Novell SecureLogin 7.0 SP3 User guide

Category
Software
Type
User guide
www.novell.com/documentation
Citrix and Terminal Services Guide
SecureLogin 7.0 SP3
April, 2012
Legal Notices
Novell,Inc.makesnorepresentationsorwarrantieswithrespecttothecontentsoruseofthisdocumentation,andspecifically
disclaimsanyexpressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.
reservestherighttorevisethispublicationandtomakechangestoitscontent,at
anytime,withoutobligationtonotifyany
personorentityofsuchrevisionsorchanges.
Further,Novell,Inc.makesnorepresentationsorwarrantieswithrespecttoanysoftware,andspecificallydisclaimsany
expressorimpliedwarrantiesofmerchantabilityorfitnessforanyparticularpurpose.Further,Novell,Inc.reservestheright
to
makechangestoanyandallpartsofNovellsoftware,atanytime,withoutanyobligationtonotifyanypersonorentityof
suchchanges.
AnyproductsortechnicalinformationprovidedunderthisAgreementmaybesubjecttoU.S.exportcontrolsandthetrade
lawsofothercountries.Youagreeto
complywithallexportcontrolregulationsandtoobtainanyrequiredlicensesor
classificationtoexport,reexportorimportdeliverables.YouagreenottoexportorreexporttoentitiesonthecurrentU.S.
exportexclusionlistsortoanyembargoedorterroristcountriesasspecifiedintheU.S.
exportlaws.Youagreetonotuse
deliverablesforprohibitednuclear,missile,orchemicalbiologicalweaponryenduses.SeetheNovellInternationalTrade
ServicesWebpage(http://www.novell.com/info/exports/)formoreinformationonexportingNovellsoftware.Novellassumes
noresponsibilityforyourfailuretoobtainanynecessaryexportapprovals.
Copyright©20052012
Novell,Inc.Allrightsreserved.Nopartofthispublicationmaybereproduced,photocopied,storedon
aretrievalsystem,ortransmittedwithouttheexpresswrittenconsentofthepublisher.
Novell,Inc.hasintellectualpropertyrightsrelatingtotechnologyembodiedintheproductthatisdescribedinthisdocument.
Inparticular,and
withoutlimitation,theseintellectualpropertyrightsmayincludeoneormoreoftheU.S.patentslistedon
theNovellLegalPatentsWebpage(http://www.novell.com/company/legal/patents/)andoneormoreadditionalpatentsor
pendingpatentapplicationsintheU.S.andinothercountries.
Novell, Inc.
1800 South Novell Place
Provo, UT 84606
U.S.A.
www.novell.com
OnlineDocumentation:Toaccessthelatestonlinedocumentation
forthisandotherNovellproducts,seetheNovell
DocumentationWebpage(http://www.novell.com/documentation).
Novell Trademarks
ForNovelltrademarks,seetheNovellTrademarkandServiceMarklist(http://www.novell.com/company/legal/trademarks/
tmlist.html).
Third-Party Materials
Allthirdpartytrademarksarethepropertyoftheirrespectiveowners.
