17
Security Features
Secure Sockets Layer/Transport Layer Security support. The Web Interface supports the
Secure Sockets Layer (SSL) protocol to secure communication between the Web Interface
server and server farms. Implementing SSL on your Web server together with Web browsers
that support SSL ensures the security of data as it travels through your network. The Web
Interface uses Microsoft .NET Framework to implement SSL and cryptography.
Access Gateway support. Citrix Access Gateway is a universal SSL virtual private network
(VPN) appliance that, together with the Web Interface, provides a single, secure point of
access to any information resource—both data and voice. The Access Gateway combines the
best features of Internet Protocol Security (IPSec) and SSL VPN without the costly and
cumbersome implementation and management, works through any firewall, and supports all
resources and protocols.
Secure Gateway support. Secure Gateway, together with the Web Interface, provide a
single, secure, encrypted point of access through the Internet to servers on your internal
corporate networks. Secure Gateway simplifies certificate management because a server
certificate is required only on the Secure Gateway server, rather than on every server in
the farm.
Smart card support. The Web Interface supports the use of smart cards for user
authentication to provide secure access to applications, content, and desktops. Using smart
cards simplifies the authentication process for users while at the same time enhancing
logon security.
Ticketing. This feature provides enhanced authentication security. The Web Interface
obtains tickets that authenticate users to resources. Tickets have a configurable expiration
period and are valid for a single logon. After use, or after expiration, a ticket is invalid and
cannot be used to access resources. Use of ticketing eliminates the explicit inclusion of
credentials in the .ica files that the Web Interface uses to connect to resources.
Secure Ticket Authority redundancy. You can configure multiple redundant Secure Ticket
Authorities (STAs) for users accessing their resources through the Access Gateway. This
enables you to mitigate against the possibility of the STA becoming unavailable midway
through a user’s session, preventing reconnection to the session. When redundancy is
enabled, the Web Interface attempts to obtain and deliver to the gateway two tickets from
two different STAs. If one of the STAs cannot be contacted during a user session, the
session continues uninterrupted using the second STA.
Change password. Users logging on to the Web Interface or the Citrix online plug-in using
explicitly supplied domain credentials have the option of changing their Windows password
if it expires. Users can change their password regardless of whether or not their computer is
in the domain to which they are attempting to authenticate.
Account self-service. Integration with the account self-service feature available in Citrix
Password Manager enables users to reset their network password and unlock their account
by answering a series of security questions.