More features supported for SAML
Metadata reading and generation support for SAML SP and IdP configuration
Metadata export for SAML SP
https://vserver.company.com/metadata/samlsp/<action-name>
Metadata import for SAML SP
set samlAction <name> [-metadataUrl <url> [-metadataRefreshInterval <int>] https://idp.citrix.com/samlidp/metadata.xml
Metadata import for SAML IdP
set samlIdPProfile <name> [-metadataUrl <url>] [-metadataRefreshInterval <int>]
Name-value attribute support for SAML authentication
-
In samlAction command, you can configure a maximum of 64 attributes separated by comma with total size less than 2048 bytes.
-
Citrix® recommends that you use the attributes list. Use of "attribute 1 to attribute 16" will cause session failure if the extracted attribute size is large.
To configure the name-value attributes by using the CLI
add authentication samlAction <name> [-Attributes <string>]
add authentication samlAction samlAct1 -attributes “mail,sn,userprincipalName”
Assertion Consumer Service URL support for SAML IdP
Increase of SessionIndex size in SAML SP
Custom authentication class reference support for SAML SP
-
The names of the classes must include alphanumeric characters or a valid URL with proper XML tags.
-
If you have to configure multiple custom classes, each class must be separated by commas
To configure the customAuthnCtxClassRef attributes by using the CLI
-
add authentication samlAction samlact1 –customAuthnCtxClassRef http://www.class1.com/LoA1,http://www.class2.com/LoA2 -
set authentication samlAction samlact2 –customAuthnCtxClassRef http://www.class3.com/LoA1,http://www.class4.com/LoA2
To configure the customAuthnCtxClassRef attributes by using the GUI
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Actions > SAML.
-
On the SAML page, select Servers tab and Click Add.
-
On the Create Authentication SAML Server page, enter the name for SAML action.
-
Scroll down to configure the class types in Custom Authentication Class Types section.custom authentication class types
Support for artifact binding in SAML IdP
Assertion Consumer Service URL support for SAML IdP
FIPS offload support
-
Add SSL FIPSadd ssl fipsKey fips-key
-
Create a CSR and use it at CA server to generate a certificate. You can then copy the certificate in /nsconfig/ssl. Let's assume that the file is fips3cert.cer.
add ssl certKey fips-cert -cert fips3cert.cer -fipsKey fips-key -
Specify this certificate in the SAML action for SAML SP module
set samlAction <name> -samlSigningCertName fips-cert -
Use the certificate in samlIdpProfile for SAML IdP module
set samlidpprofile fipstest –samlIdpCertName fips-cert
Common SAML terminologies
-
Assertion: A SAML assertion is an XML document returned by the Identity Provider to the Service Provider after authentication of the user. The assertion has a specific structure, as defined by the SAML standard.
-
Types of Assertions: The following are the types of assertion.
-
Authentication - the user is authenticated by a particular means at a particular time
-
Authorization - the user was granted or denied access to a specified resource
-
Attributes - the user is associated with the supplied attributes
-
-
Assertion Consumer Service (ACS): The service provider's endpoint (URL) that is responsible for receiving and parsing a SAML assertion
-
Audience Restriction: A value within the SAML assertion that specifies who (and only who) the assertion is intended for. The "audience" will be the service provider and is typically a URL but can technically be formatted as any string of data.
-
Identity Provider (IdP): In terms of SAML, the Identity Provider is the entity that verifies the identity of the user, in response to a request by the Service Provider.The Identity Provider is responsible for maintaining and authenticating the user's identity
-
Service Provider (SP): In terms of SAML, the Service Provider (SP) offers a service to the user and allows the user to sign in by using SAML. When the user attempts to sign in, the SP sends a SAML authentication request to the Identity Provider (IdP)
-
SAML Binding: SAML requestors and responders communicate by exchanging messages. The mechanism to transport these messages is called a SAML binding.
-
HTTP Artifact: One of the binding options supported by the SAML protocol. HTTP Artifact is useful in scenarios where the SAML requester and responder are using an HTTP User-Agent and do not want to transmit the entire message, either for technical or security reasons. Instead, a SAML Artifact is sent, which is a unique ID for the full information. The IdP can then use the Artifact to retrieve the full information. The artifact issuer must maintain state while the artifact is pending. An Artifact Resolution Service (ARS) must be set up.HTTP Artifact sends the artifact as a query parameter.
-
HTTP POST: One of the binding options supported by the SAML protocol.HTTP POST sends the message content as a POST parameter, in the payload.
-
HTTP Redirect: One of the binding options supported by the SAML protocol.When HTTP Redirect is used, the Service Provider redirects the user to the Identity Provider where the login happens, and the Identity Provider redirects the user back to the Service Provider. HTTP Redirect requires intervention by the User-Agent (the browser).HTTP Redirect sends the message content in the URL. Because of this, it cannot be used for the SAML response, because the size of the response will typically exceed the URL length allowed by most browsers.Notes:
-
The NetScaler appliance supports POST and Redirect bindings during logout.
-
The
ns_aaa_trusted_redirect_hostsis a pattern set allow list used for SAML logout redirect validation before redirecting the user to the unknown hosts. During SAML logout, theRelayStateparameter might contain a redirect URL where the user must be sent after logout completes. For enhanced security, the admins can use thens_aaa_trusted_redirect_hostspattern set to validate the redirect URL.
-
-
Metadata: Metadata is the configuration data in SP and IdP to know how to communicate to each other which will be in XML standards