Forum Discussion

Manuel_Cristob3's avatar
Manuel_Cristob3
Icon for Nimbostratus rankNimbostratus
Aug 20, 2018

F5 APM with DUO w/out replacing the storefront

Anyone deployed and configured DUO with Citrix-iapp (2.4.4) on version 13.x without replacing the Storefront Servers? We do have DUO working as designed by replacing Storefront with a webtop but I was wondering if DUO will also work if we do not replace the Storefront farm before we try this route.

 

thanks

 

4 Replies

  • I am running 13.1.1 and Setup Citrix using the template with DUO and It works fine.

     

    However I cant get Duo to work with the Citrix Webtop. Credentials are failing which doesn't make sense because I am also mapping drives using the same session variables successfully. The Event viewer in the Citrix DDC application log generates an Event ID 2100 "The Citrix Broker Service failed to validate a user's credentials on an XML service.

     

    Verify the trust relationships between your domains.

     

    Error details: User: 'ABCD\jdoe' Error: 'InvalidCredentials' Message: 'Failed Windows logon, error code 1326'

     

    This was working in 12.1.2

     

    If you or anyone else has insight on this issue please let me know.

     

    Thank you!

     

  • i am not sure if it is too late ..

     

    we recently implement solution using iApp . 2 factor Authentication with DUO. we used storefront as is just use F5 as a gateway .

     

    it wasn't easy since ran into so many roadblock, we have working now internally and externally with browser and Receiver

    • MK4321's avatar
      MK4321
      Icon for Nimbostratus rankNimbostratus

      Hi guys, Is there any chance you can share with me the solution? I am running into this same issue running on the same code 13.1.1 iapp 2.4.5. I have Duo working internally and SSO works to Storefront, but externally DUO works but SSO token for username and password does not get passed to Storefront and users need to authenticate again to see their resources externally.

       

      Would you please be so kind to share with me the solution to this issue?

      • hanifpayak's avatar
        hanifpayak
        Icon for Nimbostratus rankNimbostratus

        it depends on how did you configure share your policy detail , i might be able to help you. you can email me on hanif.payak@ngnxtech.com