Posted on 2011-09-27
Last Modified: 2012-05-12
Hi there,

I wanted to confirm my knowledge about ICA and encryption with SSL\TLS.

If my portal web interface used SSL this would encrypt my authentication credentials, however, when I executed a published app this would invoke the ICA protocol from my client and this is not encrypted.

The only way I can see to have ICA encrypted would be to have some sort of VPN (either via an SSL VPN or IPsec or whatever). This would naturally encapsulate my ICA traffic.

Is this basically correct?


Question by:58872
LVL 15

Accepted Solution

joharder earned 500 total points
ID: 36714104
Yes, let me explain.

You can use two SSL streams to highly secure your environment.  For external traffic, you should always use some type of VPN, even if it's something as simplistic as Secure Gateway (hey, it's free and it works quite well!).

For internal traffic security, you can put an SSL cert on your WI servers in order to secure XML/STA communications.  This is called SSL Relay and was originally designed and supported for small environments (<5 servers), but sufficed quite nicely to for securing communications between WI and XML service servers/brokers (usually ZDCs).  Even when this is not used (and my guess is that it's only used in maybe 5-10% of deployments), user credentials are obfuscated, which means that they're jumbled and not easily picked off.  Of course, using SSL Relay would be more secure.

Please note that SSL Relay is NOT a substitution for a VPN!  If you have Citrix resources being accessed by external users, you really need at least Secure Gateway!!!

Author Closing Comment

ID: 36715649
Many thanks

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Citrix on an ipad 13 20
Citrix receiver on windows 7 8 74
Mac Printer driver substitution in XenApp 7.6 5 56
Citrix receiver 4.3 half of the second monitor is half black 2 50
#Citrix #XenApp #Citrix Scout #Citrix Insight Services #Microsoft VMMAP #Microsoft ADEXPLORE #Microsoft RAMMAP #Microsoft TCPVIEW #Microsoft AUTORUNS #Microsoft PROCESS EXPLORER #Microsoft PROCESS MONITOR
If your vDisk VHD file gets deleted from the image store accidentally or on purpose, you won't be able to remove the vDisk from the PVS console. There is a known workaround that is solid.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

910 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now