<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>www.annoying.dk &#187; prompting</title>
	<atom:link href="http://www.annoying.dk/tag/prompting/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.annoying.dk</link>
	<description>yet another useless blog</description>
	<lastBuildDate>Wed, 14 Apr 2010 09:00:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>Troubleshooting Pass-through authentication with Citrix XenApp</title>
		<link>http://www.annoying.dk/2010/02/02/troubleshooting-pass-through-authentication-with-citrix-xenapp/</link>
		<comments>http://www.annoying.dk/2010/02/02/troubleshooting-pass-through-authentication-with-citrix-xenapp/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 14:29:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[logon]]></category>
		<category><![CDATA[pass-though-pass though]]></category>
		<category><![CDATA[prompt]]></category>
		<category><![CDATA[prompting]]></category>
		<category><![CDATA[XenApp]]></category>

		<guid isPermaLink="false">http://www.annoying.dk/?p=82</guid>
		<description><![CDATA[This is just a quick post while i remember what ive done to solve the problem, i&#8217;ve spent quite amount of time troubleshooting this issue and if i get the time, i will update it later on. In my previous post, i talked about running the ica client in the userlogon script, making it possible [...]]]></description>
			<content:encoded><![CDATA[<p>This is just a quick post while i remember what ive done to solve the problem, i&#8217;ve spent quite amount of time troubleshooting this issue</p>
<p>and if i get the time, i will update it later on.</p>
<p><span id="more-82"></span></p>
<p>In my previous post, i talked about running the ica client in the userlogon script, making it possible to open files from explorer with a streamed application.</p>
<p>in this case, it would be nice to use Pass-Though Authentication so the user dont get prompted twice for logon credentials.</p>
<p>so i started playing around with it &#8211; actually spent way to many hours on something that should be pretty straight forward.</p>
<p>one of the first things one should do, is to reinstall the ica client as admin with the correct options like</p>
<blockquote><p>CitrixOnlinePluginFull.exe /silent SERVER_LOCATION=&#8221;http://10.20.30.40:81&#8243; ADDLOCAL=&#8221;ICA_Client,PN_Agent,SSON&#8221; ENABLE_SSON=&#8221;Yes&#8221;</p></blockquote>
<p>so heres a short list of stuff to check (feel free to comment if theres more)</p>
<ul>
<li>Add the ica client adminstrative template for the domain and enabled pass-though &amp; Local username password</li>
<li>Checked the reg key for NetworkProvider/Order (Citrix single-SignOn needs to be in top)</li>
<li>Checked that pass-though was enabled and set to default on the XenWeb servers under PNAgent service site/Config.xml</li>
<li>Check that SSOnUserSetting=On in &#8220;UserProfiles\userxxx\AppData\Roaming\ICAClient\APPSRV.ini&#8221; and not Off</li>
</ul>
<p>In my case none of the above worked, and a few days after i found this <a href="http://support.citrix.com/article/CTX123686" target="_self">article</a>. with a hotfix that should solve the problem</p>
<blockquote><p>Pass-through authentication is not available when accessing a published application from within a published desktop on XenApp 5.0 servers. The user is required to provide valid credentials to launch a session within the desktop session even when pass-through authentication is enabled in the XenApp Plugin.</p></blockquote>
<p>Another possible workaround is to enable GPO &#8211; Computer Configuration\Administrative Templates\System\Credentials Delegation</p>
<p>&#8220;Allow Delegating Default Credentials&#8221; &#8211; set it to Enable, leave &#8220;Concatenate OS defaults with input above&#8221; checked, and click &#8220;Show&#8230;&#8221;</p>
<div>Add the name of your WI/PNA server and click OK.</div>
<div></div>
<div>After reinstalling the client on my own machine as local administrator &#8211; it worked, it got the option to choose Pass-Though auth under Logon mode in the ica client.</div>
<div>what exactly did it i cant remember, since my goal was to get the client working ON the xenapp server (running win2k8 64bit)</div>
<div>but i just cant manage to get SsonSvr.exe running. so until futher notice, this problem is not solved.</div>
<div></div>
]]></content:encoded>
			<wfw:commentRss>http://www.annoying.dk/2010/02/02/troubleshooting-pass-through-authentication-with-citrix-xenapp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
