- JaCarta PKI
.. Citrix XenDesktop 7.x.
JaCarta PKI USB-, MicroUSB- - , , .
.. Citrix :
- , XenApp/XenDesktop;
- Netscaler Gateway;
- - USB- VDI Citrix , ;
- Citrix (PKI), PKI Citrix.
Citrix - USB- JaCarta .. (PKI) X.509, . , .
- USB- JaCarta - , , (secure by design).
-
- Microsoft Windows Server 2008 R2 (DC.aladdin.local)
- Microsoft Windows Server 2008 R2 Microsoft Certification Authority (MS CA) (CA.aladdin.local)
- Microsoft Windows Server 2008 R2 () XenDesktop (Citrix Director, Citrix License Server, Citrix Studio, Citrix StoreFront, Citrix Delivery Controller) (XD7.aladdin.local).
- Microsoft Windows 7 64-bit (Test2.aladdin.local)
- Citrix Receiver 4.0.0.45893
- JC Client 6.24.16
- Microsoft Windows 7 32-bit , (win7x32.aladdin.local)
- Citrix Receiver 4.0.0.45893
- JC Client 6.24.16
- Virtual Delivery Agent
1.
. () Windows 7 (32-bit).
Virtual Delivery Agent ( XenDesktop 7.0), JC Client 6.24.16 ( JC Client 6.24.16 JC-Client ), , . .
C
,
Citrix Studio ( Citrix XenDesktop 7.x
http://support.citrix.com/proddocs/topic/xendesktop-71/cds-install-config-intro.html),
Citrix Studio (Start -> All Programs -> Citrix), Citrix Delivery Controller
Machine Catalogs,
Create Machine Catalog (. 1).
. 1 Create Machine Catalog
Next.
Windows Desktop OS - (. 2).
. 2
Next.
Virtual Machines Machine Creation Services (MCS) (. 3).
. 3
Next.
Desktop Experience , (. 4). .
. 4
Next.
(. 5).
. 5
Next.
(. 6).
. 6
Next.
Active Directory (AD) (. 7).
(OU)
AD, .
. 7 Active Directory Computer Account
Next.
, (. 8).
. 8 Summary
Finish.
(. 9).
. 9
2. Delivery Group
, (
Delivery Group).
Citrix Studio Delivery Group ->
Create Delivery Group (. 10).
. 10 Delivery Group
, (. 11).
. 11 Machines
Next.
: (. 12).
. 12 Delivery Type
Next.
, (. 13).
. 13
Next.
Citrix Receiver (. 2.5).
Manually, using a StoreFront server address that I will provide later (. 14).
. 14 Citrix StoreFront
Next.
(. 15).
. 15 Summary
Finish.
(. 16).
. 16 Delivery Group
: , ( Registered (. 17)).
. 17
3.
() . Windows 7 x64 JC Client 6.24.16.
Web- Citrix
XenDesktop:
http://xd7.aladdin.local/Citrix/StoreWeb/ (. 18).
Citrix Receiver , Citrix Receiver (. 19).
.
. 18 Web- XenDesktop
. 19 Citrix Receiver
AD. , 1.2 (. 20).
. 20 Web- XenDesktop
, , (. 21).
( -> )
. 21
-
1. IIS
, XenDesktop 7, Internet Information Services (IIS) (. 22).
. 22 IIS
Server Certificates (. 23).
. 23 IIS
Create Domain Certificate (. 24).
. 24 Create Certificate
(. 25).
Common name XenDesktop. : xd7.aladdin.local.
. 25
Friendly name XenDesktop. :
xd7.aladdin.local (. 26).
. 26 IIS
Finish.
, (. 27).
. 27
2. SSL IIS
Default Web Site Bindings
Add (. 28).
. 28 Site Bindings
https, SSL certificate IIS (. 29).
: xd7.aladdin.local.
. 29 Add Site Binding
OK.
, (. 30).
. 30
Site Bindings.
3. Citrix StoreFront
! StoreFront . , Citrix StoreFront . , (
propagate your configuration changes to the server group).
Citrix Studio. Citrix StoreFront Authentication (. 31).
. 31 StoreFront Authentication
Add/Remove Authentication Methods.
Add/Remove Methods (. 32).
Smart card.
. 32 Add/Remove Authentication Methods
OK.
,
Authentication Smart card (. 33).
. 33
Default Web Site -> Citrix -> Authentication -> Certificate (. 34).
. 34 Certificate Home
SSL Settings -> Require SSL. Require (. 35).
