Rate this Article:
You must be signed in to rate again
Article Feedback Print View
Alternate Languages: N/A

Access Gateway, Enterprise Edition - Basic Smart Card Troubleshooting

Document ID: CTX113761   /   Created On: Jul 9, 2007   /   Updated On: Jul 9, 2007
Average Rating: not yet rated

Summary

When configuring authentication to an Access Gateway, Enterprise Edition-hosted Virtual Private Network (VPN), you can use smart card hosted certificates. The Access Gateway, Enterprise Edition Administrator's Guide states that only Shinwa smart cards are supported, however, Citrix understands other types of smart card readers are often used. This document describes how to best troubleshoot smart card issues.

Background

When configuring smart card authentication, the authentication type specified on the Access Gateway is Client Cert Authentication (mandatory or optional). Once this is done, the Access Gateway client takes the certificate on the local system’s smart card as well as certificates in the personal store.

Internet Explorer generates a PIN code request when it accesses the smart card reader. The Access Gateway does the same afterwards. If this transaction fails, Citrix suggests the following troubleshooting procedure:

Troubleshooting smart card issues

  1. Often, the root issue of what is thought to be a smart card problem is actually a certificate problem. Citrix recommends that you test your certificate against an SSL site when it resides in the local system store to ensure the client and server certificates have a clean handshake process.
  2. Test the authentication request after you have deleted the vserver's client certificates from Internet Explorer’s personal store.
  3. Obtain a network trace (nstrace.sh –m 7) and contact Citrix Technical Support for further assistance.

Most smart card problems can be reproduced using any smart card Cryptographic Service Provider (CSP). Generally, the same problem happens when testing against a non-Access Gateway SSL Web site. The key is isolating the problem. If you are unable to reproduce an issue using another CSP, then Citrix Technical Support may consider it to be an issue specific to that vendor’s CSP.

In that case, Citrix requests that you send a reader and card to test with and upload the version of the CSP software that you are using.

More Information

Additional background or reference information can be found on pages 47-48 of CTX112724 – Citrix Access Gateway Enterprise Edition Administrator's Guide.


This document applies to:

Search
Knowledge Center
XenApp
XenApp Plugins (Clients)
XenServer
XenDesktop
NetScaler Application Delivery
Access Gateway
EdgeSight
Provisioning Server
WANScaler
Password Manager
Does it work with Citrix? Verify it - introducing the new Citrix Ready Community Verified