文档介绍:webbrowserapp.#1app.#2app.#3withCASserviceCAS:whydidwechooseit?webbrowserapp.#1app.#2app.#3authenticationserverwithoutSSOuserdatabaseuserIdIdpasswordUserauthenticationCASserverHTTPSwebbrowserUserauthenticationTGC:TicketGrantingCookieUser’spassporttotheCASserverPrivateandprotectedcookie(theonlyoneusedbyCAS,optional)Opaquere-playableticketCASIdpasswordHTTPSuseressinganapplicationafterauthenticationwebbrowserCASserverTGCHTTPSapplicationTGCSTSTSTST:ServiceTicketBrowser’spassporttotheCASclient(application)Opaqueandnonre-playableticketVerylimitedvalidity(afewseconds)essinganapplicationafterauthenticationCASserverHTTPSTGCSTSTSTIDwebbrowserTGCRedirectionsaretransparenttousersapplicationST:ServiceTicketBrowser’spassporttotheCASclient(application)Opaqueandnonre-playableticketVerylimitedvalidity(afewseconds)AccessinganapplicationwithoutauthenticationwebbrowserCASessinganapplicationwithoutauthenticationwebbrowserCASIdessanapplicationapplicationAuthenticatinguserswithCASCASauthenticationlefttoadministratorsESUP-PortailCASGenericHandlerMixedauthenticationXMLconfigurationLDAPdirectorydatabaseNISdomainX509certificatesKerberosdomainWindowsNTdomainflatfilesCASserverN-tierinstallationsPGT:ProxyGrantingTicketApplication’spassportforausertotheCASserverOpaqueandre-playableticketwebbrowserCASserverTGCapplication(CASproxy)STSTserviceIDPGTPGT