Using vWorkspace With Private Certificates Part 1: The Quest vWorkspace Windows Client
Monday, 06 July 2009 by Michel Roth
Part of the extensive feature set of Quest vWorkspace is the ability to allow anyone access to vWorkspace hosted applications regardless of their location or client device. To make sure that everyone is able to securely use vWorkspace hosted applications, Quest vWorkspace ships with a SSL Gateway to secure (encrypt) all vWorkspace related traffic.

The Quest SSL Gateway uses a server certificate to secure all vWorkspace related traffic. As you probably know, due to the nature of any certificate infrastructure, the ROOT CA needs to be trusted on the client for the connection to be securely established. In production environments this poses no problem at all since commercial certificates are typically used of which the corresponding ROOT CA typically is already automatically trusted.

In POC or test environments however, commercial certificates are used less often. Quest vWorkspace is perfectly able to deal with these so called “private certificates”.  To use private certificates with the Windows vWorkspace client, the corresponding ROOT CA of the private certificate needs to be trusted on the client. If the client machine is a member of the Windows domain that the ROOT CA is in, then the certificate is automatically trusted. But what if you are connecting from a Windows client that is not in the same domain as the ROOT CA is? In that case, the ROOT CA needs to be trusted by the client (manually). Since obtaining and importing the ROOT CA certificate can be somewhat of a difficult task for the average user, Quest vWorkspace Web Access has the ability to help out here.

One of the features of Quest Web Access is the ability to host any kind of download (next to the vWorkspace client). One way to make it very easy for users to trust the ROOT CA of the Quest SSL Gateway server is to host the ROOT CA certificate on the Quest Web Access download page.

Source: http://blogs.inside.quest.com/provision/2009/07/06/using-vworkspace-with-private-certificates-part-1-the-quest-vworkspace-windows-client/


Related Items:

Two new BETAs available: Quest vWorkspace 6.2 Beta 1 and the Quest vWorkspace Mac AppPortal Beta 1 (13 June 2009)
Explaing Certificates On The TS Gateway (15 December 2008)
How To Use the /autodelete Option With vWorkspace AppPortal (30 June 2009)
Quest vWorkspace wins two SYS-CON Virtualization Journal Readers' awards (28 May 2009)
Take a look at some smooth demo videos of vWorkspace (28 May 2009)
Web Interface Auto Import Private Root Certificate For WI 4 (1 May 2005)
Configuring Remote Access Using Temporary Certificates In Citrix Access Essentials (14 December 2006)
Quest vWorkspace Compatibility Mode and Wyse Thin OS devices (26 June 2009)
Certificate Conversion Tool For Secure Gateway Migrations (24 July 2006)
ICA 10.1 Client Adds Support for Client Certificates (3 October 2007)
Comments (0)