Configuring Client Certificate Authentication
-
If the user does not provide a valid certificate during the Secure Sockets Layer (SSL) handshake.
-
The user name extraction fails, authentication fails.
-
Contact Citrix support to enable automatic selection of client certificates in macOS devices.
-
The automatic selection of client certificates is not supported in the App Store version of the Citrix Secure Access for macOS.
| CA certificate configurations | Client certificate options | Expected behavior of Citrix Secure Access™ |
|---|---|---|
| CA1 is configured on NetScaler Gateway | Client certificate 1 from CA1 | Citrix Secure Access selects the client certificate automatically and proceeds with authentication without user interaction. |
| Client certificate 1 and client certificate 2 from CA 1 | Citrix Secure Access selects the client certificate based on maximum expiry time and proceeds with authentication without user interaction. | |
| CA1 and CA2 are configured on NetScaler Gateway | Client certificate 1 and client certificate 2 either from CA 1 or CA 2 | Citrix Secure Access selects the client certificate based on maximum expiry time and proceeds with authentication without user interaction. |
| Only 1 client certificate either from CA1 or CA2 | Citrix Secure Access selects the client certificate automatically and proceeds with authentication without user interaction. | |
| Client certificate 1 from CA1 and client certificate 2 from CA 2 | Citrix Secure Access prompts the user with both client certificates and the user should select the client certificate based on their requirement. |
To configure the client certificate as the default authentication type by using the GUI
-
Go to Configuration > NetScaler Gateway, and then click Global Settings.
-
In the details pane, under Authentication Settings, click Change authentication CERT settings.
-
Select ON to enable two factor authentication using the certificate as per your requirement.
-
In User Name Field, select the type of certificate field that holds the user names.
-
In Group Name Field, select the type of the certificate field that holds the group name.
-
In Default Authorization Group, type the name of the default group, and then click OK.