-

   rss_rss_hh_new

 - e-mail

 

 -

 LiveInternet.ru:
: 17.03.2011
:
:
: 51

:


Citrix XenDesktop 7.x c - JaCarta PKI

, 28 2017 . 09:51 +
- JaCarta PKI .. Citrix XenDesktop 7.x.

JaCarta PKI USB-, MicroUSB- - , , .

.. Citrix :

  • , XenApp/XenDesktop;
  • Netscaler Gateway;
  • - USB- VDI Citrix , ;
  • Citrix (PKI), PKI Citrix.

Citrix - USB- JaCarta .. (PKI) X.509, . , .

- USB- JaCarta - , , (secure by design).

-



  • Microsoft Windows Server 2008 R2 (DC.aladdin.local)
  • Microsoft Windows Server 2008 R2 Microsoft Certification Authority (MS CA) (CA.aladdin.local)
    • JC Client 6.24.16

  • Microsoft Windows Server 2008 R2 () XenDesktop (Citrix Director, Citrix License Server, Citrix Studio, Citrix StoreFront, Citrix Delivery Controller) (XD7.aladdin.local).
    • Citrix XenDesktop 7.0

  • Microsoft Windows 7 64-bit (Test2.aladdin.local)
    • Citrix Receiver 4.0.0.45893
    • JC Client 6.24.16

  • Microsoft Windows 7 32-bit , (win7x32.aladdin.local)
    • Citrix Receiver 4.0.0.45893
    • JC Client 6.24.16
    • Virtual Delivery Agent




1.


. () Windows 7 (32-bit).
Virtual Delivery Agent ( XenDesktop 7.0), JC Client 6.24.16 ( JC Client 6.24.16 JC-Client ), , . .

C

, Citrix Studio ( Citrix XenDesktop 7.x http://support.citrix.com/proddocs/topic/xendesktop-71/cds-install-config-intro.html), Citrix Studio (Start -> All Programs -> Citrix), Citrix Delivery Controller Machine Catalogs, Create Machine Catalog (. 1).


. 1 Create Machine Catalog

Next.

Windows Desktop OS - (. 2).


. 2

Next.

Virtual Machines Machine Creation Services (MCS) (. 3).


. 3

Next.

Desktop Experience , (. 4). .


. 4

Next.

(. 5).


. 5

Next.

(. 6).


. 6

Next.

Active Directory (AD) (. 7).

(OU) AD, .


. 7 Active Directory Computer Account

Next.

, (. 8).


. 8 Summary

Finish.

(. 9).


. 9

2. Delivery Group


, (Delivery Group).

Citrix Studio Delivery Group -> Create Delivery Group (. 10).


. 10 Delivery Group

, (. 11).


. 11 Machines

Next.

: (. 12).


. 12 Delivery Type

Next.

, (. 13).


. 13

Next.

Citrix Receiver (. 2.5).

Manually, using a StoreFront server address that I will provide later (. 14).


. 14 Citrix StoreFront

Next.

(. 15).


. 15 Summary

Finish.

(. 16).


. 16 Delivery Group

: , ( Registered (. 17)).


. 17

3.


() . Windows 7 x64 JC Client 6.24.16.

Web- Citrix XenDesktop: http://xd7.aladdin.local/Citrix/StoreWeb/ (. 18).

Citrix Receiver , Citrix Receiver (. 19).

.


. 18 Web- XenDesktop


. 19 Citrix Receiver

AD. , 1.2 (. 20).


. 20 Web- XenDesktop

, , (. 21).

( -> )


. 21

-



1. IIS


, XenDesktop 7, Internet Information Services (IIS) (. 22).


. 22 IIS

Server Certificates (. 23).


. 23 IIS

Create Domain Certificate (. 24).


. 24 Create Certificate

(. 25).

Common name XenDesktop. : xd7.aladdin.local.


. 25

Friendly name XenDesktop. : xd7.aladdin.local (. 26).


. 26 IIS

Finish.

, (. 27).


. 27

2. SSL IIS


Default Web Site Bindings

Add (. 28).


. 28 Site Bindings

https, SSL certificate IIS (. 29).

: xd7.aladdin.local.


. 29 Add Site Binding

OK.

, (. 30).


. 30

Site Bindings.

3. Citrix StoreFront


! StoreFront . , Citrix StoreFront . , (propagate your configuration changes to the server group).

Citrix Studio. Citrix StoreFront Authentication (. 31).


. 31 StoreFront Authentication

Add/Remove Authentication Methods.

Add/Remove Methods (. 32).

Smart card.


. 32 Add/Remove Authentication Methods

OK.

, Authentication Smart card (. 33).


. 33

Default Web Site -> Citrix -> Authentication -> Certificate (. 34).


