This message was deleted.
# citrix-netscaler
s
This message was deleted.
I hope this helps you
j
Thanks, Salim. I did see that one and skimmed it... the opening paragraph through me as it links to generic SAML which isnt specific to ADC.. I'll give it another read, thanks! 🙂
👍 1
c
Duo has some excellent first-party docs for netscaler integration, even options for nFactor. Highly recommend making sure you're looking at their KB for ADC/NS/Gateway instructions.
j
Thanks, Mike - having a dig now.. I was surprised to see this note:
The goal here is to use SAML with ADC/DUO to access the Universal Prompt feature.. I think this means we dont have to worry about on-prem DUO proxies...
The part that has me confused is how can DUO work as the iDP with no DUO AD proxy... digging through docs now 🙂
s
Documenting wise i would say RSA is very nice and easy
j
My task at hand is to transition an existing ADC/DUO deployment from using RADIUS to SAML, cheers
s
Ohh Okay
👍 1
o
I did do this yea, but been a minute - I remember having to do the custom CIP... mappings as they dictate in there for SAML 2.0 but other than that, i don't remember any other issues getting it to work
also tested going from the DUO portal first as the starting point (IdP initiatied flow) and that worked similar to myapps (azure) or Oktas landing portal for apps.
j
Nice one - thanks, Scott 🙂
@Oz Zy so just to confirm.. Azure AD wasnt in the mix... DUO was the iDP, yeah?
My lack of DUO xp is getting me here.. with Azure AD as iDP the accounts are synced from AD Connect.. Im trying to workout how DOU knows about the accounts and where they get synced from if there is no onprem proxy for AD, ta
o
yea, DUO in my case I have the 'authentication proxy' doing a sync. Just checked it and appears i need to upgrade to get new features. ha. But yea, I have the auth proxy piece connected and syncing what i need
so yea, on prem proxy similar to Azure AD connect
j
Nice one, Scott.. that makes sense... So I'm still using DUO SSO hosted cloud service which provides universal prompt and thats where the SAML request goes... the user identity is sync'd from good old traditional on prem AD using DUO sync upto DUO cloud..
So I dont need to even bring Azure AD into the mix.. this is much clearer now.. virtual beer on the way 😉
That also solves this potential blocker:
o
lol. i wish the vBeers tasted near as good as the physical ones. hahaha
😛 2