Citrix Cloud - SAML Relying Party Configuration - RSA Ready Implementation Guide
Originally Published: 2023-03-21
This article describes how to integrate RSA with Citrix Cloud using SAML Relying Party.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as a Relying Party to Citrix Cloud
Procedure
- Sign in to RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the My Relying Parties page, click Add a Relying Party.
- On the Relying Party Catalog page, click Add for Service Provider SAML.
- On the Basic Information page, enter a name for the Service Provider in the Name field.
- Click Next Step.
- On the Authentication page, choose SecurID Access manages all authentication.
- In the 2.0 Access Policy for Authentication drop-down list, select a policy that was previously configured and click Next Step.
- On the Connection Profile page, for Data Input Method, select Import Metadata.
- Click Choose File to browse and select the Citrix Cloud SAML metadata file.
This metadata file can be obtained from the Citrix Cloud console > SAML configuration page as mentioned in the Configure Citrix Cloud section. - On the Connection Profile page, select Enter Manually.
- Scroll down to the Service Provider section and enter the following details:
- Import the metadata and verify that the ACS URL and Service Provider Entity ID are filled correctly.
This metadata file can be obtained from the Citrix Cloud console.
- Import the metadata and verify that the ACS URL and Service Provider Entity ID are filled correctly.
- For Audience for SAML Response, proceed with the Default: Service Provider Entity ID option.
- For SAML Response Protection, choose IdP signs entire SAML response.
- Click Download Certificate and save the certificate.
This certificate is required for SAML configuration in Citrix Cloud. - Scroll down to the User Identity section and select the following:
- Identifier Type: emailAddress
- Property: mail
- In the Statement Attributes section, enter the following attribute names and property values:
- Attribute Name: cip_email, Attribute Source: Identity Source, Property: mail
- Attribute Name: cip_oid, Attribute Source: Identity Source, Property: objectGUID
- Attribute Name: cip_sid, Attribute Source: Identity Source, Property: objectSid
- Attribute Name: cip_upn, Attribute Source: Identity Source, Property: userPrincipalName
- Scroll down to the Message Protection section and choose IdP signs entire SAML response.
- Click Save and Finish.
- Locate the application you created on the Relying Parties page and click Edit > Metadata > Download Metadata File.
- Click Publish Changes and wait for the operation to be completed.
After publishing, your application is now enabled for SSO.
Configure Citrix Cloud SSO
Perform these steps to integrate Citrix Cloud with RSA uisng Relying Party.
Procedure
- Sign in to Citrix Cloud at https://citrix.cloud.com.
- On the Citrix Cloud menu, click Identity and Access Management.
- On the Authentication tab, for SAML 2.0, select Connect. When prompted, enter a short, URL-friendly, identifier for your company and click Save and continue.
- On the Configure SAML page, enter the following:
- Entity ID: Enter the Identity Provider Entity ID from the metadata file downloaded from RSA Cloud Authentication Service.
- SSO Service Provider: Enter the SingleSignOnService URL from the metadata file.
- Binding Mechanism: Select HTTP POST.
- SAML Response: Select Must Sign Response.
- X.509 Certificate: Upload SecurID X.509 certificate downloaded in the previous section.
- Authentication Context: Set Authentication Context as Unspecified, Minimum.
- Logout URL: If required, specify the RSA Portal URL obtained in the previous section to redirect users to the application portal page on logout.
- Download the SAML Metadata file.
- Click Test and Finish.
- Perform the following steps to configure the Workspace Authentication method:
- On the Citrix Cloud menu, click Workspace Configuration.
- Click the Authentication tab and choose SAML 2.0.
- On the Citrix Cloud menu, click Workspace Configuration.
The configuration is complete.
Related Articles
Palo Alto NGFW Global Protect - SAML Relying Party Configuration - RSA Ready Implementation Guide 110Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 230Number of Views Microsoft Entra ID - SAML Relying Party Configuration - RSA Ready Implementation Guide 85Number of Views Workday - SAML Relying Party Configuration - RSA Ready Implementation Guide 4Number of Views Microsoft Entra ID External Authentication Methods (EAM) - Relying Party Configuration Using OIDC - RSA Ready Implementati… 499Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide How to recover the Application and AFX after an unexpected database failure in RSA Identity Governance & Lifecycle RSA Authentication Manager Upgrade Process Troubleshooting AFX Connector issues in RSA Identity Governance & Lifecycle Provisioning-Termination Rule fails to filter on Custom Attributes that have the same Display Names across Multiple Object…
Don't see what you're looking for?