ITB Single Sign-On (CAS)
ITB's campus-wide single sign-on, built on the Apereo CAS (Central Authentication Service) protocol and running on ITB's own host login.itb.ac.id. The CAS 2.0 and CAS 3.0 ticket-validation endpoints are publicly reachable and return machine-readable cas:serviceResponse XML — verified 2026-09-01, /cas/p3/serviceValidate returned 200 application/xml with an INVALID_TICKET authenticationFailure for a synthetic ticket. No SAML or OIDC metadata is exposed (/cas/idp/metadata and /cas/oidc/.well-known/openid-configuration both 404), and shibboleth.itb.ac.id resolves in DNS but serves nothing, so ITB has no evidenced Shibboleth/SAML federation entry. Service registration and account provisioning are restricted to ITB-affiliated applications, and ITB publishes no specification for this surface.