Brian Madden Logo
Your independent source for application and desktop virtualization.
advertisement

CAG EE 9.0 Smart Card Support with XenApp, in the Advanced Access Control / Citrix Access Gateway forum on BrianMadden.com

rated by 0 users
Not Answered This post has 0 verified answers | 3 Replies | 2 Followers

Top 500 Contributor
Points 385
Ron Kuper posted on Thu, Feb 5 2009 11:10 PM

Hello,

Can the new Citrix Access Gateway Enterprise Edition 9.0 authenticate users to XenApp with smart cards (require client certificate)?

 If so, can it perform SSO to WI and XenApp with that authentication method?

Or would the users need to first authenticate to their smartcard (Pin/Bio/etc.) and then enter their domain username and password on a web form?

If the latter is true, than can the CAG at least map the client certificate to a specific domain user (UPN Mapping?) so that users won't be able to try and guess other users passwords after the smartcard authentication?

Is this an issue or have I got it all wrong?? :)

(If you use PKI and CAG EE 9.0 then how did you configured it?)

 

BTW The only document I found for that is this:

http://support.citrix.com/article/CTX116373

But it is applied to CAG EE 8.0. It also say some weird stuff like:

1. Set CAG client certificate to optional

2. Set ICA Proxy to OFF (huh?!)

3. Set WI access and dmz to direct. (huh?!)

4. Set WI authentication to Pass-through with smart card (Isn't that only work with the full PN Client??)

5. Set IIS to require and map client certificate.

I'm confused. Can anyone see a logic here??

 

Thanks for your comments,

Ron Kuper

 

  • | Post Points: 20

All Replies

Top 500 Contributor
Points 385

Thanks.


I already got the answer for, at least, one question.


When using client certificate authentication the AGEE can extract the username from a specified field in the certificate and then use that for the second authentication without allowing the user to change.
I think Jay Tomlin's 'Kerberos Authentication' using the WI in parallel and UPN Mapping to the AD is much more elegant, robust and secured.


I guess AGEE and co' still have some work to do for integrating XenApp authentication. (All the current NetScaler/Net6/CSG fusion is really confusing and rarely clear what it can or can't do)


 

  • | Post Points: 5
Not Ranked
Points 100
On the matter of mapping a user certificate to a domain user by the CAGEE the answer is "no". Authentication using the CAGEE is limited to checking if certain field within the offered client certificate are valid and checking an CRL (certificate revocation list). Yet the WI can use smartcards (being on an windows platform). Ultimate you could try letting the CAGEE check for certificate validity and CRL only and leave the actual authentication to the webinterface. If interpreted correctly this is what Citrix suggests in the workaround. From a security standpoint you would rather have authentication on the CAGEE before granting access to the WI. Placing the WI in a DMZ is allways a good idea. In this scenario I would strongly advise it.
  • | Post Points: 5
Page 1 of 1 (3 items) | RSS