CAS OmniAuth Provider (FREE SELF)

To enable the CAS OmniAuth provider you must register your application with your CAS instance. This requires the service URL GitLab supplies to CAS. It should be something like: https://gitlab.example.com:443/users/auth/cas3/callback?url. Handling for Single Logout (SLO) is enabled by default, so you only have to configure CAS for back-channel logout.

  1. On your GitLab server, open the configuration file.

    For Omnibus package:

    sudo editor /etc/gitlab/gitlab.rb

    For installations from source:

    cd /home/git/gitlab
    
    sudo -u git -H editor config/gitlab.yml
  2. See Configure initial settings for initial settings.

  3. Add the provider configuration:

    For Omnibus package:

    gitlab_rails['omniauth_providers'] = [
      {
        name: "cas3",
        label: "Provider name", # optional label for login button, defaults to "Cas3"
        args: {
            url: "CAS_SERVER",
            login_url: "/CAS_PATH/login",
            service_validate_url: "/CAS_PATH/p3/serviceValidate",
            logout_url: "/CAS_PATH/logout"
        }
      }
    ]

    For installations from source:

    - { name: 'cas3',
        label: 'Provider name', # optional label for login button, defaults to "Cas3"
        args: {
          url: 'CAS_SERVER',
          login_url: '/CAS_PATH/login',
          service_validate_url: '/CAS_PATH/p3/serviceValidate',
          logout_url: '/CAS_PATH/logout' } }
  4. Change 'CAS_PATH' to the root of your CAS instance (such as cas).

  5. If your CAS instance does not use default TGC lifetimes, update the cas3.session_duration to at least the current TGC maximum lifetime. To explicitly disable SLO, regardless of CAS settings, set this to 0.

  6. Save the configuration file.

  7. Reconfigure or restart GitLab for the changes to take effect if you installed GitLab via Omnibus or from source respectively.

On the sign in page there should now be a CAS tab in the sign in form.