Integration Guide. SafeNet Authentication Service. Strong Authentication for Citrix Web Interface 4.6

Similar documents
Integration Guide. SafeNet Authentication Service. Protecting Microsoft Internet Security and Acceleration (ISA) Server 2006 with SAS

Integration Guide. SafeNet Authentication Service. Strong Authentication for Juniper Networks SSL VPN

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft NPS Technical Manual Template

Integration Guide. SafeNet Authentication Service. Protecting SugarCRM with SAS

Integration Guide. SafeNet Authentication Service. NetDocuments

Integration Guide. SafeNet Authentication Client. Using SAC CBA with Juniper Junos Pulse

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for VMware Horizon 6

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft SharePoint on IIS 7/8. Technical Manual Template

Integration Guide. SafeNet Authentication Service. Using RADIUS Protocol for Citrix GoToMyPC

SafeNet Authentication Manager. Integration Guide. Using SAM as an Identity Provider for Dropbox

SafeNet Authentication Service Cisco AnyConnect Agent. Configuration Guide

Integration Guide. SafeNet Authentication Service. SAS Using RADIUS Protocol with CA SiteMinder

Integration Guide. SafeNet Authentication Manager. Using SafeNet Authentication Manager with Citrix XenApp 6.5

Integration Guide. SafeNet Authentication Client. Using SAC CBA with BitLocker

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Citrix NetScaler 10.5

Integration Guide. SafeNet Authentication Service. Protecting Syncplicity with SAS

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Okta

Integration Guide. SafeNet Authentication Service. Using SAS as an Identity Provider for Better MDM

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with SonicWALL E-Class Secure Remote Access

Welcome Guide. SafeNet Authentication Service. MP-1 BlackBerry. SafeNet Authentication Service: Welcome Guide. MP-1 BlackBerry

KT-4 Keychain Token Welcome Guide

Welcome Guide. SafeNet Authentication Service. RB-1 Tokens. SafeNet Authentication Service: Welcome Guide. RB-1 Tokens

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for Tableau Server

Integration Guide. SafeNet Authentication Service. SAS using RADIUS Protocol with WatchGuard XTMv. SafeNet Authentication Service: Integration Guide

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for SonicWALL Secure Remote Access

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Microsoft DirectAccess

Integration Guide. SafeNet Authentication Client. Using SAC CBA for VMware Horizon 6 Client

SAS Agent for NPS CUSTOMER RELEASE NOTES. Contents

Integration Guide. SafeNet Authentication Manager. Using SAM as an Identity Provider for PingFederate

Synchronization Agent Configuration Guide

SAS Agent for NPS FAQS. Contents. Page 1 of 5. Description... 2 Frequently Asked Questions... 2 Product Documentation... 5 Support Contacts...

Integration Guide. SafeNet Authentication Manager. SAM using RADIUS Protocol with Check Point Security Gateway

Integration Guide. SafeNet Authentication Manager. Using RADIUS Protocol for Cisco ASA

Synchronization Agent Configuration Guide

SAS Agent for Microsoft Internet Information Services (IIS)

Oracle iplanet Web Server Integration Guide

MobilePASS for BlackBerry OS 10

SAS Agent for Microsoft SharePoint

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service Agent for Cisco AnyConnect Client. Installation and Configuration Guide

SafeNet Authentication Client

SafeNet Authentication Service

SafeNet Authentication Client

SafeNet Authentication Service Token Validator Proxy Agent. Installation and Configuration Guide

SafeNet Authentication Service

Sentinel Cloud Run-time Java Samples ReadMe

Sentinel Cloud V.3.6 Installation Guide

SafeNet Authentication Client

SafeNet Authentication Service

SafeNet Authentication Service

SafeNet Authentication Service (SAS) Service Provider Billing and Reporting Guide

SafeNet Authentication Client

SafeNet Authentication Service

SafeNet Authentication Client

SafeNet Authentication Client

SafeNet Authentication Service Agent for Microsoft Outlook Web App. Installation and Configuration Guide

SafeNet Authentication Service

Citrix Access Gateway Implementation Guide

Oracle Access Manager Configuration Guide

SafeNet Authentication Manager

Implementation Guide for protecting Juniper SSL VPN with BlackShield ID

Implementation Guide for protecting. SonicWall Security Appliances. with. BlackShield ID

SafeNet Authentication Client

SAS Synchronization Agent

SafeNet Authentication Manager

SafeNet Authentication Service

Preface. Microsoft SQL Server 2008 and Luna SA/Luna PCI Integration Guide SafeNet, Inc. All rights reserved.

