This message was deleted.
# citrix-netscaler
s
This message was deleted.
l
As long as they aren't using it, it'll be fine.
j
You know what's coming next don't you - it's that kind of customer - how would they know they aren't using it? Is there something I can check to verify that?
c
if they using an IDP such as Azure AD /OKTA ect they will be using SAML so potentially breaking auth. If they just use standard ldap auth they not impacted by it
👍 1
l
You'll need to check for authentication policies on the ADC to see what points where. Should be fairly straight forward.
👍 1
r
You should be able to check the AAA/Vserver policies. This link will get you to the right spots. Ignore the troubleshooting part.
👍 1
j
Damn, now I'm going to have to log into the damned thing
l
Or request the config file
💡 1
c
easiest method is check the GW Vserver and look at the basic auth (primary/Secondary auth) if there is nothing bound and it has a authentication profile set you will need to look at the AAA auth profile / Vserver and check the setup might be a advanced auth policy bound on the AAA vserver or could be using Nfactor and your would have to look at the Nfactor visualizer
👍🏻 1
yeah as Leee mentioned getting the ns.conf and looking for add authentication samlAction would be easier
j
I've asked one of the people with access to export the config file and have a look (it's the kind of client that can't send it to me without a full genetic scan first) - cheers all
c
or can grep it out cat /flash/nsconfig/ns.conf | grep samlaction -i
✔️ 1
j
That might make their head explode
😂 1
l
Option 2, screen share once they have the running config in notepad and find SAML lol if not found it's not being used. These types of clients always make me laugh. Belt and braces about config files etc... But they probably have the same local admin account on all servers.
j
Lord God, you think I can do a screen share?! That would involve me probably being arrested
😂 1
But yes, probably right on the admin account
r
Sounds like you have some super strict rules you have to get through.
j
Yeah, but those rules don't extend to support and therefore, patches
So they don't appear to be using it (which is good) - how do you actually disable it?
c
disable the Netscaler acting as a saml idp/sp ? you would need to remove any saml advanced auth polices and switch to a different kind of authentication
if you checked the ns.conf and dont see add authentication samlAction they wont be using SAML auth so the vulnerability wont apply to it
j
So if they're not in ns.conf, no action required?
💯 1
c
yup
r
Correct
John and Leee are NetScaler masters.
j
Thanks all
👍 1