This message was deleted.
# citrix-netscaler
s
This message was deleted.
đź‘€ 1
j
Thanks Arthur, you're having practical experiences with enabling logon encryption? I had two customers with very strange AAA issues (timeouts / no sso / nfactor schema issues) and all was related to logon encryption. Disabled logon encryption and everything was working fine. Citrix Case is open until today for about three months now...
j
What build are you on Julian?
a
There is dependency on web browsers. It should work fine on most popular web browsers (Chrome, Edge, Firefox). Web browsers need to be updated - on very old builds it will not work at all - displaying error message about encryption. Unfortunately it’s incorrect message for users - already reported to Citrix and they will change it in near future. On some “strange” web browsers.. not sure if it will work correctly 🤷🏻‍♂️
j
Exactly, thanks for your informations Arthur. This is the closed message of our case within the statement from the engienering: "As discussed, encryption feature is instructing (using Java Script) to user browser to use available algorithm on user computer to encrypt the credentials sent by user. NetScaler use reverse algorithm to decrypt the data. In successful authentication scenario, the browser generates a unique encrypted string which contains username, password, timestamp information. In most cases, timestamp always ends with numbers. However, in some random algorithm the string continues with random character instead of ending with number of timestamp; which causes failure in authentication as NetScaler finds invalid character/s on string. Due to this behavior this is considered as an enhancement, which would require Java Script to be tuned, need to understand which algorithm would cause this from user machine, appending new algorithm to NetScaler and tune NetScaler to avoid random characters. As of now, we do not have any ETA for this enhancement but you can use "NSHELP-28507" as a reference and check with your sales account manager for the progress."
👍 2
a
What did I do before implementation? I verified what browsers users were connecting from. the verification covered over 20,000 connections. What I was looking for? • Outdated web browsers • “Strange” / Non standard web browsers • Outdated CWA clients (In theory all CWA clients support logon encryption Did you get chance to investigate affected endpoints ? It’s good to understand what’s wrong on user endpoints..