Who We Are
What We Do
Who We Serve
Resources
Connect With an ExpertExplore Our Solutions
Home/Blog & Podcasts/NetScaler SAML Advisory: Check Your Exposure and Apply the Interim Workaround
Blogs·Proactive Assessment and Remediation Guidance for NetScaler SAML Authentication Deployments

NetScaler SAML Advisory: Check Your Exposure and Apply the Interim Workaround

Recommended review and implementation of Citrix crash mitigation controls for environments utilizing SAML authentication.

If your NetScaler uses SAML authentication, apply Citrix's interim responder policy now. If it does not, a two-command check confirms it and you are done.

What is happening

Citrix published Security Update: Guidance for NetScaler SAML Authentication Deployments on October 2, 2026. It recommends a proactive review and a crash mitigation control for any NetScaler that handles SAML authentication.

Community reporting describes the impact: crafted SAML requests crash the NetScaler authentication daemon, nsaaad. After repeated crashes the appliance restarts, and then its HA peer does too. The same reporting says Citrix treats this as a new issue, separate from CTX697096, with a security bulletin and fixed builds planned.

For most organizations, NetScaler Gateway is the front door to Citrix apps and desktops. An authentication outage there is a remote-access outage for every user. The workaround below takes minutes and needs no reboot.

Step 1: Check whether you use SAML

This guidance applies only to NetScaler environments configured for SAML authentication. Two objects matter:

  • add authentication samlAction means NetScaler acts as a SAML Service Provider.
  • add authentication samlIdPProfile means NetScaler acts as a SAML Identity Provider.

Run both commands from the NetScaler CLI:

show runningConfig | grep "add authentication samlAction"
show runningConfig | grep "add authentication samlIdPProfile"

If either command returns an object, continue to Step 2.

If neither returns anything, stop here. Document the result, notify your engineering team, and do not proceed with Steps 2 through 10. No further action is required.

Steps 2 to 6: Create and run the responder policy

The workaround is one responder policy that drops malformed SAML responses sent to /cgi/samlauth before they reach the authentication daemon. You place it in a file, run the file as a batch, and confirm the policy exists.

Step 2: Create the workaround file. Open the editor from the NetScaler shell:

vi /var/saml_protection_v1.txt

Press i to enter INSERT mode, paste the policy from Step 3, then press Esc. Save and exit with :wq. To exit without saving, use :q!.

Step 3: Paste the responder policy. It is a single line. Copy it exactly, with no added line breaks:

add responder policy pol_samlauth_prefixlist_block "HTTP.REQ.URL.PATH.SET_TEXT_MODE(IGNORECASE).EQ(\"/cgi/samlauth\") && (HTTP.REQ.BODY(65536).SET_TEXT_MODE(URLENCODED).SET_TEXT_MODE(IGNORECASE).DECODE_USING_TEXT_MODE.AFTER_STR(\"SAMLResponse=\").AFTER_STR(\"SAMLResponse=\").LENGTH.GT(0) || HTTP.REQ.BODY(65536).SET_TEXT_MODE(URLENCODED).SET_TEXT_MODE(IGNORECASE).DECODE_USING_TEXT_MODE.AFTER_STR(\"SAMLResponse=\").BEFORE_STR(\"&\").B64DECODE.REGEX_MATCH(re#(?is)PrefixList.(\"([^\" ]* ){15}|'([^' ]* ){15})#))" DROP DROP

Step 4: Verify the file contents.

cat /var/saml_protection_v1.txt

Step 5: Run the configuration. From the NetScaler CLI:

batch -f /var/saml_protection_v1.txt

Step 6: Verify the policy was created.

show responder policy pol_samlauth_prefixlist_block

Steps 7 to 9: Bind the policy

A policy does nothing until it is bound. Not every environment has both an AAA VPN virtual server and an authentication virtual server, so apply the bindings that match your architecture.

Step 7: Bind to the AAA VPN virtual server.

bind vpn vserver "<AAA_VSERVER_NAME>" -policy pol_samlauth_prefixlist_block

Step 8: Bind to the authentication virtual server.

bind authentication vserver "<AUTH_VSERVER_NAME>" -policy pol_samlauth_prefixlist_block -type AAA_REQUEST -priority 100

Step 9: Apply the global binding.

bind responder global pol_samlauth_prefixlist_block 100 END -type REQ_OVERRIDE

Then save the running configuration so the policy and its bindings survive a restart:

save ns config

Step 10: Validate and record the result

Confirm the policy exists and shows up in the running configuration with its bindings:

show responder policy pol_samlauth_prefixlist_block
show run | grep pol_samlauth_prefixlist_block

On an HA pair, run the validation on both nodes. Then test a normal SAML sign-in to confirm users are unaffected.

Record the outcome for each appliance:

Item

Response

SAML authentication detected

Yes / No

Workaround applied

Yes / No

AAA vServer updated

Yes / No

Authentication vServer updated

Yes / No

Global binding applied

Yes / No

Validation completed

Yes / No

What this workaround does not do

  • It is not the fix. This is an interim control. Plan to upgrade once Citrix releases fixed builds and its security bulletin.
  • It covers the Service Provider endpoint. The policy matches /cgi/samlauth only. If Step 1 found a samlIdPProfile, ask Citrix Support about protection for the Identity Provider side.
  • It does not tell you what already happened. Check /var/log/messages for nsaaad exit entries and look for core files. If you find crashes, open a case with Citrix Support.

How XenTegra Canada can help

XenTegra Canada is a Citrix Platinum Partner & Preferred Service Delivery Partner. Our engineers work on NetScaler every day, backed by our Global CoE and Global NOC.

If you want a second set of eyes, we can:

  • Run the SAML exposure check across all of your NetScaler appliances
  • Apply and validate the interim workaround in a change window that suits you
  • Review logs for signs of authentication daemon crashes
  • Plan and deliver the upgrade when fixed builds arrive

Contact us at www.xentegracanada.com to book a NetScaler security review.

Sources

← Back to Blog & PodcastsTalk to an Expert