This message was deleted.
# citrix-netscaler
s
This message was deleted.
m
Where is the prompting happening? Within the web browser or on the VDA?
s
VDA
s
if you just hit storefront in DR, does the VDA still prompt? Everything worked before the Netscaler upgrade?
s
Works fine when accessing DR Storefront server directly
m
Was there ever a FAS Implementation. maybe the Storefront has the Setting "Delegate Authentication to Citrix Gateway" in place? Is there a event log in Application or System log? Or maybe in the security log of the vda a failed security audit?
c
Users being prompted for creds when logging into the VDA is normally FAS related but if you are using LDAP+RAdius you wont be using SAML auth and need Citrix FAS so cant be that. There was a RDS setting "always prompt for password" that used to cause some issues with SSO to VDA's maybe worth checking that
s
If it is RDS setting then it should prompt with old NetScaler firmware too, not just latest build
c
Computer Configuration > Administrative Templates > Windows Components > Remote Desktop Services > Remote Desktop Session Host > Security. "Always prompt for password upon connection"
it same VDA's ? same OU/polices ?
s
Yes, everything same except the NetScalers hosting Gateway.
m
even the storefront is the same in the backend? then forget the asking about FAS. Maybe just a traffic Policy with SSO set to "on" on the vpn vserver?
m
This sounds like FAS, but if there is no FAS and StoreFront configs were not changed, check to see what session policy you’re hitting on the NetScaler. I know “REQ.HTTP.HEADER Referer EXISTS” no longer works after 12.1 and maybe you’re hitting some unexpected policy.
s
@Marion - Isn’t traffic policy responsible for NetScaler Gateway passthrough authentication when nFactor is used (Gateway to StoreFront SSO)?
We have a traffic policy with user attributes passed on for SSO, as I mentioned Gateway passthrough authentication is working fine and also app enumeration. Issue is only with VDA SSO?
b
So I would focus on the session policy that the non-workspace app endpoints are triggering. Look at the sso to windows settings within the domain field and ensure they are correct with the domain and matching storefronts. using the nsconmsg -d current -g _hits at shell Any event logs in the storefront that help identify?
s
No events on the StoreFront server. But we made progress in identifying the issue. We are using AAA auth profile with LDAP, RADIUS and EULA as the factors. We created a test AAA auth profile and tested the following. 1. LDAP only - VDA SSO worked 2. LDAP and RADIUS - VDA SSO worked 3. LDAP and EULA - VDA SSO failed 4. LDAP, RADIUS and EULA - VDA SSO failed We are having issue only with EULA as one of the factor on the latest firmware, same EULA works fine on older firmware.
b
Interesting. Can you use EULA from a theme instead of as a factor? Or is there a possible way to make the EULA as a NOAUTH factor
s
We have EULA configured as NO_AUTHN auth policy
m
13.1-42.47 just dropped. I too use your firmware and nFactor LDAP+RADIUS, but no EULA. I haven't seen the problem. I'm checking over the release notes to see if the issue's I'm having is resolved. https://docs.citrix.com/en-us/citrix-adc/current-release/citrix-adc-release-notes/release-notes-13-1-42-47.html#fixed-issues
s
Another bug with 37.38
SSL files is empty. None of buttons are working, can’t create new key file or CSR.
m
NetScaler firmware releases and GUI bugs go together like peas and carrots.
s
Resolved - EULA Login Schema on DR NetScalers had SSO checked under advanced settings. After I checking that, VDA SSO started working.