LDAP authentication
Create an LDAP Authentication Action using the GUI
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Actions > LDAP.
-
Click Add. The Create Authentication LDAP Server screen is displayed.
-
Enter a name.
-
Update the parameter details. For more details, see LDAP parameters.
-
Click Test network connectivity to verify the entered details. See also Testing LDAP authentication.
-
Click Create.
Create an LDAP Authentication Action using the CLI
add authentication ldapAction. For more information, see add authentication ldapAction.
add authentication ldapAction ldap_server -serverip 1.1.1.1 -ldapBase "Cn=Users,dc=example,dc=com" -ldapBindDn admin@example.com -ldapBindDnPassword -ldapLoginName sAMAccountName
Edit an LDAP authentication action using the GUI
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Actions > LDAP.
-
Click the action you wish to edit.
-
Update the parameters. For more details, see LDAP parameters.
-
Click Test network connectivity to verify the entered details. See also Testing LDAP authentication.
-
Click OK to save.
Edit an LDAP authentication action using the CLI
set authentication ldapAction. For more information, see set authentication ldapAction.
set authentication ldapAction ldap_server -serverip 2.2.2.2
Create an LDAP authentication policy using the GUI
-
Navigate to Security > AAA - Application Traffic > Advanced Policies > Policy.
-
Click Add.
-
Enter a Name.
-
Choose Action Type of LDAP.
-
Under Action specify the authentication server you created.
-
Enter the Expression as TRUE.
-
Click Create.
Kv
Create an LDAP authentication policy using the CLI
add authentication ldappolicy. For more information, see add authentication ldappolicy.
add authentication Policy LDAP_Pol -rule TRUE -action ldap_server
LDAP parameters
Server name or Server IP
Security type
Port
-
389 for unsecured LDAP connections (for plain text LDAP)
-
636 for secure LDAP connections (for SSL LDAP)
-
3268 for Microsoft unsecure LDAP connections (for plain text Global Catalog Server)
-
3269 for Microsoft secure LDAP connections (for SSL Global Catalog Server)
Authenticate
authentication.
Server Logon Name Attribute
| LDAP server | User attribute | Case sensitive |
|---|---|---|
| Microsoft Active Directory Server | userPrincipalName or sAMAccountName | No |
| Novell eDirectory | ou | Yes |
| IBM Directory Server | uid | Yes |
| Lotus Domino | CN | Yes |
| Sun ONE directory (formerly iPlanet) | uid or cn | Yes |
Server type
Base DN
| LDAP server type | Example |
|---|---|
| Microsoft Active Directory Server | CN=Users,dc=example,dc=com |
| Novell eDirectory | ou=users,ou=dev |
| IBM Directory Server | cn=users |
| Lotus Domino | OU=City,O=Citrix, C=US |
| Sun ONE directory (formerly iPlanet) | ou=People,dc=citrix,dc=com |
Bind DN
| LDAP server | Bind DN |
|---|---|
| Microsoft Active Directory Server | CN=Administrator, CN=Users, DC=citrix, DC=local |
| Novell eDirectory | cn=admin, o=citrix |
| IBM Directory Server | LDAP_dn |
| Lotus Domino | CN=Notes Administrator, O=Citrix, C=US |
| Sun ONE directory (formerly iPlanet) | uid=admin,ou=Administrators, ou=TopologyManagement,o=NetscapeRoot |
Administrator password
Referral
binddn credentials that are used with the referring (GC) server. To enable referral support, you configure an LDAP action to follow referrals, and specify the maximum number of referrals to follow.
binddn credentials that it used with the previous server, and performs the operation which generated the referral. This feature is transparent to the user.
set authentication ldapAction <name> -followReferrals ON
set authentication ldapAction <name> -maxLDAPReferrals <integer>
Key-based authentication
-
Can store the retrieved public key, and the LDAP action uses this attribute to retrieve SSH key information from the LDAP server.
-
Can extract attribute names of up to 24 KB.
-
SSH daemon sends an AAA\_AUTHENTICATE request with password field empty to authentication, authorization, and auditing daemon port.
-
If LDAP is configured to store the SSH public key, authentication, authorization, and auditing responds with the "sshPublicKey" attribute along with other attributes.
-
SSH daemon verifies these keys with the client keys.
-
SSH daemon passes the user name in the request payload, and authentication, authorization, and auditing returns the keys specific to this user along with generic keys.
sshPublicKey parameter. For example:
set authentication ldapAction LDAP_Action -sshPublicKey <sshPublicKey>
Name-value attributes
-
Minimizes the effort for administrators by remembering the attribute by name (not just by value)
-
Enhances the search to query the attribute value associated with a name
-
Provides an option to extract multiple attributes
attributes parameter.
set authentication ldapAction ldapAct1 -attributes "company, mail"
Cloud attributes settings
CloudAttributes
set authentication ldapAction LDAP_Action -CloudAttributes ENABLED
Testing LDAP authentication
-
Navigate to Security > AAA - Application Traffic > Policies > Authentication > Advanced Policies > Actions > LDAP.
