This message was deleted.
# citrix-netscaler
s
This message was deleted.
d
What's your logout URL configured to in the AAD app?
d
thanks for the reply @Daniel Marsh. It's https://login.microsoftonline.com/GUID/saml2 which I dont think is correct 🤔
d
No - it should be https://<gatewayfqdn>/cgi/logout
d
thanks will give that a go
hmm damn, still getting it
that look correct? 🤔
fixed it, was a config issue on netscaler side. Didn't have the right signing cert and issuer name set in the saml policy
👍 1
m
Citrix says it should be https://<gatewayfqdn>/cgi/logout but Microsoft say it should be https://login.microsoftonline.com/GUID/saml2, so which is it? I’ve only managed to get it working with the MS url
and there’s other citrix docs that say it should be https://saml.cloud.com/saml/logout/callback
if using citrix cloud
d
https://<gatewayfqdn>/cgi/logout seemed to work for us, not using citrix cloud
d
Mike when you hit /cgi/logout it kills your logged in session on the NetScaler (NSC_AAAC cookie), then redirects to the logout URL specified in your SAML profile to kill the SAML session as well.
🙌 1
m
does cgi/logout work for gateway service too?
d
When you configure Cloud for Azure AD it automatically sets up the apps in AAD with OID & OAuth and there's no SAML settings to define - so I'm not sure how it works behind the scenes. The Citrix docs don't go into any detail about how it's configured unfortunately.
m
That's what I've found too, I'm also asking the product team
👍 1
d
Let me know what you find out!