This message was deleted.
# citrix-netscaler
s
This message was deleted.
j
You can choose the duration of the client secret. When refreshing if you’re having token error, that’s just a GUI thing. As soon as your NetScaler is able to reach the AAD token endpoint, it will not rotate. See some details here, hope it helps https://www.julianjakob.com/citrix-netscaler-oauth-to-azure-ad-with-login_hint-subject-field/
m
Thanks Julian - I did pull up your article the other day. We are getting an “Error trying to validate Access Token” message when we go to the OAuth VIP and after authenticating to AAD (successfully). There is no error in the NetScaler GUI, all looks well. I spoke to Citrix and they wanted to know what the Client Secret was and I told them it’s constantly rotating. They then said “We’ve never seen that behavior before, that is wrong and is causing your issue”. But we have a build exactly same as this, in a lab, going to a different AAD Enterprise App & Web Server and it is working, and does the same. So I knew that assessment by them was likely wrong.
In ns.log: “OAUTH RESP: ns_aaa_oauth_resp_handler, response code 401 is not 200 OK, bailing out ” Also “AAATM Error Handler: Found extended error code 1310727, ReqType 16386 request /oauth/login?code=0.ARw….
Pretty much identical NS config in lab works fine (with different AAD/EA + IIS server) so seems to be something possibly with AAD Domain or EA settings perhaps?
Been a real butt kicker
I just saw the nuance in your original note “As soon as your NetScaler is able to reach the AAD token endpoint, it will not rotate.“. Hmm. I can confirm NS can contact login.microsoftonline.com. What else would it need access to to make this stop rotating and confirm a lock, so to speak?
k
I've never seen NS rotating the actual value... I think the secret is static. However the value you see in GUI or CLI is encrypted jibberish, no the actual value. Also, what's the status of your OAuth action? That should give you some info whether NS is able to connect to the IdP.