This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
I use nFactor for this... so in the SAML claim we check the User ID (which is often email), then in the next factor do an LDAP search (non-authenticating) for that UserID in mail attribute, then store for example userPrincipalName in NetScaler Attribute1 and apply a traffic policy on GW that injects the Attribute1 as the login name attribute
So if your user would be sth like email: chaitanya@public.com upn: chaitanya@private.local ... the StoreFront would get the latter one
c
storefront will still enumerate with upn id received from netscaler. isnt it?
k
if you do the traffic policy as described above
StoreFront store is enabled for FAS, then it grabs a cert from PKI for the chosen UID and uses the cert for sso
c
Is this possible in netscaler: At citrix gateway If user enters active directory userid, netscaler should authenticate at active directory. If user enters email id, netscaler should open ping credentials page and authenticate with ping.
k
yes... you'd need a single factor schema on the AAA vServer that only requires the username
then a next factor in a policy label that checks if the username contains "@" for instance
and if it does, then it redirects the user to chosen IdP
we've actually done that to a couple of customers
c
ok.. I will give it a try.
see if that would help you?
c
Sure thank you for that.
@Kari Ruissalo (WyW) Regarding my initial question on sending email id to storefront, as per this article, (https://c4rm0.wordpress.com/logon-to-netscaler-using-userprinciplename-instead-of-samaccountname/) we are sending userprincipalname back to storefront. Is it a simplified version of what I've posted earlier?
k
Done for today
c
🙂
This is how I've configured policies in AAA vServer
I've added "only username" login schema to AAA vserver. Added that AAA vserver to citrix gateway. When users open citrix gateway, netscaler will first show username page. When user enters userid or email, that LDAP policy will kick in as it has low priority, and it will check whether there is @ in user input (username text box). If there is no @, it will show password page (I've added "only password" login schema as NEXT Factor in AAA vserver). This is where user enters their AD password and logs in. If user enters email id, LDAP policy fails and it redirects to SAML page. I've configured ADFS in my environment. so in my case if user enters email it will open ADFS page but if I enter random usernames like sdf or aaa or bbb, it is redirecting to my ADFS page. It should say user not found etc, or at password page it should fail. But I m confused why it is redirecting to SAML ADFS page. There is no @ in my input. It is just aaa and bbb. Also, if I enter correct username and wrong password, it is logging in, but when showing apps it is showing cannot complete your request error. technically it should say wrong pwd. Is it because I've used "only password" login schema?
What is the best way to overcome this issue and configure it?