Contents 3
Contents
About This Guide 7
1 Getting Started 9
1.1 Support on Windows Microsoft Vista . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
1.2 Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .9
1.2.1 Internet Explorer Enhanced Security Configuration. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
1.2.2 Disabling Internet Explorer Enhanced Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
1.3 Installation Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .10
1.4 Overview of Citrix Application Deployment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
1.4.1 Application Modes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
1.4.2 Deploying in Corporate Directory Environments . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
1.4.3 Deploying the Full Citrix Desktop. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
1.4.4 Deploying Published Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .11
1.4.5 Deploying Citrix Desktop and Published Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12
1.5 Novell SecureLogin Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .12
2 Installing Novell SecureLogin on a Citrix Server 13
3 Deploying Citrix Applications 17
3.1 Launching an Application in a Citrix Environment . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.2 Configuring Citrix Load Balancing . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .17
3.2.1 Creating a New Load Evaluator. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
3.2.2 Loading New Load Evaluators to the Citrix Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .18
3.2.3 Deploying Existing Citrix Published Applications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .20
4 Using Connectors 21
4.1 Enabling an Application with Connectors. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .21
4.2 Deleting Connectors. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .22
5 Using NMAS, Secure Workstation, and pcProx with Citrix 23
5.1 Requirements. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .23
5.2 Using NMAS with Citrix . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .23
5.3 Using pcProx with Citrix. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .24
5.4 Using Secure Workstation with Citrix. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .25
6 Setting Terminal Services 27
6.1 Integrating Microsoft Terminal Server and Citrix . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .27
6.2 GINA Credential Pass-Through . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
6.2.1 What Happens when GINA Pass-Through is Working? . . . . . . . . . . . . . . . . . . . . . . . . . . . 28
6.3 Integrating with Citrix Components . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
6.3.1 Windows GINA Authentication. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .29
6.3.2 Program Neighborhood . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
6.3.3 Using Desktop Shortcuts to Published Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .30
6.3.4 Handling Password Changes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
6.4 Virtual Channel. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
4 Contents
6.4.1 Virtual Channel Components. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .31
6.4.2 Auto-Detecting the Client Protocol. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
6.5 Requirements for Terminal Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
6.5.1 Server Requirements. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .32
6.5.2 Workstation Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
6.6 Setting Up the Server. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .33
6.6.1 Setting the GINA . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 33
6.6.2 Configuring OnDemand. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .34
6.7 Setting Up Workstations. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
6.7.1 Novell Client (without the NMAS Client) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
6.7.2 Novell Client (with the NMAS Client). . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .35
6.7.3 Microsoft Workstation with No Novell Client Installed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
6.8 Installing the Virtual Channel Driver. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .36
6.8.1 Workstations with the Citrix Client (ICA) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 36
6.8.2 Workstations with the Terminal Server Client (RDP). . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
6.9 Installing the Terminal Server Web Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
6.10 Integrating with Citrix Published Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
6.10.1 Modifying the Command Line . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .37
6.10.2 Using SLLauncher Syntax . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .38
6.11 Registry Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 38
6.11.1 Auto-Detecting the Client Protocol. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
6.11.2 Servers with a Novell Client. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
6.11.3 Localized Machine. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
6.11.4 Third-Party GINA. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .39
6.12 Debugging Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .40
6.13 Files Installed . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .40
6.13.1 Citrix Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .40
6.13.2 Terminal Services Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
6.13.3 CitrixServer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
6.13.4 Microsoft Terminal Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
6.13.5 Citrix Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .41
7 Upgrading 43
7.1 Issues with Upgrading . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .43
7.1.1 Changes With Encryption . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .43
7.1.2 Issues In Reading Old Data. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .43
7.1.3 Upgrading the Data Store . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
7.1.4 Prompting for a Passphrase During an Upgrade. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
7.1.5 About the New Protection Method. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .44
7.1.6 Adding the New Encryption Algorithm. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 45
7.2 Deployment Options. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .45
7.2.1 Installation Options in a Citrix Environment. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .45
7.2.2 Deploying Existing Citrix Published Applications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .45
7.2.3 Using the Installation Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .46
7.2.4 Deploying in Citrix Desktop Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .46
7.2.5 Deploying Existing Citrix Published Applications. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .46
7.2.6 Citrix Published Applications and the Application Definition Wizard . . . . . . . . . . . . . . . . . .47
7.3 Upgrading from Earlier Versions to Novell SecureLogin 7.0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .47
7.3.1 Restriction on Upgrades . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .47
7.3.2 Upgrading to Novell SecureLogin 7.0 from Novell SecureLogin 3.5.x. . . . . . . . . . . . . . . . .47
7.4 Phased Upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .48
7.5 Hot Desk and Mobile Users . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .48
7.6 Stopping Tree Walking. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .48
7.7 Changing the Directory Database Version. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .49
7.8 Deployment Prerequisites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .49
7.9 Developing a Migration Plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 50
Contents 5
7.9.1 Example of a Migration Plan . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .50
8 Troubleshooting 53
6 Novell SecureLogin Citrix and Terminal Services Guide
About This Guide 7
About This Guide
Thisdocumentprovidesthefollowinginformation:
Chapter 1,“GettingStarted,”onpage 9
Chapter 2,“InstallingNovellSecureLoginonaCitrixServer,”onpage 13
Chapter 3,“DeployingCitrixApplications,”onpage 17
Chapter 4,“UsingConnectors,”onpage 21
Chapter 5,“UsingNMAS,SecureWorkstation,andpcProxwithCitrix,”onpage 23
Chapter 6,“SettingTerminalServices,”onpage 27
Chapter 7,
“Upgrading,”onpage 43
Audience
Thisguideisintendedfor:
NetworkAdministrators
SystemsAdministrators
ITSupportStaff
Feedback
Wewanttohearyourcommentsandsuggestionsaboutthismanualandtheotherdocumentation
includedwiththisproduct.PleaseusetheUserCommentsfeatureatthebottomofeachpageofthe
onlinedocumentation,orgototheNovellDocumentationFeedback(http:// www.novell.com/
documentation/feedback.html)andenteryourcommentsthere.
