Jump to content
Welcome to our new Citrix community!

NetScaler AAA Form ->SSO->Integrated Auth


Recommended Posts

Hi Folks,

 

I'm migrating a customer's internal websites from KEMP to the NetScalers. The objective being to securely reverse proxy all the internal websites externally with AAA authentication.

 

Scenario:

Customer wishes to use NetScaler AAA Form for client-side authentication, which should then SSO to a back-end server that only supports integrated authentication.

 

Now I can only get this to work by design, using 401 based AAA. Doesn't work when I change the AAA Virtual Server to Forms-based(as expected).

 

Are there any work-around's for this as the KEMP's do have a feature called Custom Authentication Forms which allows to you to define client-side and server side authentication.

 

https://support.kemptechnologies.com/hc/en-us/articles/203126599-Custom-Authentication-Form

 

Surely, if the KEMP's can do it out of the box - there should be way for the NetScaler's too? Shouldn't it?  :)

 

cheers

Vinay

Link to comment
Share on other sites

  • 1 year later...

I realize I am resurrecting a fairly old thread, but were you able to get anywhere with this?

 

I too would like to be able to use  AAA Form based authentication to then pass credentials back to a website prompting for NTLM credentials.

 

If you were access the server/website directly, you receive a 401 style authentication window, which doesn't give me a form path to populate for my "Form Action URL" in the Traffic policy.

Link to comment
Share on other sites

  • 2 years later...

For the record I got it to work.

Form-based to NTLM SSO, works with a Session Policy with SSO to Web Applications enabled, bound to to the AAA-server.

 

I also had to adjust the SSO Attribute on the authentication server (to sAMAccountName or UserPrincipalName).

 

Since I have multiple domains with separate authentication policys I had to use "UserPrincipalName" so it also passes the domain. In Citrix documentation it sometimes spells "UserPrincipleName" but it need to be "UserPrincipalName".

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...