Jump to content

Citrix ADC 13.0 Oauth 2.0 as SDP - Invalid State value


Groupe HISI

Recommended Posts

Hi,

 

We have deployed a Citrix ADC 13.0 as SDP configured to be connected to a IdP ProSante Connect.

 

We have an issue with the State Value, after we are connected to the IdP with the smart card we have an error : Invalid State Value Presented

 

The IdP support ask us to :

 

- Reduce the size of the State Value

- Add the parameter "nonce"

 

We dont find how to do that in Citrix ADC.

 

In ns.log we have this error :

 

"AAA Client Handler: Found extended erro
r code 1310727, ReqType 16386 request /oauth/login?state=b2F1dGhhY3Q9QU5TLVBTQy1CQUMAGrwcQQIzs210YXJnZXQ9aHR0cHM6Ly9hbnMtcG9jLXBzYy1jaXRyaXguZ3JvdXBlaGlz
aS5mci9uZi9hdXRoL2RvT0F1dGg%2FYWN0PUFOUy1QU0MtQkFDO25mPTt3dj0w&session_state=9b156bcc-446e-42e9-a951-7773b520d944&code=33936e71-ca57-4977-9a58-44b7bc0b22
6d.9b156bcc-446e-42e9-a951-7773b520d944.cded1005-2a09-4cc6-9fdf-60174942b968"

 

 

Any helps are welcome.

 

Regards,

Link to comment
Share on other sites

  • 1 year later...
On 4/19/2022 at 12:59 PM, Groupe HISI said:

Hi,

 

We have deployed a Citrix ADC 13.0 as SDP configured to be connected to a IdP ProSante Connect.

 

We have an issue with the State Value, after we are connected to the IdP with the smart card we have an error : Invalid State Value Presented

 

The IdP support ask us to :

 

- Reduce the size of the State Value

- Add the parameter "nonce"

 

We dont find how to do that in Citrix ADC.

 

In ns.log we have this error :

 

"AAA Client Handler: Found extended erro
r code 1310727, ReqType 16386 request /oauth/login?state=b2F1dGhhY3Q9QU5TLVBTQy1CQUMAGrwcQQIzs210YXJnZXQ9aHR0cHM6Ly9hbnMtcG9jLXBzYy1jaXRyaXguZ3JvdXBlaGlz
aS5mci9uZi9hdXRoL2RvT0F1dGg%2FYWN0PUFOUy1QU0MtQkFDO25mPTt3dj0w&session_state=9b156bcc-446e-42e9-a951-7773b520d944&code=33936e71-ca57-4977-9a58-44b7bc0b22
6d.9b156bcc-446e-42e9-a951-7773b520d944.cded1005-2a09-4cc6-9fdf-60174942b968"

 

 

Any helps are welcome.

 

Regards,

 

 

Did u find the issue?

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...