. 34 Certificate Home

SSL Settings -> Require SSL. Require (. 35).


. 35 SSL Settings

SSL- - :


xd7.aladdin.local Citrix XenDesktop.

, (. 36).


. 36

OK.

(. 37).


. 37 PIN- -

PIN- - OK.

SSL , (. 38).


. 38

Citrix XenDesktop SSL.

Citrix Studio. Citrix StoreFront Server Group. Change Base URL http https (. 39).


. 39 Change Base URL

OK.

Stores (. 40).


. 40 Stores

Manage Delivery Controllers.

Edit (. 41).


. 41 Manage Delivery Controllers

Transport type HTTP HTTPS (. 42, . 43).


. 42 Edit Delivery Controller HTTP


. 43 Edit Delivery Controller HTTPS

OK.

, Status Service using HTTPS (. 44).

: Citrix XenDesktop.


. 44 Status

4. XML-


XML- Citrix XenDesktop. .

Citrix XenDesktop Windows PowerShell (. 45).


. 45 Windows PowerShell

:

Set-BrokerSite -TrustRequestsSentToTheXmlServicePort $true (. 46)


. 46 Windows PowerShell

5.


. Citrix Receiver , / (. 47).


. 47 Citrix Receiver

, Citrix StoreFront (Trusted) (Local Intranet) . , Automatic logon with the current user name and password. Internet Explorer 9.0 .

, - USB- , PIN- (. 48).


. 48 Citrix Receiver: PIN- -

PIN- (. 49).


. 49 PIN-

(. 50).


. 50

. .

Win7x32 (. 51).


. 51

Windows PIN- (. 52).


. 52 -

(. 53).


. 53 -

-


1. Single Sing-On - XenDesktop 7


: - , ( ) , Citrix XenDesktop 7 (Delivery Controller, StoreFront .) , , .

Single Sign-on (SSO) - XenDesktop7 .

.

.

Citrix Receiver 4.0 .

Citrix XenDesktop.

IIS SSL IIS.

XML- XenDesktop 7.

Citrix StoreFront 2.1 SSO -.

(. 34).

2. Citrix Receiver 4.0 SSO -.


- Citrix Receiver 4.0 Citrix Receiver 4.0 . Citrix Receiver 4.0 :

  • CMD ;
  • Citrix Receiver 4.0 SSO: /includeSSON AM_SMARTCARDPINENTRY=CSP; : C:\Distr\CitrixReceiver.exe /includeSSON AM_SMARTCARDPINENTRY=CSP
  • Citrix Receiver 4.0 ;
  • , - (Task Manager/Processes) ssonsrv.exe;
  • Citrix XenDesktop, Citrix , 3.3.


- : http://support.citrix.com/proddocs/topic/receiver-windows-40/receiver-windows-smart-card-cfg.html. : To enable single sign-on for smart card authentication, To use CSP PIN prompts.

3. Citrix XenDesktop


Active Directory. .

:

  • Active Directory - Citrix ADM Template (Add Template ); Citrix Receiver: C:\Program Files (x86)\Citrix\ICA Client\Configuration\icaclient.adm.
  • ( ) -;
  • Computer Configuration -> Policies -> Administrative templates -> Classic -> Citrix Components -> Citrix receiver -> User Authentica-tion;
  • Smart Card Authentication Allow smart card authentication Use pass-through authentication for PIN. Local User Name and Password Enable pass-through authentication Allow pass-through authentication for all ICA connections (. 54, . 55).


http://support.citrix.com/proddocs/topic/ica-settings/ica-settings-wrapper.html


. 54 AD SSO


. 55 AD SSO

4. Citrix StoreFront 2.1 -


: Citrix StoreFront . , Citrix StoreFront () . , (propagate your configuration changes to the server group).

Citrix StoreFront SSO - Citrix StoreFront:

  • Citrix StoreFront 2.1, - Citrix StoreFront;
  • Add/Remove Authentication Methods Domain pass-through (. 56);


    . 56

  • - . default.ica Citrix Store, -;
  • , default.ica, :
    C:\inetpub\wwwroot\Citrix\storename\App_Data\;
  • NetScaler Gateway,
    [Application]: DisableCtrlAltDel=Off.
    ;
  • - NetScaler Gateway :
    [Application]: UseLocalUserAndPassword=On; : http://support.citrix.com/proddocs/topic/dws-storefront-21/dws-configure-conf-smartcard.html.
  • , (. 2.5). , . , ( - ) PIN- StoreFront / .



VDI ..:

  • , ;
  • ;
  • - USB- ;
  • ;
  • RSA- -;
  • , , ( RFID-), ( MasterCard VISA) ;

  • .
Original source: habrahabr.ru (comments, light).

https://habrahabr.ru/post/334322/


: [1] []
 

:
: 

: ( )

:

  URL