This article describes how to integrate RSA SecurID Access with Citrix NetScaler using SAML Relying Party.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as a Relying Party to Citrix NetScaler.
Procedure
- Sign in to RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the My Relying Parties page, click Add a Relying Party.
- On the Relying Party Catalog page, click Add for Service Provider SAML.
- On the Basic Information page, enter a Name for the Service Provider.
- Click Next Step.
- On the Authentication page, choose SecurID Access manages all authentication.
- In the 2.0 Access Policy for Authentication drop-down list, select a policy that was previously configured.
- Click Next Step.
- On the Connection Profile page, choose Enter Manually.
- Scroll down to the Service Provider section and enter the following details:
- ACS URL: The format is https://<ns_vs_hostname>/cgi/samlauth. Replace <ns_vs_hostname> with the hostname or IP address of your NetScaler virtual server, which can be obtained from the Citrix NetScaler configuration.
- Service Provider Entity ID: The format is <ns_vs_hostname>, where <ns_vs_hostname> represents the hostname or IP address of your NetScaler virtual server, which can be retrieved from the Citrix NetScaler configuration.
- Scroll down to the Message Protection section and choose IdP signs entire SAML response.
- Click Download Certificate to download the IDP signing certificate. Make a note of the certificate as it is required for the Citrix NetScaler configuration.
- Configure User Identity for NameID mapping.
- Identifier Type – Auto Detect
- Property – Auto Detect
- Scroll down to the Identity Provider section. Make a note of the Entity ID field value as it is needed in the Citrix NetScaler configuration.
- Click Save and Finish.
- Click Publish Changes and wait for the operation to be completed.
Your application is now enabled for SSO.
Configure Citrix NetScaler
Perform these steps to configure Citrix NetScaler.
Procedure
- Log on to the Citrix NetScaler Gateway web administration console.
- Browse to Configuration > NetScaler Gateway > Policies > Authentication > SAML and click Add.
- Enter a name for the SAML Authentication Policy and click Add next to the Server drop-down menu.
- Configure the SAML Authentication Server settings and click Create.
- Enter a Name for the Authentication SAML Server.
- In the Redirect URL field, enter the Identity Provider URL that was provided in the RSA Cloud Authentication Service configuration.
- In the IDP Certificate Name drop-down list, select the public certificate provided in the RSA Cloud Authentication Service configuration. If you have not added the certificate yet, refer to the steps in the Notes section to add it.
- Type mail in User Field.
- On the SAML Authentication Policy page, type ns_true in the Expression field and click Create.
- Navigate to Configuration > NetScaler Gateway > Virtual Servers.
-
Take note of the Name and IP Address of the NetScaler Virtual Server. These are needed for the RSA Cloud Authentication Service configuration.
-
Click to edit the NetScaler Gateway Virtual Server.
-
Click + to bind a Basic Authentication policy.
-
Select SAML Policy and Primary Type and click Continue.
-
Click > icon to select the policy.
-
Select the authentication policy that was configured earlier to bind it and click Select.
-
Set the Priority and click Bind.
-
Click Done.
The configuration is complete.
Notes
In the NetScaler Gateway web administration console, you may not have a NetScaler virtual server initially. In this case, you will need to create your virtual server, assign it a preferred name, and assign an IP address.
You can configure as many virtual servers as necessary, but ensure that the state of the virtual server is set to UP for proper functionality.
If you need to add a public certificate, follow these steps:
- Navigate to Traffic Management > SSL > Certificates.
- Click Install.
- Enter a name for the certificate-key pair.
- Click Choose File next to the certificate file name field. A file browser appears, allowing you to select and upload your certificate file. The public certificate file should be of the .cert type.
- Select the file and click Open to confirm.
- If you have a private key, repeat the same steps for the private key file. This field is optional and hence you may not have a private key to upload.
- Set the Certificate Format to PEM.
- Click Install.
Your certificate is added and available for future use.
Return to Citrix NetScaler - RSA Ready Implementation Guide.
Related Articles
Citrix ShareFile - RSA Ready Implementation Guide 13Number of Views Citrix Cloud - RSA Ready Implementation Guide 26Number of Views Citrix NetScaler - SAML IDR SSO Configuration - RSA Ready Implementation Guide 7Number of Views Citrix NetScaler - SAML My Page SSO Configuration - RSA Ready Implementation Guide 5Number of Views Citrix NetScaler - RSA Ready Implementation Guide 27Number of Views
Trending Articles
RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Release Notes: Cloud Access Service and RSA Authenticators RSA Release Notes for RSA Authentication Manager 8.8 RSA-2026-04: RSA Governance and Lifecycle Security Update for SUSE Linux Enterprise Server Vulnerabilities