Docker部署CAS Server配置:如何注册SSO服务、创建用户及对接自研中间件?
Hey there! Let's tackle your CAS setup step by step—since you're new to both CAS and Docker, I'll keep things simple and actionable. You've got two key goals: registering your custom app as a CAS service for SSO, and adding more users to your Docker-hosted CAS Server. Let's break each down.
CAS uses "service registrations" to recognize which apps are allowed to use its SSO functionality. Here's how to set this up:
First, make sure you can easily edit CAS config files. If you didn't mount local directories when starting your CAS container, restart it with volume mounts so you can modify files locally without jumping into the container:
docker run -d -p 8443:8443 \ -v /your/local/cas/config:/etc/cas/config \ -v /your/local/cas/services:/etc/cas/services \ apereo/cas:latestReplace
/your/local/cas/configand/your/local/cas/serviceswith actual paths on your machine where you want to store CAS configs.Next, create a service registration file in your local
servicesdirectory (name it something likemy-custom-app.json). This tells CAS about your app:{ "@class": "org.apereo.cas.services.RegexRegisteredService", "serviceId": "^https://your-app-domain/.*", "name": "My Custom Software", "id": 1000, "description": "SSO access for my self-developed app", "evaluationOrder": 1, "attributeReleasePolicy": { "@class": "org.apereo.cas.services.ReturnAllAttributeReleasePolicy" } }serviceId: Replace with a regex that matches all URLs from your custom app (e.g.,^http://localhost:8080/.*if testing locally).id: Use a unique number (no duplicates with other services).attributeReleasePolicy: This returns all user attributes to your app, which is great for testing.
Restart your CAS container to apply the new service:
docker restart <your-cas-container-name-or-id>You can get the container ID/name with
docker ps.Finally, configure your custom app's CAS client:
- Point it to your CAS Server's URL (e.g.,
https://localhost:8443/cas). - Set the service URL to match the
serviceIdyou used in the registration file. - Test the flow: Visit your app's login page, it should redirect to CAS's login screen. After logging in with
casuser/Mellon, you'll be sent back to your app authenticated.
- Point it to your CAS Server's URL (e.g.,
By default, CAS uses a JSON user store for development. Here's how to add more users:
Go to your local
cas/configdirectory, and create or edit thecas.propertiesfile. Add this line to enable JSON user authentication:cas.authn.json.location=classpath:users.jsonCreate a
users.jsonfile in the sameconfigdirectory. This file holds all your user accounts. Here's an example with the default user plus two new ones:{ "users": [ { "username": "casuser", "password": "Mellon", "attributes": { "email": "casuser@example.com", "firstName": "CAS", "lastName": "User" } }, { "username": "johndoe", "password": "JohnDoe123!", "attributes": { "email": "john.doe@example.com", "firstName": "John", "lastName": "Doe" } }, { "username": "janedoe", "password": "JaneDoe456!", "attributes": { "email": "jane.doe@example.com", "firstName": "Jane", "lastName": "Doe" } } ] }Note: This uses plain-text passwords, which is only safe for development. For production, you'll need to encrypt passwords using CAS's password encoders.
Restart your CAS container again, and you can now log in with your new user accounts (e.g.,
johndoe/JohnDoe123!).
Quick Tips for Newbies
- CAS uses HTTPS by default, so when accessing the CAS login page, use
https://localhost:8443/cas—you'll get a certificate warning, which is normal for development. - If you need to peek inside the CAS container to check paths, run
docker exec -it <cas-container-id> /bin/bashto open a shell. - For your custom app's CAS client, pick a library that matches your tech stack: Java uses
cas-client-core, Python usespython-cas, Node.js usescas-authentication, etc.
内容的提问来源于stack exchange,提问作者Paul L