Documentation Updates
ForthemostrecentversionoftheNovellSecureLoginCitrixandTerminalServicesGuide,visittheNovell
DocumentationWebsite.(http://www.novell.com/documentation/securelogin70/index.html)
Additional Documentation
FordocumentationonotherNovellSecureLogindocumentation,seetheNovellSecureLogin
DocumentationWebsite(h ttp://www.novell.com/documentation/securelogin70).
TheotherdocumentsavailablewiththisreleaseofNovellSecureLoginare:
GettingStarted
NovellSecureLoginReleaseNotes7.0ServicePack3
NovellSecureLoginQuickStartGuide
NovellSecureLoginOverviewGuide
8 Novell SecureLogin Citrix and Terminal Services Guide
Installation
NovellSecureLoginInstallationGuide
Administration
NovellSecureLoginAdministrationGuide
NovellSecureLoginApplicationDefinitionWizardAdministrationGuide
pcProxGuide
EndUser
NovellSecureLoginUserGuide
Reference
NovellSecureLoginApplicationDefinitionGuide
Documentation Conventions
InNovelldocumentation,agreaterthansymbol(>)isusedtoseparateactionswithinastepand
itemsinacrossreferencepath.
1
Getting Started 9
1
Getting Started
NovellSecureLoginintegratestightlywithCitrixandterminalservices,todeliveramoreefficient,
simple,andreliablesinglesignonsolution.
Thisdocumentprovidesinstructionsfordirectoryserversandterminalservers(theCitrixserver
environment).Forexample,aMicrosoftActiveDirectoryserverforuserprovisioningand
managementwiththeapplicationsdeployed
byusingaCitrixserver.
YoumustconfiguretheCitrixandterminalserveranduserworkstationspriortoinstallingNovell
SecureLogin.TheNovellSecureLogininstallationpackagenowdetectsCitrixandterminalserver
filesandinstallstherequiredsupportingfilesautomatically.InscenarioswhereCitrixorterminal
servicesaredeployedafteryour
NovellSecureLoginimplementation,youmustredeploytheNovell
SecureLogininstallationpackagetoinstalltherequiredNovellSecureLogincomponents.
Thissectioncontainsthefollowinginformation:
Section 1.1,“SupportonWindowsMicrosoftVista,”onpage 9
Section 1.2,“Prerequisites,”onpage 9
Section 1.3,“InstallationOverview,”onpage 10
Section 1.4,“OverviewofCitrixApplicationDeployment,”onpage 11
Section 1.5,“Novell
SecureLoginAttributes,”onpage 12
1.1 Support on Windows Microsoft Vista
MicrosoftWindowsVistaisrecognizedasa Citrix andterminalservicesclient.TheInstallCitrixand
terminalservicessupportoptionisdisplayedwheninstallingNovellSecureLogin.
TheMicrosoftWindowsVistaisnotsupportedasaCitrixoraterminalservicesserver.
1.2 Prerequisites
ThefollowingaretheprerequisitesforinstallingNovellSecureLoginonaCitrixandterminal
servicesserver:
ExtendtherelevantenterpriseorcorporatedirectoryschemawiththeNovellSecureLoginsingle
signonattributes.