. 35 SSL Settings
SSL- - :
xd7.aladdin.local Citrix XenDesktop.
, (. 36).
. 36
OK.
(. 37).
. 37 PIN- -
PIN- -
OK.
SSL , (. 38).
. 38
Citrix
XenDesktop SSL.
Citrix Studio.
Citrix StoreFront Server Group.
Change Base URL http https (. 39).
. 39 Change Base URL
OK.
Stores (. 40).
. 40 Stores
Manage Delivery Controllers.
Edit (. 41).
. 41 Manage Delivery Controllers
Transport type HTTP HTTPS (. 42, . 43).
. 42 Edit Delivery Controller HTTP
. 43 Edit Delivery Controller HTTPS
OK.
,
Status Service using HTTPS (. 44).
: Citrix XenDesktop.
. 44 Status
4. XML-
XML- Citrix XenDesktop. .
Citrix XenDesktop
Windows PowerShell (. 45).
. 45 Windows PowerShell
:
Set-BrokerSite -TrustRequestsSentToTheXmlServicePort $true (. 46)
. 46 Windows PowerShell
5.
. Citrix Receiver , / (. 47).
. 47 Citrix Receiver
,
Citrix StoreFront (Trusted) (Local Intranet) . ,
Automatic logon with the current user name and password. Internet Explorer 9.0 .
, - USB- , PIN- (. 48).
. 48 Citrix Receiver: PIN- -
PIN- (. 49).
. 49 PIN-
(. 50).
. 50
. .
Win7x32 (. 51).
. 51
Windows PIN- (. 52).
. 52 -
(. 53).
. 53 -
-
1. Single Sing-On - XenDesktop 7
: - , ( ) , Citrix XenDesktop 7 (Delivery Controller, StoreFront .) , , .
Single Sign-on (SSO) - XenDesktop7 .
.
.
Citrix Receiver 4.0 .
Citrix XenDesktop.
IIS SSL IIS.
XML- XenDesktop 7.
Citrix StoreFront 2.1 SSO -.
(. 34).
2. Citrix Receiver 4.0 SSO -.
- Citrix Receiver 4.0 Citrix Receiver 4.0 . Citrix Receiver 4.0 :
- CMD ;
- Citrix Receiver 4.0 SSO: /includeSSON AM_SMARTCARDPINENTRY=CSP; : C:\Distr\CitrixReceiver.exe /includeSSON AM_SMARTCARDPINENTRY=CSP
- Citrix Receiver 4.0 ;
- , - (Task Manager/Processes) ssonsrv.exe;
- Citrix XenDesktop, Citrix , 3.3.
- :
http://support.citrix.com/proddocs/topic/receiver-windows-40/receiver-windows-smart-card-cfg.html. :
To enable single sign-on for smart card authentication, To use CSP PIN prompts.
3. Citrix XenDesktop
Active Directory. .
:
- Active Directory - Citrix ADM Template (Add Template ); Citrix Receiver: C:\Program Files (x86)\Citrix\ICA Client\Configuration\icaclient.adm.
- ( ) -;
- Computer Configuration -> Policies -> Administrative templates -> Classic -> Citrix Components -> Citrix receiver -> User Authentica-tion;
- Smart Card Authentication Allow smart card authentication Use pass-through authentication for PIN. Local User Name and Password Enable pass-through authentication Allow pass-through authentication for all ICA connections (. 54, . 55).
http://support.citrix.com/proddocs/topic/ica-settings/ica-settings-wrapper.html
. 54 AD SSO
. 55 AD SSO
4. Citrix StoreFront 2.1 -
: Citrix StoreFront . , Citrix StoreFront () . , (
propagate your configuration changes to the server group).
Citrix StoreFront SSO - Citrix StoreFront:
- Citrix StoreFront 2.1, - Citrix StoreFront;
- Add/Remove Authentication Methods Domain pass-through (. 56);
. 56
- - . default.ica Citrix Store, -;
- , default.ica, :
C:\inetpub\wwwroot\Citrix\storename\App_Data\;
- NetScaler Gateway,
[Application]: DisableCtrlAltDel=Off.
;
- - NetScaler Gateway :
[Application]: UseLocalUserAndPassword=On; : http://support.citrix.com/proddocs/topic/dws-storefront-21/dws-configure-conf-smartcard.html.
- , (. 2.5). , . , ( - ) PIN- StoreFront / .
VDI ..:
- , ;
- ;
- - USB- ;
- ;
- RSA- -;
- , , ( RFID-), ( MasterCard VISA) ;
-
.
https://habrahabr.ru/post/334322/