Forum Discussion

SamuelB's avatar
SamuelB
Icon for Nimbostratus rankNimbostratus
Nov 22, 2013

Two-factor authentication for Citrix Receiver for Windows

I have deployed F5 APM with two-factor authentication. APM is currently replacing the Web Interface / Storefront servers. Two-factor authentication is confirmed working for the Webtop, Citrix Receiver for Mac, Citrix Receiver for iOS and Citrix Receiver for Android. My issue is that Citrix Receiver for Windows doesn't appear to have the necessary options to select the Logon type of "Security token only" or "Domain and security token" like the Receiver for other OS's do. I suspect that Citrix Receiver for Windows requires some kind of configuration push from the server (which in my case is APM). Has anyone else experienced this issue or have any ideas?

 

  • Currently, Receiver does not support such behavior. It relies on the user having access to the token prior to starting the login attempt

     

  • Interesting point, Henrik - was not aware that mobile Receiver supports this type of iterative communication via Radius. It's a bit different with APM as it does its own built-in OTP - so we'd need to investigate exactly how the communication happens between Netscaler and Receiver to ensure that APM can something similar. I would suggest opening a case with support to have it escalated and investigated further.

     

  • Andrey_Terentye's avatar
    Andrey_Terentye
    Historic F5 Account

    The 11.6.0 HF5 functionality does not cover: 1. APM Webtop (StoreFront replacement) deployment 2. SMS/OTP authentication

     

    What 11.6.0 HF5 enables is ability to display logon dialog with two password fields (for token and AD password) for Windows Receiver client (other clients can be manually configured to display two fields).

     

    When Windows Receiver sees two-password dialog it assumes it is talking to StoreFront, hence limitation (1).

     

    The two-password dialog is not suitable for SMS/OTP case as token is not know to the user up front (as it is in classic RSA+AD case). With single-password dialog APM does not yet support SMS/OTP workflow for Receivers, hence limitation (2).

     

  • Hello, is this feature (With single-password dialog APM does not yet support SMS/OTP workflow for Receivers, hence limitation) available in some newest versions of F5?

     

    I'm currently building F5 configuration for Citrix Storefront and we need sms-auth for it. We have some portals with OTP exist and we would like to use OTP when user uses Citrix Receiver to connect Storefront via F5.

     

    • henning_mne's avatar
      henning_mne
      Icon for Nimbostratus rankNimbostratus
      I've just visited a customer asking the same question. They would like to use OTP/SMS in combination with Citrix Receiver to replace a Netscaler and SMS Passcode setup. I'm not able to trigger a new prompt asking for passcode/token only from the APM. I would really appreciate an update regarding such a feature.
    • J_Hord's avatar
      J_Hord
      Icon for Nimbostratus rankNimbostratus

      Any updated on this. I too have a customer wanting this integration. It acutally works in the sense that the RADIUS triggers and goes through it's Auth routine. However it appears to be impacting the credentials delivered to StoreFront and it's breaking authentication.

       

    • The-messenger's avatar
      The-messenger
      Icon for Cirrostratus rankCirrostratus

      Any update on this? I am also interested in this and as well, using a Radius server.

       

      I've implemented DUO security for 2 factor on the web side, works very well and DUO uses a Radius server. I need to implement 2 factor for the receiver as well.