ICA Basic Encryption FAQ (without the Secure ICA option pack)
ICA Basic Encryption FAQ (without the Secure ICA option pack) ICA Basic Encryption FAQ (without the Secure ICA option pack)
Citrix states in their article: CTX155541
CTX155541 - ICA Basic Encryption FAQ (without the Secure ICA option pack)
This document was published at: http://support.citrix.com/kb/entry.jspa?externalID=CTX155541
Document ID: CTX155541, Created on: Dec 12, 2000, Updated: Apr 23, 2003
Products: Citrix MetaFrame 1.8 for Microsoft NT 4.0 Server Terminal Server Edition, Citrix MetaFrame 1.8 for Microsoft Windows 2000, Citrix WinFrame 1.8
Basic Encryption Questions and Answers:
Basic encryption is better defined as "scrambling." It is available in each of our ICA Clients (except our Web Client) over any transport to remove "clear text" from the line (although there is no real clear text in the protocol). The algorithm is simple and exportable, but for security conscious groups it is not a secure solution. Hardware authentication devices such as SecureID or VPN software such as Citrix Extranet are recommended if SecureICA is unavailable.
Will removing the Disable Encryption After Login check box (Advanced WinStation Configuration) cause all data for the entire session to be encrypted?
Yes.
What type of encryption is actually occurring when encryption is set to Basic?
It's a very "light" encryption of our own design. It's not meant to be secure. It just provides some protection against a snooper program on the network scanning for user names and passwords.
Is the ICA protocol comparable to the SSL protocol?
The encryption used is not comparable. SSL does try to be secure, wheres Basic encryption only "scrambles" data.
Does the ICA protocol have a specific key sequence for the encryption? 40-bit? 128 bit?
It does have a small key in the sense that the same data is encrypted differently each time. However, the encryption is simple and permits export without restrictions.
Does the encryption hinder the performance of the session across a dial-up line?
Yes, minimally. It adds a little to the amount of data on the wire and some extra CPU processing at both ends. It is not noticeable except on very slow clients.
NOTE: If you want to secure your data from any determined attack, the Basic encryption currently in the ICA protocol will not help you. You must install SecureICA for the server and clients, which is available for WinFrame 1.7 or MetaFrame 1.0 and higher. For WAN links, use VPN software such as Citrix Extranet to create a secure communication.
User login
Who's new
- Preatercelepe
- Kxtuzjgv
- Maitacewwisat
- abnonsoks
- themopoty