CAS supports a policy-driven feature to limit successive failed authentication attempts to help prevent brute force Single sign-on provides a win/win in terms of security and convenience: it reduces password exposure to a single, trusted credential broker while transparently providing access to multiple services without repetitious logins. The Central Authentication Service (CAS) is a single sign-on protocol for the web. However, proxy tickets carry risk in that services accepting proxy tickets are responsible for validating the The name CAS also refers to a software package that implements this protocol. In December 2006, the Andrew W. Mellon Foundation awarded Yale its First Annual Mellon Award for Technology Collaboration, in the amount of $50,000, for Yale's development of CAS. Leaving the management interface A ticket-granting cookie is an HTTP cookie set by CAS upon the establishment of a single sign-on session. Proxy authentication, or delegated authentication, provides a powerful, important, and potentially security-improving (Note that CAS has historically supported the CAS is security software that provides secure Web-based single sign-on to Web-based applications. authentication is configured on a per-service basis, but the service management facility The filters are configured to sanitize authentication request parameters and reject the request if it is not compliant with the CAS protocol in the event that for instance, a parameter is repeated multiple times, includes multiple values, contains unacceptable values, etc. For back-channel logout, the SLO process relies on the SimpleHttpClient class which has a threads pool: its size must be defined to properly treat all the logout requests. Several other CAS distributions have been developed with new features. Long term authentication allows users to elect additional convenience at the expense of reduced security. The use of CAS generally CAS was conceived and developed by Shawn Bayern of Yale University Technology and Planning. CAS supports a number of features that can be leveraged to implement various security policies. Single sign-out, or single log-out (SLO), is a feature by which CAS services are notified of the termination of a CAS 