Implementation Guide for protecting. CheckPoint Firewall-1 / VPN-1. with. BlackShield ID

SafeNet MobilePASS+ for Android. User Guide

SafeNet Authentication Manager

SafeNet Authentication Service Authentication API for Microsoft.Net. Developer Guide

Cisco Terminal Services (TS) Agent Guide, Version 1.0

Cisco Terminal Services (TS) Agent Guide, Version 1.1

SafeNet Authentication Service. Push OTP Solution Guide

SafeNet Authentication Service. Java Authentication API Developer Guide

Dell SonicWALL NSA 3600 vpn v

SafeNet Authentication Client

SafeNet Authentication Manager

Implementing CRYPTOCard Authentication. for. Whale Communications. e-gap Remote Access SSL VPN

HOB HOB RD VPN. RSA SecurID Ready Implementation Guide. Partner Information. Product Information Partner Name. Last Modified: March 3, 2014 HOB

RSA SecurID Ready Implementation Guide. Last Modified: March 27, Cisco Systems, Inc.

Cisco Terminal Services (TS) Agent Guide, Version 1.1

Gemalto Bluetooth Device Manager

Barracuda Networks SSL VPN

Microsoft Unified Access Gateway 2010

SafeNet Authentication Manager

SafeNet Authentication Service Synchronization Agent. Configuration Guide

SafeNet Authentication Manager

<Partner Name> RSA SECURID ACCESS Standard Agent Implementation Guide. WALLIX WAB Suite 5.0. <Partner Product>

SafeNet Authentication Client

SafeNet Authentication Manager

SafeNet Authentication Service

VMware Identity Manager vidm 2.7

Virtual KeySecure for AWS

RSA SecurID Implementation

One Identity Starling Two-Factor Desktop Login 1.0. Administration Guide

RSA Ready Implementation Guide for. GlobalSCAPE EFT Server 7.3

Transcription:

SafeNet Authentication Service Integration Guide Technical Manual Template Release 1.0, PN: 000-000000-000, Rev. A, March 2013, Copyright 2013 SafeNet, Inc. All rights reserved. 1

Document Information Document Part Number 007-012631-001, Rev A Release Date July 2009 Trademarks All intellectual property is protected by copyright. All trademarks and product names used or referred to are the copyright of their respective owners. No part of this document may be reproduced, stored in a retrieval system or transmitted in any form or by any means, electronic, mechanical, chemical, photocopy, recording, or otherwise, without the prior written permission of SafeNet, Inc. Disclaimer SafeNet makes no representations or warranties with respect to the contents of this document and specifically disclaims any implied warranties of merchantability or fitness for any particular purpose. Furthermore, SafeNet reserves the right to revise this publication and to make changes from time to time in the content hereof without the obligation upon SafeNet to notify any person or organization of any such revisions or changes. We have attempted to make these documents complete, accurate, and useful, but we cannot guarantee them to be perfect. When we discover errors or omissions, or they are brought to our attention, we endeavor to correct them in succeeding releases of the product. SafeNet invites constructive comments on the contents of this document. These comments, together with your personal and/or company details, should be sent to the address or email below. Contact Method Mail Email Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017, USA TechPubs@safenet-inc.com 2

Contents Contents Introduction... 4 Third-Party Software Acknowledgement... 4 Overview... 4 Operation... 4 Applicability... 4 Prerequisites... 5 Installation... 5 Troubleshooting... 7 Logging Level... 7 Agent Upgrade... 8 Support Contacts... 8 3

