ICA 10.1 Client Adds Support for Client Certificates
Wednesday, 03 October 2007 by Michel Roth
Earlier versions (than 10.1) of the ICA Client had a limitation in the fact that they didn't work properly with an Citrix Access Gateway that required SSL client certificates for client connections. As of version 10.1 this limitations no longer exists. The weird thing is that this bug fix / feature enhancement never made in into the documentation of the 10.1 ICA Client.


Earlier versions (than 10.1) of the ICA Client had a limitation in the fact that they didn't work properly with an Citrix Access Gateway that required SSL client certificates for client connections. As of version 10.1 this limitations no longer exists. The weird thing is that this bug fix / feature enhancement never made in into the documentation of the 10.1 ICA Client.



Jay Tomlin has all the details
: "I'm happy to report that this limitation has been addressed with the release of the Win32 Presentation Server client version 10.1. Somehow this new feature managed to escape the readme.

Access Gateway (any edition) can be set to require a valid client certificate before allowing users to log on, and Access Gateway Enterprise Edition can go further and actually authenticate the user based on the certificate alone. When the option to require a client certificate is enabled, and Web Interface is configured to send Presentation Server clients through the gateway unassisted by a network-layer tunnel, the ICA client must perform its own SSL handshake with the gateway and pump the ICA traffic through that SSL tunnel."

Related Items:

Explaing Certificates On The TS Gateway (15 December 2008)
Certificate Conversion Tool For Secure Gateway Migrations (24 July 2006)
v4.2.1 Hotfix For Citrix Access Gateway (24 February 2006)
Vulnerabilities in Access Gateway Standard and Advanced Editions clients (23 July 2007)
Configuring Remote Access Using Temporary Certificates In Citrix Access Essentials (14 December 2006)
New 8.0 Firmware For Access Gateway Enterprise Edition (3 April 2007)
Clientless Failover Functionality: Citrix Access Gateway and Advanced Access Control (11 May 2006)
Citrix Access Gateway With Advanced Access Control Vulnerabilities (15 November 2006)
Access Gateway Traffic Flow Diagram (13 September 2006)
Citrix Access Gateway Unspecified Information Disclosure Vulnerability (29 January 2007)
Comments (0)