Learn how to a build a cloud-first strategyRegister Now

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 870
  • Last Modified:

ICA and SSL

Hi there,

I wanted to confirm my knowledge about ICA and encryption with SSL\TLS.

If my portal web interface used SSL this would encrypt my authentication credentials, however, when I executed a published app this would invoke the ICA protocol from my client and this is not encrypted.

The only way I can see to have ICA encrypted would be to have some sort of VPN (either via an SSL VPN or IPsec or whatever). This would naturally encapsulate my ICA traffic.

Is this basically correct?

Thanks

 
0
58872
Asked:
58872
1 Solution
 
joharderCommented:
Yes, let me explain.

You can use two SSL streams to highly secure your environment.  For external traffic, you should always use some type of VPN, even if it's something as simplistic as Secure Gateway (hey, it's free and it works quite well!).

For internal traffic security, you can put an SSL cert on your WI servers in order to secure XML/STA communications.  This is called SSL Relay and was originally designed and supported for small environments (<5 servers), but sufficed quite nicely to for securing communications between WI and XML service servers/brokers (usually ZDCs).  Even when this is not used (and my guess is that it's only used in maybe 5-10% of deployments), user credentials are obfuscated, which means that they're jumbled and not easily picked off.  Of course, using SSL Relay would be more secure.

Please note that SSL Relay is NOT a substitution for a VPN!  If you have Citrix resources being accessed by external users, you really need at least Secure Gateway!!!
0
 
58872Author Commented:
Many thanks
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now