Configuring and Binding a Client Certificate Authentication Policy
-
In the configuration utility, on the Configuration tab, expand NetScaler Gateway > Policies > Authentication.
-
In the navigation pane, under Authentication, click CERT.
-
In the details pane, click Add.
-
In Name field, type a name for the policy.
-
Next to Server, click New.
-
In Name, type a name for the profile.
-
Next to Two Factor, select OFF.
-
In User Name field and Group Name field, select the values and then click &Create. Note: If you previously configured client certificates as the default authentication type, use the same names that you used for the policy. If you completed the User Name field and Group Name field for the default authentication type, use the same values for the profile.
-
In the Create Authentication Policy dialog box, next to Named Expressions, select the expression, click Add Expression, click Create and then click Close.
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
-
In the details pane, click a virtual server and then click Open.
-
In the configure NetScaler Gateway Virtual Server dialog box, click the Authentication tab.
-
Click Primary or Secondary.
-
Under Details, click Insert Policy.
-
In Policy Name, select the policy and then click OK.
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
-
In the details pane, click a Virtual Server and then click Open.
-
On the Certificates tab, click SSL Parameter.
-
Under Others, click Client Authentication.
-
In Client Certificate, select Optional or Mandatory and then click OK twice. Select Optional if you want to allow other authentication types on the same virtual server and do not require the use of client certificates.
-
For more information about Callback URL, see Import a NetScaler Gateway.
-
For more information about certificates, see Install, link, and update certificates.