Tuesday, 2013-08-20

*** nowen1 (~nowen@50-194-249-125-static.hfc.comcastbusiness.net) has joined #wikid12:47
*** nowen1 is now known as nowen_work12:48
*** mo (4084d7c2@gateway/web/freenode/ip.64.132.215.194) has joined #wikid18:37
mohello18:37
nowen_workhi18:37
*** mo is now known as Guest7482118:37
Guest74821i use wikid with citrix access gateway18:38
Guest74821i have configured the connection as per wikid recommendation18:39
Guest74821however, i would like to use single sign on with citrix18:39
Guest74821because I have to enter the passcode from wikid into the password field of citrix i cannot use sso with citrix18:39
Guest74821is there a work around18:40
Guest74821?18:40
nowen_workok - so there a single sign-on product from Citrix you want to use?18:40
Guest74821yes citrix access gateway already has a sso with xendesktop18:42
nowen_workso, if you tell the CAG to authenticate to WiKID, does that not do it?18:42
Guest74821it does but it uses the pin code to login;  what citrix does is it takes the login credentials which includes the pin code and sends to the second server i'm trying to log into which is xendesktop18:44
Guest74821but xendesktop is not aware of the pin code as password and it fails to authenticate18:45
nowen_workSorry, I'm not following.  The CAG does SSO and it talks radius. The CAG authenticates a user that is logging in. The user is authenticated by WiKID and is logged into the CAG.  Then, you try to login to xendesktop and it does not accept the CAG's authorization token?18:47
nowen_workI bet the CAG is not really doing SSO18:47
Guest74821no18:47
Guest74821cag is just passing credentials18:48
nowen_workthat's not SSO18:48
nowen_workdoes citrix have a product that really does SSO?18:48
Guest74821i don't know18:48
Guest74821but the cag can pass credentials to xendestop or xenapp and login automaticlaly18:49
nowen_workare you sure that SSO is not an option?  it appears to be for the Web Interface18:51
Guest74821without wikid i would enter my credentials to cag the cag then launches xendesktop and logs me in without i'm having to login to xendesktip18:53
Guest74821however it fails with wikid, so i'm assuming that with wikid cag sents credentials  that includes pin code instead of password thus failing18:54
nowen_workyes, I understand that Credential Forwarding works. What I am wonder is if SSO works?18:55
nowen_workReal18:56
nowen_workReal SSO does not forward credentials.  it uses a token or ticked of some sort18:57
nowen_workdoes this help: http://support.citrix.com/proddocs/topic/access-gateway-92/agee-multifactor-auth-double-source-sso-tsk.html18:58
Guest74821i don't have these options19:46
Guest74821i'm not using the version of cag you sent me19:46
nowen_worksounds like you need to talk to Citrix.19:47
Guest74821i'm using cag appliance19:47
Guest74821i didn't think it was possible with what i have now19:47
nowen_workyou either need to be able to use real SSO or be able to enter both the password and the wikid otp19:47
Guest74821you are right19:50
nowen_workwe are well beyond my citrix knowledge ;-)19:50
Guest74821i think we need a real sso as you said19:52
Guest74821thanks19:52
nowen_worknp19:52
*** Guest74821 has quit (Quit: Page closed)19:57
*** nowen_work has quit (Quit: Leaving.)21:21

Generated by irclog2html.py 2.11.0 by Marius Gedminas - find it at mg.pov.lt!