We have been using CAS for 10+ years for our authentication and have been using 
an external tomcat. With my next release I am moving to using the embedded 
tomcat. I have noticed that my audits are logging our load balancer IP Address 
instead of the client's. I have extended 
CasTomcatServletWebServerFactoryCustomizer to include the RemoteIpValve and to 
write the X-Forwarded-For header to this valve.

Saying this, am I approaching this wrong? I could not find a configuration to 
enable this behavior.

I do have the following set in my properties file.

cas.audit.engine.alternate-client-addr-header-name=X-Forwarded-For

I was curious if there was another setting I am missing before my deployment 
next week.

Thanks,
 -Jeremy
________________________
Jeremy Wickham
Mississippi State University
jeremy.wick...@msstate.edu<mailto:jeremy.wick...@msstate.edu>
Webex Personal Room: https://msstate.webex.com/meet/jrw16

-- 
- Website: https://apereo.github.io/cas
- List Guidelines: https://goo.gl/1VRrw7
- Contributions: https://goo.gl/mh7qDG
--- 
You received this message because you are subscribed to the Google Groups "CAS 
Community" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to cas-user+unsubscr...@apereo.org.
To view this discussion on the web visit 
https://groups.google.com/a/apereo.org/d/msgid/cas-user/CYYPR01MB83124634A3DA07C8B76F347099712%40CYYPR01MB8312.prod.exchangelabs.com.

Reply via email to