MakesureyouhaveadministratorlevelaccesstotheCitrixorTerminalServicesserver.
Ifsinglesignonis
requiredforJavaapplications,installSunJavaRuntimeEngine1.3orlater,
andOracleJInitiator1.3.1orlaterontheserverandworkstations.
UninstallallversionsoftheNovellSecureLoginpriortoversion5.5.xupgrade.
10 Novell SecureLogin Citrix and Terminal Services Guide
1.2.1 Internet Explorer Enhanced Security Configuration
ThisinformationappliestotheconfigurationofaserverinaMicrosoftWindowsServer2003
operatingsystemenvironment.
Bydefault,theMicrosoftWindowsServer2003installsInternetExplorerEnhancedSecurity
Configurationdesignedtodecreasetheexposureofenterpriseserverstothepotentialattacksthat
mightoccurthroughWebcontentandapplication
scripts.Becauseofthis,someWebsitesmightnot
displayorperformasexpectedwiththeinstalledNovellSecureLogin.
Formoreinformationonenhancedsecurity,seetheMicrosoftSupportWebsite.(http://
support.microsoft.com/kb/81514/enus)
1.2.2 Disabling Internet Explorer Enhanced Security
IfyouareexperiencingdifficultyaccessingsinglesignonenabledwebpagesfromaWindowsServer
2003server,dooneofthefollowing:
InInternetExplorer,selectTools>InternetOptions>AdvancedtabandundertheBrowsingheading,
selectEnablethirdpartywebbrowserextensions.
or
Usethe
WindowsAdd/RemoveWindowsComponentsontheControlPaneltodisableMicrosoft’s
InternetEnhancedSecurityConfiguration.
1.3 Installation Overview
FollowingarethehighleveltasksoftheCitrixandterminalservicesserverinstallation.
ThedocumentationforinstallingNovellSecureLoginonaCitrixorMicrosoftTerminalServices
coversthedefaultinstallationassumingthatNovellSecureLoginisinstalledonboth,theserverand
ontheworkstation.Ifyouhaveinstallingonlyon
theserverandnotontheworkstation,seeTID
7000523(http://www.novell.com/support/php/
search.do?cmd=displayKC&docType=kc&externalId=70 00523&sliceId=1&docTypeID=DT_T ID_1_ 1&
dialogID=115592134&stateId=00115588299)attheNovellSupportWebsite(http://www.novell.com/
support/microsites/microsite.do).
Inthedefaultinstall,
Slinas.dll
isinstalledontheserver.However,ifNovellSecureLoginisnot
installedontheworkstations,
SlinaC.dll
mustbeinstalledontheserver.
1 UninstallNovellSecureLoginversions5.5.andearlierbeforeupgradingtoNovellSecureLogin
7.0.
2 Extendthecorporatedirectoryschema.
IMPORTANT:Iftheschemawasextendeddu ringthedeploymentofNovellSecureLogin
version3.5orlater,youdonotneedtorepeattheprocess.
Refertotherelevantdirectoryinstallationanddeploymentguideforinstructions.
3 InstallNovellSecureLoginontheCitrixandterminalservicesserver.
Getting Started 11
1.4 Overview of Citrix Application Deployment
Section 1.4.1,ApplicationModes,”onpage 11
Section 1.4.2,“DeployinginCorporateDirectoryEnvironments,”onpage 11
Section 1.4.3,“DeployingtheFullCitrixDesktop,”onpage 11
Section 1.4.4,“DeployingPublishedApplications,”onpage 11
Section 1.4.5,“DeployingCitrixDesktopandPublishedApplications,”onpage 12
1.4.1 Application Modes
YoucandeploytheCitrixapplicationinthe followingmodes:
1.4.2 Deploying in Corporate Directory Environments
Inacorporatedirectoryenvironments,theNovellSecureLogindataisstoredonthedirectory.Thisis
donebyextendingthedirectoryschematoincludeNovellSecureLoginattributes.Forinformationon
extendingthedirectoryschemaforyourdirectory,refertotheNovellSecureLoginInstallationGuide.
