ThinOS 9.1 prompts for password twice

Viewing 12 posts - 1 through 12 (of 12 total)
  • Author
    Posts
  • #93457
    javolio
    Participant
    • Total Post: 2
    • Newbie

    I have upgraded some Wyse 5070 thin clients from ThinOS 8.6 to 9.1 recently and I’m running into an issue where I have to enter the password twice to log in.

    It first asks for the Citrix Gateway password, prompts for DUO MFA, and then I have to enter the Storefront password to get logged in.

    My setup was working fine with ThinOS 8.6. It usually just passes the credentials from gateway right through to the storefront.

    Any ideas?

    Thank you!

    Josh

    #96017
    toby
    Participant
    • Total Post: 5
    • Newbie

    Hi,

    Same problem for us. The only workaround (known to me) is to change the URL to the Storefront URL or disable the use of beacons in the wms configuration. If you disable the beacons, please keep in mind that all connections are going through the netscaler, which might be a limitation because netscaler license throughput.

    I am not happy with that.

    Best Regards

    TL

    #96043
    javolio
    Participant
    • Total Post: 2
    • Newbie

    Hi Toby,

    Thanks for the suggestion!

    Disabling beacons did the trick for us. This works OK for how our environment is set up.

    Thanks,

    Josh

     

     

    #105158
    vinz
    Participant
    • Total Post: 55
    • Back Stage Pass
    • ★★★★

    Hi,

    Same problem for us.

    We are in a test environnement, to implement the 2 factor authentication with RSA passcode.

    All my 5470 mobile thin client are upgraded to ThinOS 9.1.2101, and when we logged in, we are first prompt with the Citrix ADC Netscaler login/password/passcode, then we have to enter again the login/password for the Storefront.

    I test with a brand new Wyse 3040 in ThinOS 8.6, and the credentials are asked just once !

    I can’t see what parameter to change in the ThinOS 9.x policy in my WMS 3.2

    I don’t want all my connections going through the Netscaler, so I don’t want to disable beacons.

    Any idea ? Is this a ThinOS 9 issue ?

    Thanx

    #105187
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    Yes, this happens not with ThinOS 8.
    Could you test with a Ubuntu PC and CWA?

    CG

    #105193
    vinz
    Participant
    • Total Post: 55
    • Back Stage Pass
    • ★★★★

    Hi,

    I don’t have any Ubuntu PC, sorry !

    I tried with a Windows 10 PC and Citrix Workspace App 2103 :

    – launching directly the Citrix App : authentication twice 🙁

    – with a web browser : only the gateway authentication ! 🙂

    I’m a bit lost…

    I’ve also send an email to my Dell IT Contact regarding this issue…

    Thank you for your interest !

    #105199
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    It is a known issue and Dell is working on this.

    CG

    #105394
    vinz
    Participant
    • Total Post: 55
    • Back Stage Pass
    • ★★★★

    Hi

    Any news about this issue ?

    Or can we expect a new ThinOS 9 firmware from Dell soon ?

    Thank you

     

    #105850
    vinz
    Participant
    • Total Post: 55
    • Back Stage Pass
    • ★★★★

    Hi,

    Unfortunately, the problem is still there with ThinOS 9.1.3112

    I must add a strange thing I noticed : in the broker settings in WMS, if I desactivate the “Netscaler/ADC Authentication with a web connection” (so the connection screen is in the ThinOS style, not web style), I must enter my passcode in the password field, and my password in the passcode field… (fields are switched). But in the Web connection, fields password/passcode are correct…

    Anybody use a 2 factor authentication ?

    #106031
    htothek
    Participant
    • Total Post: 1
    • Newbie

    Hey guys — as of 9.1.2101 there is a setting:

    *Direct External Connection to the Netscaler/ADC (no beacons being used)

    That you can check that fixes this issue.

    #106101
    toby
    Participant
    • Total Post: 5
    • Newbie

    Yes, because you have the option “direct external connection to the netscaler” enabled. It depende on the infrastructure setut, but normally, if possible you want direct connections to the VDA without the netscaler, because the netscaler license is limited by bandwidth and it is expensive.

    If you disable this option you have double authentication, first at netscaler after that at the storefront, if the beacons are reachable and the citrix client gets redirected.

    In ThinOS 8.6 the behavior was different and you have only one authentication whether if you let it connect to the netscaler or the storefront. The passthrough of the authentication worked.

    As workaround you can connect to the internal storefront URL, but again, it depends on your setup.

    #106858
    nico_cepo
    Participant
    • Total Post: 9
    • Regular Joe
    • ★★

    Almost a year and this bug is still not corrected by Dell with the latest firmware …

Viewing 12 posts - 1 through 12 (of 12 total)
  • You must be logged in to reply to this topic.