re-Captcha configuration for nFactor authentication
captchaAction that simplifies re-Captcha configuration. As re-Captcha is a first-class action, it can be a factor of its own. You can inject re-Captcha anywhere in the nFactor flow.
captchaAction, you do not have to modify the JavaScript.
re-Captcha configuration
-
Configuration on Google for registering re-Captcha.
-
Configuration on NetScaler appliance to use re-Captcha as part of login flow.
re-Captcha configuration on Google
<https://www.google.com/recaptcha/admin#llist>.
-
When you navigate to this page, the following screen appears.Register a siteNoteUse reCAPTCHA v2 only. Invisible re-Captcha is still in preview.
-
After a domain is registered, the “SiteKey” and “SecretKey” are displayed.Site key and secret keyNoteThe “SiteKey” and “SecretKey” are grayed out for security reasons. “SecretKey” must be kept safe.
re-Captcha configuration on a NetScaler appliance
-
Display re-Captcha screen
-
Post the re-Captcha response to Google server
-
LDAP configuration is second factor for user logon (optional)
Display re-Captcha screen
/nsconfig/loginSchema/LoginSchema directory on the NetScaler appliance.
-
The SingleAuthCaptcha.xml login schema can be used when LDAP is configured as the first factor.
-
Based on your use case and different schemas, you can modify the existing schema. For instance if you need only re-Captcha factor (without user name or password) or dual authentication with re-Captcha.
-
If any custom modifications are done or the file is renamed, Citrix recommends copying all loginSchemas from the
/nsconfig/loginschema/LoginSchemadirectory to the parent directory,/nsconfig/loginschema.
To configure display of re-Captcha using CLI
add authentication loginSchema singleauthcaptcha -authenticationSchema /nsconfig/loginschema/SingleAuthCaptcha.xml
add authentication loginSchemaPolicy singleauthcaptcha -rule true -action singleauthcaptcha
add authentication vserver auth SSL <IP> <Port>
add ssl certkey vserver-cert -cert <path-to-cert-file> -key <path-to-key-file>
bind ssl vserver auth -certkey vserver-cert
bind authentication vserver auth -policy singleauthcaptcha -priority 5 -gotoPriorityExpression END
Post the re-Captcha response to Google server
To verify re-Captcha response from the browser
add authentication captchaAction myrecaptcha -sitekey <sitekey-copied-from-google> -secretkey <secretkey-from-google>
add authentication policy myrecaptcha -rule true -action myrecaptcha
bind authentication vserver auth -policy myrecaptcha -priority 1
https://www.google.com/recaptcha/api/siteverify to validate the Captcha information. So, ensure that the site is reachable from NetScaler.
curl -vvv https://www.google.com/recaptcha/api/siteverify.
add authentication ldapAction ldap-new -serverIP x.x.x.x -serverPort 636 -ldapBase "cn=users,dc=aaatm,dc=com" -ldapBindDn adminuser@aaatm.com -ldapBindDnPassword <password> -encrypted -encryptmethod ENCMTHD_3 -ldapLoginName sAMAccountName -groupAttrName memberof -subAttributeName CN -secType SSL -passwdChange ENABLED -defaultAuthenticationGroup ldapGroup
add authenticationpolicy ldap-new -rule true -action ldap-new
LDAP configuration is second factor for user logon (optional)
add authentication policylabel second-factor
bind authentication policylabel second-factor -policy ldap-new -priority 10
bind authentication vserver auth -policy myrecaptcha -priority 1 -nextFactor second-factor
add lb vserver lbtest HTTP <IP> <Port> -authentication ON -authenticationHost nssp.aaatm.com
**nssp.aaatm.com** – Resolves to authentication virtual server.
User validation of re-Captcha
-
Once the authentication virtual server loads the login page, the logon screen is displayed. Log On is disabled until re-Captcha is complete.Enter credentials
-
Select I’m not a robot option. The re-Captcha widget is displayed.Robot option
-
You are navigated through a series of re-Captcha images, before the completion page is displayed.
-
Enter the AD credentials, select the I'm not a robot check box and click Log On. If authentication succeeds, you are redirected to the desired resource.Series of imagesNotes:
-
If re-Captcha is used with AD authentication, the Submit button for credentials is disabled until re-Captcha is complete.
-
The re-Captcha happens in a factor of its own. Therefore, any subsequent validations like AD must happen in the
nextfactorof re-Captcha.
-