NOTE:IfyouhaveinstalledNovellSecureLogin3.5.x,oralaterversion,therequiredSecureLogin
attributesarealreadyinstalled.
1.4.3 Deploying the Full Citrix Desktop
DeployingthefullCitrixDesktoprequiresNovellSecureLoginschemaextensionsonthenetwork
directoryserverandclientinstallationontheCitrixserver.
ThedataofusersoperatingtheNovellSecureLoginandusingtheCitrixserverremotelyisstoredon
theCitrixserverandthenetworkdirectory.
1.4.4 Deploying Published Applications
DeployingpublishedapplicationsrequiresNovellSecureLoginschemaextensionsonthenetwork
directoryserverwiththeclientinstallationontheCitrixserverandtheuserworkstation.
NovellSecureLoginexecutesfromtheworkstationtologintoapplicationspublishedontheCitrix
server.NovellSecureLoginuserdatamustbestoredontheusers
workstationforGINAtoGINA
passthroughunlessNovellSecureLoginisneededforsinglesignonapplicationsthatarerunningon
thatworkstation.
Deployment Description
Deploying the Full Citrix Desktop In this mode of deployment, only the Citrix client runs on the desktop
and all other applications run on the Citrix server.
Deploying Published Applications In this mode of deployment, a combination of applications runs on the
desktop, and some are published by using the Citrix server.
Deploying Citrix Desktop and
Published Applications
Use this mode of deployment to run a full Citrix desktop, or a
combination of Citrix published applications and applications on the
workstation.
12 Novell SecureLogin Citrix and Terminal Services Guide
NOTE:TheSecureLoginApplicationDefinitionWizardcannotdetectCitrixpublishedapplications.
Youmustrunthe applicationonyourworkstationtocreateanapplicationdefinitionusingthe
wizard.
1.4.5 Deploying Citrix Desktop and Published Applications
CitrixDesktopandpublishedapplicationsrequire:
NovellSecureLoginschemaextensiononthenetworkdirectoryserver.
ACitrixserverandauserworkstation.
NovellSecureLoginexecutesfromtheworkstationortheCitrixserver,dependingonthemode
selectedbytheuser.TheNovellSecureLoginuserdataisstoredonthedirectoryserver,
theCitrix
server,andtheuserworkstation.
1.5 Novell SecureLogin Attributes
ExtendingthedirectoryschemaaddsthefollowingSecureLoginattributes:
ProtocomSSOAuthData
ProtocomSSOEntries
ProtocomSSOSecurityPrefs
ProtocomSSOProfile
ProtocomSSOEntriesChecksum
ProtocomSSOSecurityPrefsChecksum
NOTE:IfNovellSecureLogin3.5or3.5.xorlaterisinstalled,youneednotextendtheDirectory
schemabecausetheattributesarethesame.
However,anynewobjects,suchasorganizationalunits,stillrequireyoutoassignrights.
1 Logintotheserverasadministrator.
2 InserttheNovellSecureLoginproductinstallerpackage.Themainmenuisdisplayed.
3 ClickInstall/Upgradeandfollowtheonscreeninstructionsforyourinstallationtype.
4 Doubleclickthe
ndsschema.exe
fileinthe
SecureLogin\Tools|Schema\NDS
folderofthe
installerpackage.TheSecureLogin‐Schemaextensiondialogboxisdisplayed.
5 Extendtheschema.
2
Installing Novell SecureLogin on a Citrix Server 13
2
Installing Novell SecureLogin on a Citrix
Server
Afteryouhavecompletedextendingtheschematotherequireddirectoryobjects,installNovell
SecureLoginsinglesignonapplicationsontheCitrixserver.
Forinformationonextendingtheschema,seeExtendingtheeDirectorySchemaExtendingthe
eDirectorySchema”intheNovellSecureLoginInstallationGuide.
NovellSecureLogincanbeinstalled,configured,and
featuresaddedandremovedbyusing
MicrosoftWindowsinstallercommandlineoptionsandparametersspecifiedinthecommandlineor
specifiedthroughabathfile.FordetailsonNovellSecureLogininstallation,refertotheNovell
SecureLoginInstallationGuide.
