>We continue to use CAS, but we are continuing to evaluate other options
>as we start to explore a move from SSO to ESSO i.e. having a seamless
>signon from desktop through to the browser within our intranet.
We at Newcastle have ESSO via CAS and shib 2.1 deployed. We have written a guide on getting the prerequasits set up and tested with the active directory http://gfivo.ncl.ac.uk/documents/UsingKerberosticketsfortrueSingleSignOn.pdf we can provide information on how to setup CAS for SPNEGO based ESSO support should you want it, though once you have SPNEGO working on the server setting up CAS is relatively easy.
We have also been engaging with the internet2 to try and get support for SPNEGO based ESSO rolled into future version of shibboleth. I'm not sure how likely we are to be successful in that but our view is SPNEGO support shouldn't be too hard to add.