-
Select the available LDAP action from the list.
-
On the Configure Authentication LDAP Server page, scroll down to the Connections Settings section.
-
Click Test Network connectivity to check the LDAP server connection. You can view a pop-up message of successful connection to the LDAP server with TCP port details and authenticity of valid credentials.

-
To view the end-to-end LDAP authentication, click End-to-end login test link.
-
In the End-to-end login test page, click Test.
-
On the authentication page, enter the valid credentials to log in. The success screen is displayed.
-
If the authentication fails, the error screen is displayed.

-
Password expiry notification for LDAP authentication
Advantages of password expiry notification
-
Permit users to reset their passwords on their own and provide administrators a flexible way to notify the end user about their password expiry in days.
-
Eliminates end user dependence to track their password expiration days.
-
Sends notifications to the VPN portal page to the users (based on the number of days) to change their password before expiry.
Understanding the password expiry notification
Max-Pwd-Age and Pwd-Last-Set) from the LDAP authentication server.
-
Max-Pwd-Age. This attribute denotes the maximum amount of time, in 100-nanosecond intervals, until the password is valid. The value is stored as a large integer that represents the number of 100-nanosecond intervals from the time the password was set before the password expires.
-
Pwd-Last-Set. This attribute determines the date and time at which the password for an account was last changed.
pwdExpiryNotification in the set aaa parametercommand. By using this parameter, an administrator can keep track the number of days left for password expiry. The NetScaler appliance can now start notifying the end user about their password expiry.
-
An administrator, by using the NetScaler appliance, sets a time (e.g. 14-days) for password expiration.
-
The user sends an HTTP or HTTPS request to access a resource on the back-end server.
-
Before providing access, the NetScaler appliance validates the user credentials with what is configured on the LDAP authentication server.
-
Along with this query to the authentication server, the NetScaler appliance carries the request to fetch the details of the two attributes (
Max-Pwd-Age and Pwd-Last-Set). -
Based on the time left for the password to expire, an expiry notification is displayed.
-
The user then takes appropriate action to update the password.
Configure password expiry notification
-
Navigate to Security > AAA - Application Traffic > Authentication Settings.
-
Click Change authentication AAA settings.
-
On the Configure AAA Parameter page, specify the days in the Password Expiry Notification(days) field. The maximum value is 255 days.

-
Click OK.
set aaa parameter –pwdExpiryNotificationDays <positive_integer>
show aaa parameter
> set aaa parameter -pwdExpiryNotificationDays 14
Done
> show aaa parameter Configured AAA parameters EnableStaticPageCaching: YES EnableEnhancedAuthFeedback: NO DefaultAuthType: LOCAL MaxAAAUsers: Unlimited AAAD nat ip: None EnableSessionStickiness : NO aaaSessionLoglevel : INFORMATIONAL AAAD Log Level : INFORMATIONAL Dynamic address: OFF
GUI mode: ON
Max Saml Deflate Size: 1024 Password Expiry Notification Days: 14
Display of notifications
LDAP authentication with nested group extraction
-
ADC-GROUP1 is a member of ADC-GROUP2.
-
LOCAL-GROUP1 is a member of LOCAL-GROUP2.
-
DOMAIN-GROUP1 is a member of DOMAIN-GROUP2.
memberOf attribute lists its groups, while a group's member attribute lists its members. For the preceding example:
-
User1 object's
memberOfattribute references ADC-GROUP1. -
ADC-GROUP1 object's
memberattribute references User1.
To configure LDAP authentication with nested group extraction using the CLI
add authentication ldapAction <name> {-serverIP <ip_addr|ipv6_addr|*> | {-serverName <string>}} [-serverPort <port>] [-authTimeout <positive_integer>] [-ldapBase <string>] [-ldapBindDn <string>] {-ldapBindDnPassword } [-ldapLoginName <string>] [-searchFilter <string>] [-groupAttrName <string>] [-subAttributeName <string>] [-secType <PLAINTEXT | TLS | SSL>] [-svrType ( AD | NDS )][-ssoNameAttribute <string>] [-authentication ( ENABLED | DISABLED )] [-requireUser ( YES | NO )] [-passwdChange ( ENABLED | DISABLED )] [-nestedGroupExtraction ( ON | OFF ) [-maxNestingLevel <positive_integer>] [-groupSearchSubAttribute <string>] [-groupSearchFilter <string>]] [-followReferrals ( ON | OFF ) [-maxLDAPReferrals <positive_integer>]][-referralDNSLookup <A-REC | SRV-REC | MSSRV-REC> [-msSRVRecordlocation <string>]] [-validateServerCert ( YES | NO )] [-ldapHostname <string>] [-groupNameIdentifier <string>][-groupSearchAttribute <string>] [-defaultAuthenticationGroup <string>] [-Attribute1 <string>] [-Attribute2 <string>] [-Attribute3 <string>] [-Attribute4 <string>] [-Attribute5 <string>][-Attribute6 <string>] [-Attribute7 <string>] [-Attribute8 <string>] [-Attribute9 <string>] [-Attribute10 <string>] [-Attribute11 <string>] [-Attribute12 <string>] [-Attribute13 <string>][-Attribute14 <string>] [-Attribute15 <string>] [-Attribute16 <string>] [-Attributes <string>] [-sshPublicKey <string>] [-pushService <string>] [-OTPSecret <string>] [-email <string>][-KBAttribute <string>] [-alternateEmailAttr <string>] [-CloudAttributes ( ENABLED | DISABLED )]
-
serverIP: IP address assigned to the LDAP server.
