Citrix Cloud - SAML My Page SSO Configuration - RSA Ready Implementation Guide
Originally Published: 2023-03-21
This article describes how to integrate Citrix Cloud with RSA Cloud Authentication Service using My Page SSO.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service using My Page SSO.
Procedure
- Sign in to RSA Cloud Administration Console and navigate to Applications > Application Catalog.
- Click Create From Template and click Select for SAML Direct.
- On the Basic Information page, choose Cloud.
- Enter the name for the application and click Next Step.
- On the Connection Profile page, navigate to the Initiate SAML Workflow section and choose IdP-initiated.
- Scroll down to the Service Provider section and enter the following details:
- Import the metadata and verify that the ACS URL and Service Provider Entity ID are filled correctly.
This metadata file can be obtained from the Citrix Cloud console.
- Import the metadata and verify that the ACS URL and Service Provider Entity ID are filled correctly.
- Scroll down to the Identity Provider section and make a note of the Identity Provider URL. This is required for the Citrix Cloud configuration.
- Proceed with the Default option for Identity Provider Entity ID and Audience for SAML Response.
- Under the Message Protection section, for SAML Response Protection:
- Choose IdP signs entire SAML response.
- Select the Override default signing key and certificate checkbox.
- Click Generate Cert Bundle to generate and download a zip file containing the private key and certificate.
- Unzip the downloaded file to extract the certificate and private key.
- Click the first Choose File option and upload the RSA private key.
- Click the second Choose File option and upload the RSA public certificate
- Scroll down to the User Identity section and select the following:
- Identifier Type: emailAddress
- Property: mail
- In the Statement Attributes section, enter the following attribute names and property values:
- Attribute Name: cip_email, Attribute Source: Identity Source, Property: mail
- Attribute Name: cip_oid, Attribute Source: Identity Source, Property: objectGUID
- Attribute Name: cip_sid, Attribute Source: Identity Source, Property: objectSid
- Attribute Name: cip_upn, Attribute Source: Identity Source, Property: userPrincipalName
- Locate the application you created on the My Applications page and click Edit > Export Metadata.
- Click Publish Changes and wait for the operation to be completed.
After publishing, your application is now enabled for SSO.
Configure Citrix Cloud SSO
Perform these steps to integrate Citrix Cloud with RSA uisng My Page SSO.
Procedure
- Sign in to Citrix Cloud at https://citrix.cloud.com.
- On the Citrix Cloud menu, click Identity and Access Management.
- On the Authentication tab, for SAML 2.0, select Connect. When prompted, enter a short, URL-friendly, identifier for your company and click Save and continue.
- On the Configure SAML page, enter the following:
- Entity ID: Enter the Identity Provider Entity ID from the metadata file downloaded from RSA Cloud Authentication Service.
- SSO Service Provider: Enter the SingleSignOnService URL from the metadata file.
- Binding Mechanism: Select HTTP POST.
- SAML Response: Select Must Sign Response.
- X.509 Certificate: Upload SecurID X.509 certificate downloaded in the previous section.
- Authentication Context: Set Authentication Context as Unspecified, Minimum.
- Logout URL: If required, specify the RSA Portal URL obtained in the previous section to redirect users to the application portal page on logout.
- Download the SAML Metadata file.
- Click Test and Finish.
- Perform the following steps to configure the Workspace Authentication method:
- On the Citrix Cloud menu, click Workspace Configuration.
- Click the Authentication tab and choose SAML 2.0.
- On the Citrix Cloud menu, click Workspace Configuration.
The configuration is complete.
Related Articles
Microsoft Office 365 - RSA Ready Implementation Guide 291Number of Views Microsoft Office 365 - SAML My Page SSO Configuration - RSA Ready Implementation Guide 118Number of Views Microsoft Office 365 - SAML Relying Party Configuration - RSA Ready Implementation Guide 242Number of Views Microsoft Entra ID - SAML My Page SSO Configuration - RSA Ready Implementation Guide 206Number of Views Mandatory Certificate Upgrade Required by 6th October 2025 for RSA MFA Agent for PAM, RSA MFA Agent for Apache, and Third … 300Number of Views
Trending Articles
Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory RSA Authentication Manager 8.9 Release Notes (January 2026) How to factory reset an RSA Authentication Manager 8.x hardware appliance without a factory reset button from the Operatio… Deploying RSA Authenticator 6.2.2 for Windows Using DISM Artifacts to gather in RSA Identity Governance & Lifecycle
Don't see what you're looking for?