NovellSecureLoginrequiresMicrosoftWindowsinstaller3.0orlater,whichshipswithWindows
XP
ServicePack2(SP2)andisalsoavailableasaredistributablesystemcomponentforMicrosoft
WindowsServer2003(32bitsystemsonly).YoucandownloadthisfromtheMicrosoftDownload
Website(http://www.microsoft.com/downloads/Search.aspx?displaylang=en).
NOTE:Theproceduresforinstallingonadministratorworkstationsand userworkstationsarethe
same.
ThefollowingprocedureusestheMicrosoftWindowsVista64bitinstaller.
1 Logintotheworkstationasanadministra tor.
2 Doubleclick
Novell SecureLogin.msi
locatedinthe
SecureLogin\Client\x64
directoryof
theNovellSecureLogininstallerpackage.TheWelcometotheInstallationWizardforNovell
SecureLoginisdisplayed.
14 Novell SecureLogin Citrix and Terminal Services Guide
3 ClickNext.TheLicenseAgreementpageisdisplayed.
4 Acceptthelicenseagreement,thenclickNext.
TheDestinationFolderpageisdisplayed.Bydefault,theprogramissavedin
C:\Program
Files\Novell\SecureLogin\
.Youcanacceptthedefaultfolderorchoosetochange.
Tochange,clickChangeandnavigatetoyourdesiredfolder.
Installing Novell SecureLogin on a Citrix Server 15
5 ClickNext.SelectaDatastoreforSecureLogin(thatis,theinstallationenvironment)pageis
displayed.
IfyouselectNovelleDirectoryasthedatastore,seeInstalling,Configuring,andDeploying
inaNovelleDirectoryEnvironment”intheNovellSecureLoginInstallationGuide.
16 Novell SecureLogin Citrix and Terminal Services Guide
IfyouselectMicrosoftActiveDirectoryasthedatastore,seeInsta llingandConfiguringin
ActiveDirectoryEnvironment”intheNovellSecureLoginInstallationGuide.
IfyouselectMicrosoftADAMasthedatastore,seeConfiguring,Installing,andDeploying
InActiveDirectoryApplicationEnvironment”intheNovellSecureLoginInstallationGuide.
3
Deploying Citrix Applications 17
3
Deploying Citrix Applications
Thissectionhasinformationonthefollowing:
Section 3.1,“LaunchinganApplicationinaCitrixEnvironment,”onpage 17
Section 3.2,“ConfiguringCitrixLoadBalancing,”onpage 17
3.1 Launching an Application in a Citrix Environment
NovellSecureLoginintegrateswithCitrixandterminalservicesandsimplifiesthemethodinwhich
singlesignonsupportisprovidedforpublishedapplications.NovellSecureLogincanbelaunched
withoutmanuallypublishingtheCitrixapplications.NovellSecureLogincanbestartedorshut
downafterauserhasterminatedalltheapplications,which
deliversafarmoreefficient,simple,and
reliablesinglesignonsolutionforanyCitrixandterminalservicesenvironment.
3.2 Configuring Citrix Load Balancing
Asinglesignonoperationimplementedformemoryoptimizationmightresultinclientconnection
dropouts.However,thisdoesnothaveanyadverseimpactonyourCitrixserver,andyoucanresolve
thisbyconfiguringCitrixLoadEvaluatorstoincreasethenumberofallowedpagefaults.
Section 3.2.1,“CreatingaNewLoadEvaluator,”
onpage 17
Section 3.2.2,“LoadingNewLoadEvaluatorstotheCitrixServer,”onpage 18
Section 3.2.3,“DeployingExistingCitrixPublishedApplications,”onpage 20
3.2.1 Creating a New Load Evaluator
1 StarttheCitrixmanagementconsole,thenselectLoadEvaluators.
2 RightclickandselectNewLoadEvaluator.TheNewEvaluatordialogboxisdisplayed.
18 Novell SecureLogin Citrix and Terminal Services Guide
3 SpecifyanamefortheLoadEvaluator,andadescriptionforthenewevaluator.
4 FromtheAvailableRuleslist,selectPageFaultsandPageSwaps,thenclickAdd.
5 FromtheAssignedRuleslists,selectPageFaults.
Thepagedefaultsettingsareconfiguredintherulesettingsection,whichisdisplayedinthe
bottomhalfoftheNewEvaluatordialogbox.
