With the release of Citrix ADC 13.0 build 64.35, Citrix have made some change to the “Single Sign-on to Web Application” in the Session Profiles:
data:image/s3,"s3://crabby-images/45017/45017ea92b5ce1194f9900e577d169a84b16c178" alt=""
This is new and can affect the SSO to Citrix Storefront. In my test environment after upgrading to 13.0 build 64.35 I got this error when logging in to the Access Gateway:
data:image/s3,"s3://crabby-images/05eb0/05eb0ae9f6c877fd5afdea2945c6843c31f31a5d" alt=""
There were no errors in the event viewer of the Storefront Server to help me.
In the release note for ADC 13.0 build 64.35 Citrix state, the flowing:
Title: Support to disable the weak Basic, Digest, and NTLM authentication globally
The SSO configuration is now made more secure by dishonoring the following weak authentication methods globally.
– Basic authentication
– Digest Access Authentication
– NTLM without setting Negotiate NTLM2 Key or Negotiate Sign
[ NSAUTH-7747 ]
I got my test environment to work with a simple traffic profile and traffic policy.
Traffic profile:
data:image/s3,"s3://crabby-images/1ca91/1ca9150d3f6252daebbe1645a63617dd27d6de6b" alt=""
Traffic policy:
data:image/s3,"s3://crabby-images/61757/6175794fdf6501f9fbcce6ac7b8d73b23cb51772" alt=""
Just bind the policy to the Access Gateway, and you will not get the Storefront error, 😊
CLI commands:
add vpn trafficAction traf_prof_sf_sso http -SSO ON
add vpn trafficPolicy traf_pol_sf_sso true traf_prof_sf_sso
bind vpn vserver <NAME> -policy traf_pol_sf_sso -priority 100 -gotoPriorityExpression END -type REQUEST