Citrix
1Y0-440 · Question #25
1Y0-440 Question #25: Real Exam Question with Answer & Explanation
Sign in or unlock 1Y0-440 to reveal the answer and full explanation for question #25. The question stem and answer options stay visible for context.
Question
Scenario: A Citrix Architect has deployed an authentication setup with a ShareFile load-balancing virtual server. The NetScaler is configured as the Service Provider and Portalguard server is utilized as the SAML Identity Provider. While performing the functional testing, the architect finds that after the users enter their credentials on the Portalguard page by Portalguard, they get redirected back to the NetScaler Gateway page at url https://authn/fed/sps/login and receive the following error: "SAML Assertion verification failed. Please contact your administrator." The events in the nslog.log file for the issue are as follows: Feb 23 20:20:21 <loca10.err> 10.148.138.5 23/02/2018:20:20:21 GMT vorsb1 0-PPE-0 : default AAATM Message 3225369 0 : "SAML : ParseAssertion: parsed attribute NameID, value is nameid" Feb 23 20:20:21 <loca10.err> 10.148.138.5 23/02/2018:20:20:21 GMT vorsb1 0-PPE-0 : default AAATM Message 3225370 0 : "SAML: verify digest: algorithma differ, expected SHA2, found SHA256" Feb 23 20:20:44 <loca10.err> 10.148.138.5 23/02/2018:20:35:44 GMT vorsb1 0-PPE-0 : default AAATM Message 3225373 0 : "SAML : ParseAssertion: parsed attribute NameID, value is nameid" Feb 23 20:20:44 <loca10.err> 10.148.138.5 23/02/2018:20:35:44 GMT vorsb1 0-PPE-0 : default AAATM Message 3225374 0 : "SAML: verify digest: algorithma differ, expected SHA2, found SHA256" Feb 23 20:20:55 <loca10.err> 10.148.138.5 23/02/2018:20:37:55 GMT vorsb1 0-PPE-0 : default AAATM Message 3225378 0 : "SAML : ParseAssertion: parsed attribute NameID, value is nameid" Feb 23 20:20:55 <loca10.err> 10.148.138.5 23/02/2018:20:37:55 GMT vorsb1 0-PPE-0 : default AAATM Message 3225379 0 : "SAML: verify digest: algorithma differ, expected SHA2, found SHA256" What should the architect change in the SAML action to resolve this issue?
Options
- ASignature Algorithm to SHA 256
- BThe Digest Method to SHA 256
- CThe Issuer NameID to SHA2
- DSignature Algorithm to SHA 1
Unlock 1Y0-440 to see the answer
You've previewed enough free 1Y0-440 questions. Unlock 1Y0-440 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.