Configuring Smart Card Authentication
-
Create a certificate authentication policy. For more information, see Configuring Client Certificate Authentication.
-
Bind the authentication policy to a virtual server.
-
Add the root certificate of the Certificate Authority (CA) issuing the client certificates to NetScaler Gateway. For more information, see To install a root certificate on NetScaler Gateway.Important:When you add the root certificate to the virtual server for smart card authentication, you must select the certificate from the Select CA Certificate list.

-
If you set the domain on the Published Applications tab as
mydomain.com insteadmydomain. -
If you do not set the domain name on the Published Applications tab and if you run the command
wi-sso-split-upnsetting the value to 1. In this instance, the UserPrincipalName contains the domain name "mydomain.com."
Configuring Smart Card Authentication with Secure ICA® Connections
-
When logging on and when trying to start a published resource. This situation occurs if the web browser and the Citrix Workspace app are using the same virtual server that is configured to use client certificates.
-
Citrix Workspace app does not share a process or a Secure Sockets Layer (SSL) connection with the web browser. Therefore, when the ICA connection completes the SSL handshake with NetScaler Gateway, the client certificate is required a second time.
-
Client authentication on the VPN Virtual Server must be disabled.
-
SSL renegotiation must be enabled.
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
-
Select the relevant virtual server in the main details pane, and then click Edit.
-
In the Advanced options pane, click SSL Parameters.
-
Clear the Client Authentication check box.
-
Click Done.
-
Using the configuration utility, from the Configuration tab, navigate to Traffic Management, and then clickSSL.
-
In the main panel, click Change advanced SSL settings.
-
From the Deny SSL Renegotiation menu, select NO.
-
Connect the smart card to the user device.
-
Open your web browser and log on to NetScaler Gateway.