<abbrtitle="LemonLDAP::NG">LL::NG</abbr> can delegate authentication to a <abbrtitle="Central Authentication Service">CAS</abbr> server. This requires <ahref="http://sourcesup.cru.fr/projects/perlcas/"class="urlextern"title="http://sourcesup.cru.fr/projects/perlcas/"rel="nofollow">Perl CAS module</a>.
<divclass="notetip"><abbrtitle="LemonLDAP::NG">LL::NG</abbr> can also act as <ahref="idpcas.html"class="wikilink1"title="documentation:2.0:idpcas">CAS server</a>, that allows one to interconnect two <abbrtitle="LemonLDAP::NG">LL::NG</abbr> systems.
<abbrtitle="LemonLDAP::NG">LL::NG</abbr> can also request proxy tickets for its protected services. Proxy tickets will be collected at authentication phase and stored in user session under the form:
They can then be forwarded to applications trough <ahref="writingrulesand_headers.html#headers"class="wikilink1"title="documentation:2.0:writingrulesand_headers">HTTP headers</a>.
</p>
<divclass="notetip"><abbrtitle="Central Authentication Service">CAS</abbr> authentication will automatically add a <ahref="logoutforward.html"class="wikilink1"title="documentation:2.0:logoutforward">logout forward rule</a> on <abbrtitle="Central Authentication Service">CAS</abbr> server logout <abbrtitle="Uniform Resource Locator">URL</abbr> in order to close <abbrtitle="Central Authentication Service">CAS</abbr> session on <abbrtitle="LemonLDAP::NG">LL::NG</abbr> logout.
In Manager, go in <code>General Parameters</code>><code>Authentication modules</code> and choose <abbrtitle="Central Authentication Service">CAS</abbr> for authentication.
</p>
<divclass="notetip">You can then choose any other module for users and password.
</div>
<p>
Then, go in <code><abbrtitle="Central Authentication Service">CAS</abbr> parameters</code>:
</p>
<ul>
<liclass="level1"><divclass="li"><strong>Authentication level</strong>: authentication level for this module.</div>
<liclass="level1"><divclass="li"><strong>Display Name</strong>: Name to display. Required if you have more than 1 <abbrtitle="Central Authentication Service">CAS</abbr> server declared</div>
<liclass="level1"><divclass="li"><strong>Icon</strong>: Path to <abbrtitle="Central Authentication Service">CAS</abbr> Server icon, used only if you have more than 1 <abbrtitle="Central Authentication Service">CAS</abbr> server declared</div>
<liclass="level1"><divclass="li"><strong>Proxied services</strong>: list of services for which a proxy ticket is requested:</div>
<ul>
<liclass="level2"><divclass="li"><strong>Key</strong>: Service ID</div>
</li>
<liclass="level2"><divclass="li"><strong>Value</strong> Service <abbrtitle="Uniform Resource Locator">URL</abbr> (<abbrtitle="Central Authentication Service">CAS</abbr> service identifier)</div>
<divclass="notetip">If no proxied services defined, <abbrtitle="Central Authentication Service">CAS</abbr> authentication will not activate the <abbrtitle="Central Authentication Service">CAS</abbr> proxy mode with this <abbrtitle="Central Authentication Service">CAS</abbr> server.