This message was deleted.
# citrix-netscaler
s
This message was deleted.
j
The top image being the Azure AD/SAML (New), the bottom being the old/traditional, cheers
Has anyone used this to redirect back to the sign-in page?
I havent got access to test at the moment but wondering if this should be updated with the Citrix gateway address or the login.ms url in the entapp, cheers
k
I did configure the Azure Ent app logout url as the https://{gw-fqdn}/cgi/logout ... but the redirect contained additional stuff
I grabbed that with a responder policy that just redirects all requests to the /cgi/logout ... that invalidates the auth cookie for user session
j
Thanks @Kari Ruissalo (WyW). So when SF times out and it logs the user out what page do the land on? Is it the GW or the AzureAD logon page? The customer is trying to minimise user clicks/effort, which I get, cheers
k
what's the URL when they are timed out?
I would check the session settings on Gateway Session Profile and make sure the timeout on GW is equal or shorter than with StoreFront
because you want the timeout to happen on Gateway, not on SF
j
@Kari Ruissalo (WyW) its the login.ms url generated by the saml enterprise app. When it times out the land here:
I'll double check the timeout settings but the store and session policy/profiles are the same as prod targeting the new Store. Ideally when it times out they are redirected to a login prompt vrs having to re-enter the GW URL, cheers
Just confirmed the session profile timeout on the Netscaler, its set for 20 mins and this matches the SF timeout, cheers
@Kari Ruissalo (WyW) - Ive added the https://{gw-fqdn}/cgi/logout to the saml EntApp, with SF and the GW set to match at 20 mins the new behaviour is that the session refreshes and auto logs in/land on SF when the 20 min timeout is reached. Better user XP of course but bit of a security issue. Any ideas? I might test the GW timeout a little lower than the 20 min SF timeout, cheers
k
Can't remember by heart, but have you set the logout endpoint in NetScaler?
j
Thanks mate - yeah, that in place and looks something like:
k
If you check the metadata from AAD (the xml), it supports redirect for slo?
j
Yeah that looks ok, I'll try lower the GW timeout to see what results I get, cheers
@Kari Ruissalo (WyW) Its looking much better now mate. Increased the SF timeout to 25 mins. I now get this when the time out (or manual logoff)
If I click login Im redirected to the Azure AD/saml auth page 🙂
k
Yeah, great. It's better the Gateway session expires before SF session. That way the session authentication is timed out in proper place
🍻 1
j
Nice one - thanks for the help and collab man 🙂