[Micronet] Connexxus web site

classic Classic list List threaded Threaded
4 messages Options
Reply | Threaded
Open this post in threaded view
|

[Micronet] Connexxus web site

T. K. Chen
Hi Micronet,

   Does any body know the technical contact for our new UC Travel portal
system(Connexxus https://secure.ucop.edu/connexxus/index.php)?
   The portal does not seem to have a proper "logoff" function. The "Exit"
button on the upper right corner doesn't seem to logoff users from CAS.


Thanks!

=======================
T. K. Chen
ERSO Application Programmer
177M Cory Hall
Berkeley, CA 94720-1770
-----------------------
Office (510) 642-7618
[hidden email]


 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Connexxus web site

Karl R. Grose
On 09/14/2010 19:38, T. K. Chen wrote:

>     Does any body know the technical contact for our new UC Travel portal
> system(Connexxus https://secure.ucop.edu/connexxus/index.php)?

Connexxus is using Shibboleth which in our implementation does not have
the equivalent of the CAS global logout feature.

--Karl

=======
>     The portal does not seem to have a proper "logoff" function. The "Exit"
> button on the upper right corner doesn't seem to logoff users from CAS.

 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Connexxus web site

T. K. Chen
It will pose a security risk, since users cannot do a CAS logoff from this
system.

=======================
T. K. Chen
ERSO Application Programmer
177M Cory Hall
Berkeley, CA 94720-1770
-----------------------
Office (510) 642-7618
[hidden email]
 

> -----Original Message-----
> From: [hidden email] [mailto:micronet-list-
> [hidden email]] On Behalf Of Karl R. Grose
> Sent: Tuesday, September 14, 2010 7:50 PM
> To: [hidden email]
> Subject: Re: [Micronet] Connexxus web site
>
> On 09/14/2010 19:38, T. K. Chen wrote:
>
> >     Does any body know the technical contact for our new UC Travel
> portal
> > system(Connexxus https://secure.ucop.edu/connexxus/index.php)?
>
> Connexxus is using Shibboleth which in our implementation does not have
> the equivalent of the CAS global logout feature.
>
> --Karl
>
> =======
> >     The portal does not seem to have a proper "logoff" function. The
> "Exit"
> > button on the upper right corner doesn't seem to logoff users from CAS.
>
>
> -------------------------------------------------------------------------
> The following was automatically added to this message by the list server:
>
> To learn more about Micronet, including how to subscribe to or unsubscribe
> from its mailing list and how to find out about upcoming meetings, please
> visit the Micronet Web site:
>
> http://micronet.berkeley.edu
>
> Messages you send to this mailing list are public and world-viewable, and
> the list's archives can be browsed and searched on the Internet.  This
> means these messages can be viewed by (among others) your bosses,
> prospective employers, and people who have known you in the past.


 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.
Reply | Threaded
Open this post in threaded view
|

Re: [Micronet] Connexxus web site

Karl R. Grose
On 09/15/2010 06:02 AM, T. K. Chen wrote:

> It will pose a security risk, since users cannot do a CAS logoff from this
> system.

Yes there is risk, as there always will be for any app that depends on a
user action to perform a logout.

Apps that use CAS and are sensitive to that risk can mitigate it by
requiring reauth and/or by using second-level CAS authN.

--Karl

=======

>> -----Original Message-----
>> From: [hidden email] [mailto:micronet-list-
>> [hidden email]] On Behalf Of Karl R. Grose
>> Sent: Tuesday, September 14, 2010 7:50 PM
>> To: [hidden email]
>> Subject: Re: [Micronet] Connexxus web site
>>
>> On 09/14/2010 19:38, T. K. Chen wrote:
>>
>>>     Does any body know the technical contact for our new UC Travel
>> portal
>>> system(Connexxus https://secure.ucop.edu/connexxus/index.php)?
>>
>> Connexxus is using Shibboleth which in our implementation does not have
>> the equivalent of the CAS global logout feature.

 
-------------------------------------------------------------------------
The following was automatically added to this message by the list server:

To learn more about Micronet, including how to subscribe to or unsubscribe from its mailing list and how to find out about upcoming meetings, please visit the Micronet Web site:

http://micronet.berkeley.edu

Messages you send to this mailing list are public and world-viewable, and the list's archives can be browsed and searched on the Internet.  This means these messages can be viewed by (among others) your bosses, prospective employers, and people who have known you in the past.