You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Docker部署CAS Server配置:如何注册SSO服务、创建用户及对接自研中间件?

Hey there! Let's tackle your CAS setup step by step—since you're new to both CAS and Docker, I'll keep things simple and actionable. You've got two key goals: registering your custom app as a CAS service for SSO, and adding more users to your Docker-hosted CAS Server. Let's break each down.

1. Register Your Custom App as a CAS Service for SSO

CAS uses "service registrations" to recognize which apps are allowed to use its SSO functionality. Here's how to set this up:

  • First, make sure you can easily edit CAS config files. If you didn't mount local directories when starting your CAS container, restart it with volume mounts so you can modify files locally without jumping into the container:

    docker run -d -p 8443:8443 \
      -v /your/local/cas/config:/etc/cas/config \
      -v /your/local/cas/services:/etc/cas/services \
      apereo/cas:latest
    

    Replace /your/local/cas/config and /your/local/cas/services with actual paths on your machine where you want to store CAS configs.

  • Next, create a service registration file in your local services directory (name it something like my-custom-app.json). This tells CAS about your app:

    {
      "@class": "org.apereo.cas.services.RegexRegisteredService",
      "serviceId": "^https://your-app-domain/.*",
      "name": "My Custom Software",
      "id": 1000,
      "description": "SSO access for my self-developed app",
      "evaluationOrder": 1,
      "attributeReleasePolicy": {
        "@class": "org.apereo.cas.services.ReturnAllAttributeReleasePolicy"
      }
    }
    
    • serviceId: Replace with a regex that matches all URLs from your custom app (e.g., ^http://localhost:8080/.* if testing locally).
    • id: Use a unique number (no duplicates with other services).
    • attributeReleasePolicy: This returns all user attributes to your app, which is great for testing.
  • Restart your CAS container to apply the new service:

    docker restart <your-cas-container-name-or-id>
    

    You can get the container ID/name with docker ps.

  • Finally, configure your custom app's CAS client:

    • Point it to your CAS Server's URL (e.g., https://localhost:8443/cas).
    • Set the service URL to match the serviceId you used in the registration file.
    • Test the flow: Visit your app's login page, it should redirect to CAS's login screen. After logging in with casuser/Mellon, you'll be sent back to your app authenticated.
2. Create Additional Users in Your Docker CAS Server

By default, CAS uses a JSON user store for development. Here's how to add more users:

  • Go to your local cas/config directory, and create or edit the cas.properties file. Add this line to enable JSON user authentication:

    cas.authn.json.location=classpath:users.json
    
  • Create a users.json file in the same config directory. This file holds all your user accounts. Here's an example with the default user plus two new ones:

    {
      "users": [
        {
          "username": "casuser",
          "password": "Mellon",
          "attributes": {
            "email": "casuser@example.com",
            "firstName": "CAS",
            "lastName": "User"
          }
        },
        {
          "username": "johndoe",
          "password": "JohnDoe123!",
          "attributes": {
            "email": "john.doe@example.com",
            "firstName": "John",
            "lastName": "Doe"
          }
        },
        {
          "username": "janedoe",
          "password": "JaneDoe456!",
          "attributes": {
            "email": "jane.doe@example.com",
            "firstName": "Jane",
            "lastName": "Doe"
          }
        }
      ]
    }
    

    Note: This uses plain-text passwords, which is only safe for development. For production, you'll need to encrypt passwords using CAS's password encoders.

  • Restart your CAS container again, and you can now log in with your new user accounts (e.g., johndoe/JohnDoe123!).

Quick Tips for Newbies

  • CAS uses HTTPS by default, so when accessing the CAS login page, use https://localhost:8443/cas—you'll get a certificate warning, which is normal for development.
  • If you need to peek inside the CAS container to check paths, run docker exec -it <cas-container-id> /bin/bash to open a shell.
  • For your custom app's CAS client, pick a library that matches your tech stack: Java uses cas-client-core, Python uses python-cas, Node.js uses cas-authentication, etc.

内容的提问来源于stack exchange,提问作者Paul L

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:01:19