-
serverName: LDAP server name as an FQDN, which is mutually exclusive with LDAP IP address. Maximum length: 127.
-
serverPort: Port on which the LDAP server accepts connections. Default value:
389. Minimum value:1. -
ldapBase: Base (node) from which to start LDAP searches. If the LDAP server is running locally, the default value of base is
dc=netscaler, dc=com. Maximum length: 127. -
ldapBindDn: Full distinguished name (DN) that is used to bind to the LDAP server. Default:
cn=Manager,dc=netscaler,dc=com. Maximum length: 127. -
ldapLoginName: LDAP login name attribute. NetScaler uses the LDAP login name to query external LDAP servers or Active Directories. Maximum length: 127.
-
searchFilter: String to be combined with the default LDAP user search string to form the search value. For example, if the search filter
"vpnallowed=true"is combined with the LDAP login name"samaccount"and the user-supplied user name is "bob", the result is the LDAP search string""&(vpnallowed=true)(samaccount=bob)"". Maximum length: 255.Note:Enclose the search string in two sets of double quotation marks.
GroupSearch:
-
groupAttrName: LDAP group attribute name. This parameter is used for group extraction on the LDAP server. Maximum length: 31.Note:If the
groupSearchFilterparameter is included in the command, then do not use this parameter. In other scenarios, use thegroupAttrNameparameter for group search operation. -
subAttributeName: LDAP group sub-attribute name. This parameter is applied on group attribute value, which is extracted from
groupAttrNameparameter. Maximum length: 31. -
nestedGroupExtraction: Allow nested group extraction, in which NetScaler queries external LDAP servers to determine whether a group is part of another group. Possible values:
ON,OFF. Default value:OFF. -
maxNestingLevel: If nested group extraction is
ON, this parameter specifies the number of levels up to which group extraction is performed. Default value:2. Minimum value:2. Maximum Value:255. -
groupSearchSubAttribute: LDAP group search subattribute that is used to determine to which groups a specific group belongs. This parameter is applied on group attribute value when the nested group extraction process happens. Maximum length: 31.
-
groupSearchFilter: String to be combined with the default LDAP group search string to form the search value. For example, the group search filter
""vpnallowed=true""when combined with the group identifier""samaccount""and the group name""g1""yields the LDAP search string""(&(vpnallowed=true)(samaccount=g1)"". IfnestedGroupExtractionisENABLED, the filter is applied on the first level group search as well, otherwise first level groups (which user is a direct member of) are fetched without applying this filter. Maximum length: 127.Note:Enclose the search string in two sets of double quotation marks. -
groupNameIdentifier: Name that uniquely identifies a group in LDAP or Active Directory. Maximum length: 127.
-
groupSearchAttribute: LDAP group search attribute used to determine the groups to which a specific group belongs. Maximum length: 31.
Different use cases for search filter
Use case 1: Basic user search
-ldapLoginName samAccountName
samAccountName attribute corresponds to the user input user1.
(&(samAccountName=user1)(objectClass=*))
add authentication ldapAction <name> -ldapLoginName userPrincipalName
userPrincipalName attribute corresponds to the user input user1@aaa.local.
(&(userPrincipalName=user1@aaa.local)(objectClass=*))
Use case 2: User search with additional filter
vpnallowed attribute set to true, use the following LDAP configuration.
add authentication ldapAction <name> -ldapLoginName samAccountName -searchFilter "(vpnallowed=true)"
samAccountName attribute corresponds to the user input user1.
(&(samAccountName=user1)(vpnallowed=true))
Use case 3: User search with group extraction
add authentication ldapAction <name> -ldapLoginName samAccountName -groupAttrName memberOf
samAccountName attribute corresponds to the user input user1.
(&(samAccountName=user1)(objectClass=*))
memberOf