Delegates the authentication to a Central Authentication Service via the CAS version 1 protocol. CAS can provide single-sign-on. It returns the authenticated username.

The default role is "authenticated". In the advanced settings, you can specify a Groovy script to parse custom validation results provided by your CAS server and convert them to other group/role authorizations.