This document explains how to configure Citrix StoreFront with Secret Double Octopus.


Integration Environment

The environment used for the integration described in this document is based on the following software versions:

  • Octopus Authentication Server version 5.0

  • Citrix Virtual Apps and Desktops 7.1909

Integration Workflow

Citrix Virtual Apps and Desktops integration involves the following sequential phases:

  1. Creating the Citrix SAML Service: Add a SAML service in the Octopus Management Console and configure service settings.

  2. Configuring StoreFront Integration: Configure SAML authentication on the StoreFront server.

Creating the Citrix SAML Service

This section explains how to create a service for Citrix StoreFront in the Octopus Management Console. Some of the service settings will be used later for Citrix StoreFront configuration.


To add and configure the Citrix SAML service:

  1. From the Octopus Management Console, open the Services menu and click Add Service. In the Generic SAML tile, click Add.



    Then, in the dialog that opens, click Create.



  2. Configure the following settings in the General Info tab:


    Setting

    Value / Notes

    Service Name

    Enter a display name to identify the service provider (e.g., Citrix XenApp).

    Issuer

    Enter the issuer of the service (e.g., Citrix).

    Description

    Enter a brief note about the service.

    Display icon

    This icon will be displayed on the Login page for the service. To change the default icon, click and upload the image of your choice (supported size 488x488 pixels).

    Login Page URL

    <https://<Enterprise Base URL>/generic-saml/<No.>/login>



    Then, click Save.

  3. Open the Parameters tab, and configure the following settings:


    Setting

    Value / Notes

    Octopus Authenticator Login

    The identifier required for the Octopus Authentication Server

    Name ID

    The parameter required for Citrix StoreFront login

    Method

    POST

    ASC URL

    https://<StoreFront Server>/Citrix/<store_name>Auth/SamlForms/AssertionConsumerService

    Audience

    http://<StoreFront Server>/Citrix/<store_name>Auth




  4. At the bottom of the Parameters tab, click ADD PARAMETER and create a new parameter for AttributeStatement.

    From the Parameter Value list, select Free Text. Then, in the field that appears to the right, enter yes.



  5. Click Save.

  6. Open the Sign on tab and update the default message in the Custom Message field. (This is the message displayed to users upon successful login.)

    Then, under X.509 Certificate, click Download to download the certificate.



  7. At the bottom of the Sign on tab, click Save.

  8. Open the Directories tab and select the checkboxes of the directories you want to integrate with the service. Then, click Save.



  9. Open the Users tab and click Add.



    A popup opens, with a list of directories displayed on the left.

  10. Expand the directories list and select the checkboxes of the groups and users that you want to add to the service. Then, click Save to close the popup.

    The groups and users you selected are listed in the Users tab.

  11. At the bottom of the Users tab, click Save. Then, from the toolbar at the top of the page, click PUBLISH and publish your changes.

Configuring StoreFront Integration

The following procedure explains how to configure StoreFront for integration with Secret Double Octopus. You will need the following data from the Sign on tab of the SAML service you created in the Octopus Management Console:

  • SAML 2.0 (Endpoint) HTTP: Click the Copy icon to copy the URL.

  • X.509 Certificate: If you have not yet downloaded the certificate, click Download now.



To configure StoreFront integration:

  1. From the StoreFront console, navigate to Citrix StoreFront > Stores.

    Then, on the right side of the page under Store Service, select Manage Authentication Methods.



  2. In the Manage Authentication Methods window, select Enable SAML Authentication > Identity Provider.

    The Identity Provider dialog opens.

  3. Configure the following settings:

    • SAML Binding: Select Post.

    • Address: Enter the SAML 2.0 (Endpoint) HTTP URL.



  4. At the bottom of the Identity Provider dialog, under Signing Certificates, click Import and import the X.509 Certificate.

  5. To save your changes, click OK.

Running the Solution

This section describes the user experience of logging into Citrix StoreFront via the Octopus Authenticator. The authentication process is as follows:

  1. From a browser, the user opens the FQDN of the Citrix StoreFront.

    The user is then redirected to the Secret Double Octopus login page.

  2. The user enters a username and clicks Login.



    A verification code is generated and displayed.



    A notification with the verification code then appears on the user's Octopus Mobile App, asking for authentication approval.

  3. The user taps Approve.



    After successful authentication, the user is logged onto Citrix StoreFront.

Footer - Secret Double Octopus