Smartcard Redirection

Overview

This feature enables secure authentication using smart card within HDX sessions on macOS, providing security through hardware-based authentication tokens. The implementation supports both traditional smart card authentication and modern FIDO2 passwordless authentication protocols.

Capabilities

  • Smart card authentication
    • Leverages physical smart card devices for strong authentication.
  • FIDO2 passwordless authentication
    • Support FIDO2 protocol standards for passwordless authentication.

Configuration and Prerequisites

  • USB redirection policy

    • To use this feature, USB redirection policy must be enabled. Additionally, smart card devices must be allowed through USB redirection rules.
  • macOS device pairing

    • Smart card devices must be paired with specific macOS user accounts.

Steps to use smart card for macOS login in HDX session

Pre-requisites

Make sure USB redirection policy is enabled and the smart card device is allowed through USB redirection rules. Make sure the smart card is paired with the specified macOS user account.

  1. Insert smart card: Insert the smart card device into the client machine.

  2. Launch HDX session: Launch an HDX session to a macOS endpoint and wait for the login window to appear.

  3. Redirect smart card: In the CWA (Citrix Workspace App) toolbar, select Devices -> [smart card device name] to redirect the smart card to the HDX session.

  4. Authenticate: Enter the smart card PIN in the macOS login window to complete the authentication and login to macOS.

Note:

SSO feature should be disabled when user use smart card for macOS login in HDX session.

Smartcard Redirection