Federation Reflection: A Better Way To Do Pass-Through Authentication?
Tuesday, 07 November 2006 by Michel Roth
Jay Tomlin on his blog, discusses the ADFS-enabled version of Web Interface: For quite some time now Web Interface has supported a "single sign-on" feature where the user is shown their published application icons without ever having to provide a username and password.

The way this works, in a nutshell, is the following:

1. From a domain workstation, the user points IE to an IIS domain member web server. IIS performs Integrated Windows Authentication (using either NTLM or Kerberos) to ascertain the user's identity.

2. Web Interface reads the user identity and performs a lookup to determine which domain groups the user belongs to.

3. The list of groups (SIDs) is sent to the Presentation Server XML broker and the applications published to those groups is returned to Web Interface.

That takes care of getting the icons painted on the web page, but connecting to one of those application uses an entirely different authentication method: the ICA client must eavesdrop on the user's workstation logon, store the credentials in memory (ssonsvr.exe) and then replay those credentials (or send a Kerberos ticket) through an ICA virtual channel when connecting to a Presentation Server.

As you can see, the initial web server authentication does nothing to help with the ICA session authentication. If you have ever struggled with a deployment of Web Interface that uses the "Pass-through" authentcation method, you are all too familiar with the pain-points that this situation creates...

You can eliminate those pain points by leveraging the ADFS-enabled version of Web Interface. This is available today as a special post-4.2 release, and ADFS support will be part and parcel of Web Interface 4.5 when it ships.

Read the entire article here.

Related Items:

Web Interface Mod: Take Smart Card Authentication to the DMZ (7 September 2006)
The New Citrix Authentication Landscape (6 December 2006)
Citrix Releases ADFS Support For Presentation Server (12 July 2006)
Restricted Groups for Web Interface 4.5 (27 March 2007)
RDP Client 6.0 FAQ (24 January 2007)
Enabling Single Sign-On On Terminal Servers Connections (24 April 2007)
Using WI 4.2 With Access Gateway Adv.Edition 4.2 (18 May 2006)
Citrix Web Interface 4.2 Review (22 August 2006)
Technical Video: Citrix and ADFS (19 December 2006)
Unattended Installation Of The Citrix Web Interface (21 September 2006)
Comments (0)add feed
password
 

busy