Citrix Virtual Apps and Desktops - Unable to Use Yubikey in Non-Browser Applications

book

Article ID: CTX696269

calendar_today

Updated On:

Description

Customers are not able to use their YubiKeys in any non-browser based applications using the FIDO2 redirection feature, but they are able to use their YubiKeys to Authenticate in Web Based Applications running in Chrome/Edge or Firefox. 

When they click on these application they are repeatedly prompted to insert their YubiKey even if it is already inserted.

image.png

This issue occurs even when the Virtual Channel Allow List is Disabled.

 

Environment

Caution! Using Registry Editor incorrectly can cause serious problems that might require you to reinstall your operating system. Citrix cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk. Be sure to back up the registry before you edit it.

Cause

The Application's executables was not entered using the list of WebAuthN Allowed Processes and/or the CtxWebAuthNHook was not present. 

Resolution

For CVAD 2203 and CVAD 2402:

Please follow: Advanced Configuration for MsEdgeWebView2 Based Applications https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/2402-ltsr/secure/fido2.html#advanced-configuration-for-msedgewebview2exe-based-applications

For CVAD 2507 and Current Release:

Please follow: Advanced Configuration for Custom Applications: https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/secure/fido2/advanced-configuration

 

Issue/Introduction

Customers are not able to use their YubiKeys in any non-browser based applications using the FIDO2 redirection feature, but they are able to use their YubiKeys to Authenticate in Web Based Applications running in Chrome/Edge or Firefox.