6 SpecifyavalueintheReportfullloadfieldwhenthenumberofpagefaultspersecondisgreater
thanthisvaluefield.
7 SpecifyavalueintheReportfullloadfieldwhenthenumberofpagefaultspersecondiflessthan
orequaltothisvaluefield.
8 FromtheAssignedRuleslist,selectPageSwapstodisplaypageswapsettingsintherulesettings
section.
9 SpecifyavalueintheReportfullloadfieldwhenthenumberofpageswapspersecondisgreater
thanthisvaluefield.
10 SpecifyavalueintheReportfullloadfieldwhenthenumberofpageswapspersecondisless
thanorequaltothisvaluefield.
11 ClickOK.
TherequiredLoadEvaluatorsareconfiguredandareloadedtotheCitrixserveronwhich
NovellSecureLoginisinstalled.
3.2.2 Loading New Load Evaluators to the Citrix Server
1 FromtheCitrixmanagementconsole,selectServers>Citrixservers.
Deploying Citrix Applications 19
2 RightclicktherelevantCitrixservername,thenselectLoadManageServer.TheLoadManage
Server‐<servername>isdisplayed.
3 FromtheAvailableLoadEvaluatorslistbox,selectConfiguredLoadEvaluators.ClickOK.
ThenewLoadEvaluatorsareloadedtotheCitrixserver.
20 Novell SecureLogin Citrix and Terminal Services Guide
3.2.3 Deploying Existing Citrix Published Applications
IfyouareupgradingfromapreviousversionofNovellSecureLogin,youdonotneedtochangethe
SLLauncher.exe
shortcutspreviouslycreatedforpublishedCitrixapplications.NovellSecureLogin
modifiestheexisting
SLLauncher.exe
automaticallysothat
SLLauncher.exe
isashellthatrunsany
commandlinepassedtoit.
TheNovellSecureLogininstallernowautomaticallydetectsthat theinstallationisonaCitrixserver
andpromptsyoutoverifythenewCitrixcomponentstobeinstalled.
IMPORTANT:AfterinstallingSecureLogin,ifyouhavebothpublishedapplicationandpublished
desktopopen,thechangesmadetoSecureLoginonthedesktopisnotreflectedinthepublished
applicationsessionuntilSecureLoginisrestarted.
  • Page 1 1
  • Page 2 2
  • Page 3 3
  • Page 4 4
  • Page 5 5
  • Page 6 6
  • Page 7 7
  • Page 8 8
  • Page 9 9
  • Page 10 10
  • Page 11 11
  • Page 12 12
  • Page 13 13
  • Page 14 14
  • Page 15 15
  • Page 16 16
  • Page 17 17
  • Page 18 18
  • Page 19 19
  • Page 20 20
  • Page 21 21
  • Page 22 22
  • Page 23 23
  • Page 24 24
  • Page 25 25
  • Page 26 26
  • Page 27 27
  • Page 28 28
  • Page 29 29
  • Page 30 30
  • Page 31 31
  • Page 32 32
  • Page 33 33
  • Page 34 34
  • Page 35 35
  • Page 36 36
  • Page 37 37
  • Page 38 38
  • Page 39 39
  • Page 40 40
  • Page 41 41
  • Page 42 42
  • Page 43 43
  • Page 44 44
  • Page 45 45
  • Page 46 46
  • Page 47 47
  • Page 48 48
  • Page 49 49
  • Page 50 50
  • Page 51 51
  • Page 52 52
  • Page 53 53
  • Page 54 54

Novell SecureLogin 7.0 SP3 User guide

Category
Software
Type
User guide

Ask a question and I''ll find the answer in the document

Finding information in a document is now easier with AI