Improve company productivity with a Business Account.Sign Up

x
?
Solved

Citrix single sign on / pass-thru authentication prompts for credentials

Posted on 2008-10-15
3
Medium Priority
?
7,489 Views
Last Modified: 2008-10-21
I have a Windows XP SP2 client trying to connect to a published app on a Windows 2003 server running Citrix Metaframe XPe using the local user name and password with pass-thru authentication.  PASS-THRU AUTHENTICATION WORKS ON EVERY SINGLE COMPUTER EXCEPT THIS ONE.  I've checked the following:

* Ensured that ICA Settings/General tab, "Pass-Through Authentication" and "Use local credentials to log on" are both checked.

* Ensured that Properties/Logon Information tab, "local user" radio button is selected and that "Pass-through Authentication" is checked.

* Confirmed that there are no local policies blocking this feature.  Changed local policy object Local Computer Policy / Computer Configuration / Administrative Templates / Citrix Components / Presentation Server Client / User Authentication / Local user name and password from "Not Configured" to "Enabled" to lock in pass-through authentication, denying the user the ability to change this to user-specified credentials.

* In separate tests, added the following lines to the C:\Documents and Settings\%username%\Application Data\ICAClient\appsvr.ini file.

EnableSSOnThruCAFile=On  to the WFClient portion of appsrv.ini.    
SSOnUserSetting=On was already in there.

0
Comment
Question by:zaphod_beeblerox
3 Comments
 
LVL 2

Assisted Solution

by:Ron9909
Ron9909 earned 400 total points
ID: 22733965
Could you check the properties of the ICA connection through the Citrix Connection Configuration utility and make sure that the 'prompt for password' check box is cleared?  Inherit user config should be checked there also.

I know you said you've checked the policy, but can you also check under:
Computer Config > Administrative Templates > Windows Components > Terminal Services > Encryption and Security as there is a further option here for prompt user on connection.
0
 

Accepted Solution

by:
zaphod_beeblerox earned 0 total points
ID: 22736653
Thank you Ron9909, but that setting is already set to Not Configured.
Upon further investigation, I found that ssonsvr.exe was not running and was not starting.  

I eventually found that the Intel wireless software was causing the problem. I fixed it by changing the order of the items in the following registry keys:

HKLM\System\CurrentControlSet\Control\NetworkProvider\Order\ProviderOrder
and
HKLM\System\CurrentControlSet\Control\NetworkProvider\HWOrder\ProviderOrder

The setting had been:

RDPNP,LanmanWorkstation,WebClient,IntelNetProvCredMan,PnSson

and I changed it to:

RDPNP,LanmanWorkstation,WebClient,PnSson,IntelNetProvCredMan

After logging off and logging back on, ssonsvr.exe started successfully, and pass-thru worked!

It appears that you can also change the Provider Order by going into Network Connections. Select Advanced...Advanced settings, then Provider Order tab and move Citrix single sign on higher up.
0
 
LVL 1

Expert Comment

by:jcneil4
ID: 25026598
Thank you zaphod_beeblerox!!!  This has been plaguing me for a long time and i couldnt figure it out!  This worked like a charm ;-)
0

Featured Post

Improve Your Query Performance Tuning

In this FREE six-day email course, you'll learn from Janis Griffin, Database Performance Evangelist. She'll teach 12 steps that you can use to optimize your queries as much as possible and see measurable results in your work. Get started today!

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

As with any other System Center product, the installation for the Authoring Tool can be quite a pain sometimes. This article serves to help you avoid making these mistakes and hopefully save you a ton of time on troubleshooting :)  Step 1: Make sur…
New style of hardware planning for Microsoft Exchange server.
The viewer will learn how to simulate a series of sales calls dependent on a single skill level and learn how to simulate a series of sales calls dependent on two skill levels. Simulating Independent Sales Calls: Enter .75 into cell C2 – “skill leve…
In this video, Percona Solutions Engineer Barrett Chambers discusses some of the basic syntax differences between MySQL and MongoDB. To learn more check out our webinar on MongoDB administration for MySQL DBA: https://www.percona.com/resources/we…

589 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question