cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
200
Views
0
Helpful
4
Replies

Citrix OAuth DUO Universal prompt

thili
Level 1
Level 1

I have set up duo universal prompt with duo guide. https://duo.com/docs/netscaler-web

Everything works nicely with the Webbrowser also the SSO. 

Now with Citrix Workspaceapp the authentication seems to work i get the DUO Push but then another old looking Login Prompt comes up with doman\username??

Even when i put the credentials there again it doesnt work. 
on the netscaler I get the following

Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8412 0 :  "Login request is not expected to be encrypted"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8413 0 :  "AAA LOGIN : X509 cert not found "
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8414 0 :  "AAAD API: sending login req to aaad for <demotest>, factor <duo_oauth_server>, auth type 4129, trans id 18152"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8415 0 :  "(0-69) send_authenticate_pdu: Sending Preamble"
Nov 21 12:14:32 <local0.notice> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8416 0 :  "SSLVPN aaad login : (0-69):  Reply Received, status from aaad: 2, aaad flags 81"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAATM Message 8417 0 :  "AAAD RESP: received resp, user: <demotest>, factor: <duo_oauth_server>, trans id 18152, pcb trans id 18152, q_flags 1879080960 aaad-resp 2 aaad-flags 81"
Nov 21 12:14:32 <local0.warn> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8418 0 :  "Created nFactor session for user demotest"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8419 0 :  "AAAD API: sending login req to aaad for <demotest>, factor <duo_factor>, auth type 4161, trans id 18152"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8420 0 :  "(0-69) send_authenticate_pdu: Sending Preamble"
Nov 21 12:14:32 <local0.notice> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8421 0 :  "SSLVPN aaad login : (0-69):  Reply Received, status from aaad: 12, aaad flags 0"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAATM Message 8422 0 :  "AAAD RESP: received resp, user: <demotest>, factor: <duo_factor>, trans id 18152, pcb trans id 18152, q_flags 1879080960 aaad-resp 12 aaad-flags 0"
Nov 21 12:14:32 <local0.info> ADC-IP  11/21/2024:11:14:32 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8423 0 :  "nFactor: serialized aainfo ctx_hint%3D0ZWaaWU8NSzFkO3Gi8QVVg%26SPpJbgfgm9c2yvDJhXoSq0zvXxUUiZ7cbtZik1vE4QVwWp4KDE9HzujE01Alf-JgmGfVDnh6p45fk5Naf0ocXPrEp8YxJvFrRImQPqT5ratCXAKB9v0t8hZaLGySFGxMlpBUKlNSw7lDCm5DN8mXHOm0Nzp7VMvNllX5KvndGBJcZrjkx0KOYWdjfYJgeLDj5O6Y9A8jyv01v2YE12YXNWQlBzRKgL2rKEwRotTFBZCNrjla_g "
Nov 21 12:14:33 <local0.info> ADC-IP  11/21/2024:11:14:33 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8424 0 :  "OAuth nFactor: context found in the url"
Nov 21 12:14:33 <local0.info> ADC-IP  11/21/2024:11:14:33 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8425 0 :  "OAuth nFactor: Derserializing context "
Nov 21 12:14:33 <local0.info> ADC-IP  11/21/2024:11:14:33 GMT Citrix-ADC 0-PPE-0 : default AAA Message 8426 0 :  "nFactor: deserialize aaa_info, action name copied to samlaction is [duo_oauth_server]"
 [duo_oauth_server]"
Nov 21 12:14:48 <local0.info> ADC-IP  11/21/2024:11:14:48 GMT Citrix-ADC 0-PPE-0 : default AAATM Message 8436 0 :  "OAUTH RP: idtoken length 1536, access token length 32, certendpoint len 0, conf-keys len 0"
Nov 21 12:14:48 <local0.info> ADC-IP  11/21/2024:11:14:48 GMT Citrix-ADC 0-PPE-0 : default AAATM Message 8437 0 :  "OAUTH RP: Successfully verified incoming token/code, username: <Anonymous>, client ip 0xfe070e2e"
Nov 21 12:14:48 <local0.info> ADC-IP  11/21/2024:11:14:48 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8438 0 :  "get_session user: <demotest>, sessionto: 30000, aaa_info flags 85 flags2 41000, new webview 1, sess flags2 20, flags3 0 flags4 400 ssoDomain <>, ssoUsername: <demotest>, ssoUsername2: <demotest>"
Nov 21 12:14:48 <local0.info> ADC-IP  11/21/2024:11:14:48 GMT Citrix-ADC 0-PPE-0 : default SSLVPN Message 8439 0 :  "WebView is complete; sending completion response; suspending session policy eval for user <demotest>, aaa flags 85, flags2 41000"
Nov 21 12:14:48 <local0.info> ADC-IP  11/21/2024:11:14:48 GMT Citrix-ADC 0-PPE-0 : default AAATM LOGOUT 8440 0 :  User demotest - Client_ip 46.14.7.254 - Nat_ip "Mapped Ip" - Vserver 10.10.10.19:443 - Start_time "11/21/2024:11:14:32 GMT" - End_time "11/21/2024:11:14:48 GMT" - Duration 00:00:16  - Http_resources_accessed 0 - Total_TCP_connections 0 - Total_policies_allowed 0 - Total_policies_denied 0 - Total_bytes_send 0 - Total_bytes_recv 0 - Total_compressedbytes_send 0 - Total_compressedbytes_recv 0 - Compression_ratio_send 0.00% - Compression_ratio_recv 0.00% - LogoutMethod "InternalError" - Group(s) "N/A"

 

4 Replies 4

DuoKristina
Cisco Employee
Cisco Employee

Can you share a screenshot of what you're talking about?

To clarify, you tried entering your AD username as YOURADDOMAINNAME\yourusername and password in the second screen?

Do you have StoreFront behind this NetScaler?

Duo, not DUO.

sure, at first I get the oAuth login prompt and also with duo. after that the old login prompt comes again. And I dont come to the VDA Desktop. on Browser it works perfectly. 

1 first normal login.png2 duo prompt.png3 old login prompt.png

Do you have StoreFront behind this NetScaler?

If so, it sounds like a pass-through issue between NetScaler and StoreFront that we've heard of before. Please take a look at this KB article: https://help.duo.com/s/article/9044.  If the suggestions in that article don't help, I'd suggest you contact NetScaler support, as Duo does not pass any credentials directly to StoreFront.

Duo, not DUO.

yes there is a Storefont behind. I will check this out, Thanks.

 

Edit: I have checked everything its okey. Through Brwoser it works but just not through the Citrix Workspace App...

Quick Links