Bug ID 523803: Support two-factor authentication for Citrix Receivers in StoreFront proxy mode

Last Modified: Aug 19, 2026

Affected Product(s):
BIG-IP APM(all modules)

Known Affected Versions:
11.6.0, 11.6.0 hf1, 11.6.0 hf2, 11.6.0 hf3, 11.6.0 hf4, 11.6.0 hf5, 11.6.0 hf6, 11.6.0 hf7, 11.6.0 hf8, 11.6.1, 11.6.1 hf1, 11.6.1 hf2, 11.6.2, 11.6.2 hf1, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 11.6.5, 11.6.5.1, 11.6.5.2, 11.6.5.3

Opened: May 18, 2015

Severity: 3-Major

Symptoms

Citrix Receivers do not detect 2-factor authentication when connecting to APM.

Impact

Citrix Receivers do not detect 2-factor authentication.

Conditions

APM is configured as StoreFront proxy and 2-factor authentication is used.

Workaround

To enable 2-factor authentication, put a Variable Assign agent in front of the Logon Page in VPE with the following expression: session.citrix.client_auth_type = expr {"1"}.

Fix Information

None

Behavior Change

Two-factor RSA+AD auth for Citrix Receiver clients now requires a new VPE configuration when APM is configured in StoreFront Integration mode. Note: To avoid a potential issue, if Citrix Receiver was already configured against APM, the Receiver accounts must be recreated.

Guides & references

K10134038: F5 Bug Tracker Filter Names and Tips