Introduction Third-Party Software Acknowledgement This document is intended to help users of SafeNet products when working with third-party software, such as Citrix Web Interface 4.6. Material from third-party software is being used solely for the purpose of making instructions clear. Screen images and content obtained from third-party software will be acknowledged as such. Overview By default, Citrix Web Interface logons requires that a user provide a correct user name and password to successfully log on. This document describes the steps necessary to augment this logon mechanism with strong authentication by adding a requirement to provide a one-time password generated by a SafeNet token using the SAS Agent for Citrix Web Interface. Operation The SAS Agent for Citrix Web Interface will place an additional field for one-time password input on the current Citrix Web Interface logon page. The user authenticates using their user name, static password and their SAS one-time password. The user is either granted or denied access based on the authentication request result. Applicability Security Partner Information Product Name Citrix Web Interface 4.6 Vendor Site Supported Client Software N/A Authentication Method http://www.citrix.com n/a SafeNet Authentication Service Supported SAS Functionality SAS Authentication RADIUS (PAP) Authentication Mode One-time password Challenge-response BlackShield ID Pro static password New PIN Mode User-changeable Alphanumeric 3-16 digit PIN User-changeable Numeric 3-16 digit PIN 4

Server-changeable Alphanumeric 3-16 digit PIN Server-changeable Numeric 3-16 digit PIN Authentication Server SAS Versions SAS All Prerequisites Verify that a Test user account can successfully authenticate via the Citrix Web Interface 4.6 when the SAS agent is not installed. The Agent must be allowed to send TCP Port 80 or 443 network traffic to the SAS server. Ensure that the chosen port is open on any firewalls between the agent and the SAS server. Installation 1. Run the Agent installer ( BlackShield ID Citrix Web Interface Agent.exe ) on the machine hosting Web Interface. 2. Accept or modify the Agent install location. Default: C:\Inetpub\wwwroot\citrix\AccessPlatform 3. Click Next. 4. Enter in the hostname or IP Address of the SAS Server. 5

5. To configure failover, place a check mark in Specify failover BlackShield ID Authentication Server and then enter the hostname or IP address of the secondary server. 6. Using a web browser, navigate to the Citrix Web Interface 4.6 logon page. The web page now has an additional field called PASSCODE. 6

7. Perform a quick test by logging on with the Test account user name, password, and token one-time password. The users Web Interface page will be displayed when authentication succeeds. Troubleshooting Logging Level By default, the Agent has the ability to log issues that arise when authenticating against SAS. To change the logging level, edit the following Registry key: \HEKY_LOCAL_MACHINE\SOFTWARE\CRYPTOCard\AuthCitrix\Loglevel By default the log level is set to 3. The log level runs from 1-5 where 1 is the lowest logging level and 5 is the most verbose logging. After changing the log level, IIS Admin service must be restarted for the new log level to take effect. Log files are located in: \\Program Files\CRYPTOCard\BlackShield ID\Citrix Agent\Logs Note that nothing is written to the log file for log levels 1, 2 or 3 unless the Agent is unable to connect to the server. All information gathered is from the SAS Snapshot tab in the SAS Manager. Symptom Login Failed Indication Possible Causes The one-time password provided for the user is incorrect. Solution Resync the token from the SAS Manager Ensure the user is using the correct token and credentials 7

Symptom Login Failed Indication Possible Causes Solution The PIN provided for the user is incorrect. In SAS Manager, reset the PIN on the Secured Users tab. Agent Upgrade To upgrade this Agent, uninstall the current version and then run a newer version of the Agent installer. For more information, refer to the SafeNet Authentication Service Administrator s Guide. Support Contacts If you encounter a problem while installing, registering, or operating this product, please make sure that you have read the documentation. If you cannot resolve the issue, contact your supplier or SafeNet Customer Support. SafeNet Customer Support operates 24 hours a day, 7 days a week. Your level of access to this service is governed by the support plan arrangements made between SafeNet and your organization. Please consult this support plan for further information about your entitlements, including the hours when phone support is available to you. Contact Method Address Contact Information SafeNet, Inc. 4690 Millennium Drive Belcamp, Maryland 21017 USA Phone United States 1-800-545-6608 International 1-410-931-7520 Technical Support Customer Portal https://serviceportal.safenet-inc.com Existing customers with a Technical Support Customer Portal account can log in to manage incidents, get the latest software upgrades, and access the SafeNet Knowledge Base. 8