware of the evolving standards in this space and has as a state goal evolution towards these as they become usable and adopted.

CAS 3.1, which will be out in the next few weeks, supports a number of the of the other interop protocols such as OpenID and SAML.


Phil,

The CAS team is keeping track of the emerging standards. CAS 3.1 will be able to be run as an OpenId Server. We're also looking at including support for CardSpace in the near future (most likely the CAS 3.1.1 release).

One area we are extremely interested in exploring is using OpenId as a way to provide lightweight federation. It seems like a much smoother way to handle the WAYF scenario.

Lots of higher-ed IT people (the boring non-research implementor types :) are really excited about OpenID. A lot of the "loose" affiliations like parents, or applicants, or associated researcher really cry out for the ability to accept an external credential, and OpenID looks like it'll fit nicely.

I know Case Western built their own OpenID provider on top of CAS. One possible interesting scenario, given CAS's deployment footprint in higher-education and increasingly commercial services is CAS could conceivable be the implementation that a lot of early adopters use to become OpenID providers...

Leave a comment

I encourage you to leave a comment below. Your email address will not be displayed on Technometria, but allows me to communicate with you directly. Your email address won't be displayed, but will be used to compute a MicroID for your comment.