How to increase chances for successfully implementing Risk Based Authentication on the RSA Authentication Agent for Citrix StoreFront
Originally Published: 2016-05-23
Article Number
Applies To
RSA Product/Service Type: Authentication Agent for Citrix StoreFront
RSA Version/Condition: 1.0, 1.5, 2.0
Issue
Notes:
- The Citrix RSA StoreFront Bridge or RSA bridge mentioned in the Citrix documentation on Configuration of Delegated Forms Authentication for RSA Adaptive Authentication on NetScaler Gateway is for RSA Adaptive Authentication (AA) and not for RSA Authentication Manager (AM). Authentication Manager uses something called the RBA Helper Application on the Citrix StoreFront in addition to the RSA Authentication Agent for Citrix StoreFront 1.0.
- As of Q2 2016, only Citrix StoreFront 3.0 is supported by RSA Authentication Manager. StoreFront 3.5 and 3.6 are not supported and probably will not work because the Delegated Forms Authentication (DFA) used in Citrix has changed.
Tasks
- Make sure the Citrix StoreFront and NetScaler gateways are working with password logon.
- Configure Citrix StoreFront for DFA and LDAP password.
- Install and successfully test the RSA Authentication Agent 1.0 for Citrix StoreFront. Get tokencode/passcode/fixed passcode logon working before attempting to get RBA to work. Use a fixed passcode if you do not have tokens.
- Configure the StoreFront to allow an RSA passcode authentication through DFA.
- Test StoreFront logon with the fixed passcode, which includes enabling DFA on the virtual server that publishes the StoreFront.
- Install the RBA Helper application on the StoreFront Windows Server, use the Citrix NetScaler 11 with DFA integration script.
Resolution
- Make sure Citrix StoreFront works through the NetScaler's gateways with AD or LDAP password logons.
- Confirm that Citrix Storefront works with DFA and with an AD or LDAP password.
- Review Citrix's product documentation on Delegated Forms Authentication.
- Once you have Citrix StoreFront working with LDAP passwords and DFA, you can install the RSA Authentication Agent for Citrix StoreFront.
- Complete two test authentications through the RSA Control Center to verify that you can communicate from the Citrix StoreFront to RSA and successfully create the node secret.
- Configure the StoreFront to allow an RSA passcode authentication through DFA.
- Follow Chapter 4 of the RSA Authentication Agent for Citrix® StoreFront 1.0 Installation and Administration Guide, Revision 1, "Configuring and Managing the Agent for Citrix StoreFront," to:
- Exclude specific network adapters from auto-registration, and
- Maintain the primary IP address of the agent.
- There should be no need to use the node secret load utility because test authentication should create the node secret.
- Follow the steps in Chapter 5 of the Installation and Administration Guide to enable Citrix Delegated Forms Authentication because DFA is a prerequisite for extending the RSA Authentication Agent for Citrix StoreFront to authenticate users with either RSA SecurID or RBA. Chap. 5 p.39 includes:
- Enabling DFA and configuring it to use RSA SecurID.
- Given that the online Citrix docs include obsolete – and potentially misleading – references to the AA RSA RBA solution, we recommend following the instructions in the .rtf installed on StoreFront to enable DFA. This is described in the second half of step 2 on page 42: “Citrix provides similar information in a document installed on Citrix StoreFront servers. See <ProgramFiles>\Citrix\Receiver StoreFront\Management\Cmdlet\DFAServerFPReadMe.rtf.
- Follow Chapter 4 of the RSA Authentication Agent for Citrix® StoreFront 1.0 Installation and Administration Guide, Revision 1, "Configuring and Managing the Agent for Citrix StoreFront," to:
- Configure DFA to use RSA SecurID authentication by using the PowerShell command (also described on page 42 ("Set-DSDFAProperty -ConversationFactory“SecurIDAuthentication”).
- Use the StoreFront MMC to enable Passthrough from the NetScaler on the published store.
- The last step for just the passcode logon is to Enable DFA on the virtual server that publishes StoreFront, Add a DFA authentication policy and configure the action of the policy with the details of the StoreFront server set when enabling DFA (the ClientID and the passphrase). At this point, authentication to the StoreFront with an RSA SecurID passcode through the virtual server URL should be successful.
- Next, add RBA by installing the RBA helper application and downloading the redirect script for the RBA agent. Be sure to choose Citrix NetScaler 11 with DFA not Citrix NetScaler 10.
- Also try clearing the domain passthrough if you are browsing the website URL from inside the network, but not getting prompted for an RSA passcode
Notes
If you need to email any .htm or .js files such as the integration script, you might need to rename the .js or .html extensions to .txt then zip them before you attach them to an email, so that the mail filters do not strip them out
Related Articles
How to increase the chances of successfully configuring Citrix Delegated Forms Authentication (DFA) with the RSA Authentic… 155Number of Views Increase timeout for RSA Authentication Agent for Web for IIS implemented for OWA 155Number of Views Implementing Risk-Based Authentication 28Number of Views Partial Failure - Changes are not published successfully on the Identity Router (IDR) but successfully published on the Cl… 28Number of Views Increase the Maximum Length of the Logon Alias 16Number of Views
Trending Articles
RSA Release Notes for RSA Authentication Manager 8.8 RSA MFA Agent 2.3.6 for Microsoft Windows Installation and Administration Guide RSA MFA Agent 2.4 for Microsoft Windows Installation and Administration Guide Downloading RSA Authentication Manager license files or RSA Software token seed records RSA MFA Agent 2.4.3 for Microsoft Windows Group Policy Object Template Guide
Don't see what you're looking for?