Objective
This article describes how to allow users to change password from Web Interface when using NetScaler Gateway and Web Interface. NetScaler Gateway can be configured to allow users to change expired passwords if the user has completed a proper setup.
This article assumes that you are configuring NetScaler Gateway in either ICA Proxy mode or that you have set Web Interface as the homepage.
Background
This article is applicable for password change, assuming that the user can log on successfully. This article cannot be used if "change password on next logon" is selected in the user profile (which is a common practice when new user accounts are created and the user must change password after logging on for the first time), unless you disable authentication on the VPN VIP.
Requirements
- Ensure that the LDAP server is properly set for secure LDAP (LDAPS) connections for the setup to work.
- Download the NGWISSO.zip file from this article.
Caution! This customization affects the XenApp or XenDesktop SmartAccess functionalities of NetScaler Gateway such as:
-
Administrators cannot hide applications externally.
-
Administrators cannot disable or enable any XenApp or XenDesktop policies based on user access from NetScaler Gateway.
Instructions
Configuring Web Interface Server to Allow Users to Change Password
-
Create a Web Interface site and specify At Web Interface as a Point of Authentication, as shown in the following screen shot.
-
Ensure that the Web Interface site launches applications successfully with the XenApp environment.
-
Download the NGWISSO.zip file from this article.
-
Extract the contents of NGWISSO.zip file.
-
Navigate to the folder for which the name matches the version of the Web Interface version installed on the server.
-
Open the Readme.txt file and complete the instructions available in the file to replace the login file.
-
Open the Citrix Access Management Console for Web Interface.
-
Select Configure Authentication Methods from Common Tasks, as shown in the following screen shot:
-
Ensure that the Explicit option is selected in the Available methods list, as shown in the following screen shot and then click Properties.
-
Expand the Explicit node in the Properties dialog box.
-
Select Authentication Type and then select Settings.
-
Type the domain information in the Domain list, select the Pre-populated option.
-
Select the Hide Domain box radio button.
-
Click OK.
Note: Entering multiple domains into the domain list is currently not supported when you select Hide Domain box.
-
Select Password Settings and configure the required option under Allow users to change password.
-
Click OK in all the open dialog boxes.
-
Test the Web Interface site without NetScaler Gateway and ensure that you can log on, start applications, and change the password.
Configuring NetScaler to Allow Users to Change Password
-
Open the LDAP authentication profile and ensure that the following settings are enabled:
-
Select Allow Password Change.
-
Select TLS or SSL. If TLS is selected, use Port 389. For SSL, use port 636.
For more information, refer to Citrix Documentation - Configuring LDAP Authentication.
-
-
If everything is set correctly, you are prompted to change the password at the next logon (if required).??
Additional Resources
In order to support password expiration during authentication, the Bind DN account must also have read access to the PwdLastSet, UserAccountControl, and msDS-User-Account-Control-Computed attributes in the LDAP directory. For more information refer to CTX108876 ??- How to Configure LDAP Authentication on NetScaler.
For troubleshooting, failure to change expired password, refer to CTX114999 -?? How to Troubleshoot Authentication with aaad.debug.
Supporto Citrix
Traduzione automatica
Questo articolo ??¨ stato tradotto da un sistema di traduzione automatica e non ??¨ stata valutata da persone. Citrix fornisce traduzione automatica per aumentare l'accesso per supportare contenuti; tuttavia, articoli automaticamente tradotte possono possono contenere degli errori. Citrix non ??¨ responsabile di incongruenze, errori o danni derivanti dell'uso di articoli automaticamente tradotte.
Citrix技術支持
自動翻譯
這篇文章被翻譯由一個自動翻譯系統,並沒有受到人們的審查。 Citrix提供自動翻譯,增加獲得支持的內容;但是,自動翻譯的文章可能可以包含錯誤。思傑不負責不一致,錯誤或損壞因使用自動翻譯的文章的結果。
Поддержка Citrix
Tradução automática
Эта статья была переведена автоматической системой перевода и не был рассмотрен людьми. Citrix обеспечивает автоматический перевод с целью расширения доступа для поддержки контента; Однако, автоматически переведенные статьи могут может содержать ошибки. Citrix не несет ответственности за несоответствия, ошибки, или повреждения, возникшие в результате использования автоматически переведенных статей.
시트릭스 지원
자동 번역
이 문서 자동 번역 시스템에 의해 번역 된 사람들에 의해 검토되지 않았다. 시트릭스는 컨텐츠를 지원하기 위해 접근을 높이기 위해 자동 번역을 제공합니다; 그러나, 자동으로 번역 기사 오류를 포함 할 수있다. 시트릭스는 자동으로 번역 된 기사의 사용의 결과로 발생하는 불일치, 오류 또는 손해에 대해 책임을지지 않습니다.