This message was deleted.
# citrix-vad
s
This message was deleted.
d
SecureICA is not the same as ICA over SSL/TLS... if you want to do TLS encryption end to end, ie even for local connections that don't pass through a NetScaler then follow the instructions here. I'd suggest using BIS-F to configure it on non-persistent VDAs. https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/secure/tls.html#tls-settings-on-vdas BIS-F: https://eucweb.com/docs/bisf-7-1912/gpo-configuration/citrix/configure-ssl-for-the-citrix-vda
If your connection passes through a NetScaler, then it will be SSL to the NetScaler, then unencrypted (ie over standard 1494/2598 ports) from the NetScaler to the VDAs
m
I'm not looking to do ICA over TLS. Which is installing certificates on every VDA and sending VDA traffic to Delivery Controllers and clients over TLS. I really just want to do SecureICA, but I'm confused how to validate it is working. It seems to be just a check box on the Delivery Group, but how does one validate it is working? ctxsession -v?
d
Ah ok, you are looking for this then - either in Connection Manager or as you say ctxsession -v
👍 1
r
I have not used SecuraICA in forever. Good to know it's still in use. I do the ICA of TLS now or try to.
m
For now, my standards dictate to use SecureICA. I'm looking at ICA over TLS for my MCS clones, but man, it scares me the same way FAS does. I should note when I run ctxsession -v on Win10 XenDesktops, the ICA Encryption field does not exist. But Daniel's last reply was exactly what I was looking for.
👍 1
d
We do lots of ICA over TLS for end to end SSL in defence and finance & banking environments etc, adds some extra considerations around HA for PKI that people might not have considered previously but overall not much changes.