27.10.4 Configuring the SAML 2.0 Event on Advanced Authentication

  1. Open the Advanced Authentication Administration portal.

  2. Click Events > Add.

  3. Create an event with the following parameters:

    • Name: Citrix StoreFront

    • Chains: select the required chains.

    • Paste the content of the file https://<adfs_hostname>/FederationMetadata/2007-06/FederationMetadata.xml to the SP SAML 2.0 meta data.

      or

      • Click Choose File and upload the saved XML file.

    • Click Save.

    NOTE:Verify that you can access the file in your browser. If the file is not displayed, then you have an issue on ADFS that you need to resolve.

  4. Click Policies > Web Authentication.

  5. Set External URL to https://AdvancedAuthenticationServerAddress/ and replace AdvancedAuthenticationServerAddress with domain name or IP address of your Advanced Authentication server.

    NOTE:To use multiple Advanced Authentication servers with SAML 2.0, you must do the following:

    1. Configure an external load balancer.

    2. Specify the address in External URL instead of specifying an address of a single Advanced Authentication server.

  6. Click Download IdP SAML 2.0 Metadata.

    You must open the file as an XML file.

    NOTE:If {"Fault":{... ` is displayed, you must verify the configuration.