If your NetScaler uses SAML authentication, apply Citrix's interim responder policy now. If it does not, a two-command check confirms it and you are done.
What is happening
Citrix published Security Update: Guidance for NetScaler SAML Authentication Deployments on October 2, 2026. It recommends a proactive review and a crash mitigation control for any NetScaler that handles SAML authentication.
Community reporting describes the impact: crafted SAML requests crash the NetScaler authentication daemon, nsaaad. After repeated crashes the appliance restarts, and then its HA peer does too. The same reporting says Citrix treats this as a new issue, separate from CTX697096, with a security bulletin and fixed builds planned.
For most organizations, NetScaler Gateway is the front door to Citrix apps and desktops. An authentication outage there is a remote-access outage for every user. The workaround below takes minutes and needs no reboot.
Step 1: Check whether you use SAML
This guidance applies only to NetScaler environments configured for SAML authentication. Two objects matter:
add authentication samlActionmeans NetScaler acts as a SAML Service Provider.add authentication samlIdPProfilemeans NetScaler acts as a SAML Identity Provider.
Run both commands from the NetScaler CLI:
show runningConfig | grep "add authentication samlAction"
show runningConfig | grep "add authentication samlIdPProfile"
If either command returns an object, continue to Step 2.
If neither returns anything, stop here. Document the result, notify your engineering team, and do not proceed with Steps 2 through 10. No further action is required.
Steps 2 to 6: Create and run the responder policy
The workaround is one responder policy that drops malformed SAML responses sent to /cgi/samlauth before they reach the authentication daemon. You place it in a file, run the file as a batch, and confirm the policy exists.
Step 2: Create the workaround file. Open the editor from the NetScaler shell:
vi /var/saml_protection_v1.txt
Press i to enter INSERT mode, paste the policy from Step 3, then press Esc. Save and exit with :wq. To exit without saving, use :q!.
Step 3: Paste the responder policy. It is a single line. Copy it exactly, with no added line breaks:
add responder policy pol_samlauth_prefixlist_block "HTTP.REQ.URL.PATH.SET_TEXT_MODE(IGNORECASE).EQ(\"/cgi/samlauth\") && (HTTP.REQ.BODY(65536).SET_TEXT_MODE(URLENCODED).SET_TEXT_MODE(IGNORECASE).DECODE_USING_TEXT_MODE.AFTER_STR(\"SAMLResponse=\").AFTER_STR(\"SAMLResponse=\").LENGTH.GT(0) || HTTP.REQ.BODY(65536).SET_TEXT_MODE(URLENCODED).SET_TEXT_MODE(IGNORECASE).DECODE_USING_TEXT_MODE.AFTER_STR(\"SAMLResponse=\").BEFORE_STR(\"&\").B64DECODE.REGEX_MATCH(re#(?is)PrefixList.(\"([^\" ]* ){15}|'([^' ]* ){15})#))" DROP DROP
Step 4: Verify the file contents.
cat /var/saml_protection_v1.txt
Step 5: Run the configuration. From the NetScaler CLI:
batch -f /var/saml_protection_v1.txt
Step 6: Verify the policy was created.
show responder policy pol_samlauth_prefixlist_block
Steps 7 to 9: Bind the policy
A policy does nothing until it is bound. Not every environment has both an AAA VPN virtual server and an authentication virtual server, so apply the bindings that match your architecture.
Step 7: Bind to the AAA VPN virtual server.
bind vpn vserver "<AAA_VSERVER_NAME>" -policy pol_samlauth_prefixlist_block
Step 8: Bind to the authentication virtual server.
bind authentication vserver "<AUTH_VSERVER_NAME>" -policy pol_samlauth_prefixlist_block -type AAA_REQUEST -priority 100
Step 9: Apply the global binding.
bind responder global pol_samlauth_prefixlist_block 100 END -type REQ_OVERRIDE
Then save the running configuration so the policy and its bindings survive a restart:
save ns config
Step 10: Validate and record the result
Confirm the policy exists and shows up in the running configuration with its bindings:
show responder policy pol_samlauth_prefixlist_block
show run | grep pol_samlauth_prefixlist_block
On an HA pair, run the validation on both nodes. Then test a normal SAML sign-in to confirm users are unaffected.
Record the outcome for each appliance:
Item
Response
SAML authentication detected
Yes / No
Workaround applied
Yes / No
AAA vServer updated
Yes / No
Authentication vServer updated
Yes / No
Global binding applied
Yes / No
Validation completed
Yes / No
What this workaround does not do
- It is not the fix. This is an interim control. Plan to upgrade once Citrix releases fixed builds and its security bulletin.
- It covers the Service Provider endpoint. The policy matches
/cgi/samlauthonly. If Step 1 found asamlIdPProfile, ask Citrix Support about protection for the Identity Provider side. - It does not tell you what already happened. Check
/var/log/messagesfornsaaadexit entries and look for core files. If you find crashes, open a case with Citrix Support.
How XenTegra Canada can help
XenTegra Canada is a Citrix Platinum Partner & Preferred Service Delivery Partner. Our engineers work on NetScaler every day, backed by our Global CoE and Global NOC.
If you want a second set of eyes, we can:
- Run the SAML exposure check across all of your NetScaler appliances
- Apply and validate the interim workaround in a change window that suits you
- Review logs for signs of authentication daemon crashes
- Plan and deliver the upgrade when fixed builds arrive
Contact us at www.xentegracanada.com to book a NetScaler security review.
Sources
- Security Update: Guidance for NetScaler SAML Authentication Deployments, Citrix Community
- netscaler-ctx697096-checker v1.11 release notes, Thomas Poppelgaard, for crash behavior and workaround scope
