This message was deleted.
# citrix-netscaler
s
This message was deleted.
c
If you can configure Gateway to not send the user's password to StoreFront then you can enable "Fully delegate credentials" in StoreFront and don't enable FAS. The VDA won't have the user's password at that point.
a
Ok, great thanks Carl. Not sending the users password to Storefront, is this something done by adjusting session policies?
c
I'm thinking of a Traffic Policy that uses a fake Password field.
a
Ok, great, I’ll give it a go. To put the request into context, security teams where I’m working don’t permit the use of ICA files that could be hijacked despite their very short life, if credentials are passed all the way thru. Prompting at the guest OS forces a subsequent auth even if the ICA is compromised (excessive I know)
However, internally, there is no issue and they’re happy with pass thru - hence the need for a split scenario!
r
Interestingly, Im fighting the opposite with a customer. Passthrough works for all of their desktops, except one persistent Delivery Group of machines which is prompting for login after launching.
a
Hey Carl, I tried another option by configuring Storefront receiver for web and removing pass thru from netscaler gateway which at least got me through initial auth externally to then re-auth against the storefront, however I then get “your logon has expired...” so I guess this just won’t work even though that’s pretty much the desired end state. As for traffic policies, I created a new one with SSO disabled, but I get an error “cannot process your request”, again I imagine because storefront identified that the request originated from a Netscaler, but the expression it is receiving is unexpected. Do you know what the expression would need to be to meet what Storefront is expecting to at least display the subsequent authentication prompt screen?
d
Andrew, would the RDP policy "always prompt for password upon connection" help here? I don't know if it kicks in for an ICA connection as well as RDP
a
Hi Daniel, no, I tried that, but the connection responds to the settings under published applications rather than RDP policy. I’ve considered whether modifying the default.ica is a possibility on the storefront directly but I’ve not had any joy. Would modifying direct.ica work to drop the SSO?