<?xml version="1.0"?>
<rss version="2.0"><channel><title><![CDATA[Infrastructure & Platform Security Latest Topics]]></title><link>https://community.citrix.com/forums/forum/1628-infrastructure-platform-security/</link><description><![CDATA[Infrastructure & Platform Security Latest Topics]]></description><language>en</language><item><title>Global Deny List in Packet flow diagram</title><link>https://community.citrix.com/forums/topic/258916-global-deny-list-in-packet-flow-diagram/</link><description><![CDATA[<p>Hi,</p><p>In the TechZone article <a rel="" href="https://community.citrix.com/techzone-blogs/netscaler/netscaler-global-deny-list-always-on-protection-for-the-threats-you-havent-modeled-yet-r1254/#2_Unconditional_evaluation_in_the_request_pipeline__3e5a90">NetScaler Global Deny List: Always-on protection for the threats you haven’t modeled yet</a> the following is stated:</p><blockquote class="ipsQuote" cite="" data-ipsquote=""><div class="ipsQuote_contents" data-ipstruncate=""><p><strong>Always evaluated:</strong> Unlike WAF signatures, NetScaler Global Deny List rules are evaluated unconditionally for relevant traffic before requests hit subsequent processing modules. If traffic matches a global deny rule, it is immediately blocked. </p></div></blockquote><p>However, this feature doesn't appear in the Packet Flow diagram in docs (<a rel="external nofollow" href="https://docs.netscaler.com/en-us/citrix-adc/current-release/getting-started-with-citrix-adc#packet-flow">https://docs.netscaler.com/en-us/citrix-adc/current-release/getting-started-with-citrix-adc#packet-flow</a>).</p><p>Have I missed something here? Does this evaluate in the traffic flow in the same place where WAF or somewhere else?</p>]]></description><guid isPermaLink="false">258916</guid><pubDate>Wed, 15 Apr 2026 11:06:35 +0000</pubDate></item><item><title>Automating TLS security hardening</title><link>https://community.citrix.com/forums/topic/258917-automating-tls-security-hardening/</link><description><![CDATA[<p>Hi,</p><p></p><p>Is there a way to unbind all CipherGroups from an SSL Profile without entering it's name? (Or somehow script our way around it)?</p><p>Let's say we have an SSL Profile called <code>ns_default_ssl_profile_frontend</code> and currently we have bound a Cipher Group called <code>comping-cipher-2025-q1</code> and we want to replace it with <code>comping-cipher-2026-q1</code>. This case is easy when we know the name, but if the old cipher is named <code>comping-cipher-2023-q2</code>, the unbind command wouldn't work anymore.</p><p>The target is to homogenize our managed environments and apply similar setup for TLS posture, but the starting point is not ideal. Ideas?</p>]]></description><guid isPermaLink="false">258917</guid><pubDate>Wed, 15 Apr 2026 11:56:40 +0000</pubDate></item><item><title><![CDATA[NetScaler Security Bulletin for CVE 2026-3055 & CVE 2026-4368]]></title><link>https://community.citrix.com/forums/topic/258854-netscaler-security-bulletin-for-cve-2026-3055-cve-2026-4368/</link><description><![CDATA[<p>Hi All,</p><p></p><p>A security bulletin for NetScaler CVE's (CVE 2026-3055 and CVE 2026-4368) has been published here: <a rel="external nofollow" href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300">https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696300</a> There's an associated blog for Global Deny List which was published sometime ago: <a rel="" href="https://community.citrix.com/techzone-blogs/netscaler/netscaler-global-deny-list-always-on-protection-for-the-threats-you-havent-modeled-yet-r1254/">https://community.citrix.com/techzone-blogs/netscaler/netscaler-global-deny-list-always-on-protection-for-the-threats-you-havent-modeled-yet-r1254/</a>. If you see public discussions about CVE's on any public forum such as reddit etc, please point customers to this link, we'll be answering questions here.</p>]]></description><guid isPermaLink="false">258854</guid><pubDate>Mon, 23 Mar 2026 09:38:36 +0000</pubDate></item><item><title>Looking for ACME Support on Citrix ADM/NetScaler On-Prem (14.1)</title><link>https://community.citrix.com/forums/topic/258607-looking-for-acme-support-on-citrix-admnetscaler-on-prem-141/</link><description><![CDATA[<p>Hello everyone,</p><p>I’m looking to automate SSL certificate management on our Citrix NetScaler.</p><p>I’ve read in several posts that Citrix ADM, now called NetScaler Console, uses ACME for certificate renewal. I also found multiple references stating that ACME should be supported starting with release 14.1. However, I couldn’t find any confirmation in the 14.1 release notes that ACME is already available for the on-premises version.<br><br>Release Note: <a rel="external nofollow" href="https://docs.netscaler.com/en-us/updates?product=NetScaler%2520Console%2520on-prem%2520%28ADM%29&amp;version=14.1&amp;build=56.71">https://docs.netscaler.com/en-us/updates?product=NetScaler%2520Console%2520on-prem%2520%28ADM%29&amp;version=14.1&amp;build=56.71</a></p><p>Has anyone gained practical experience using ACME with Citrix ADM/NetScaler Console on-prem, or is this feature still in planning?</p><p>Thank you in advance for your help!</p>]]></description><guid isPermaLink="false">258607</guid><pubDate>Thu, 20 Nov 2025 09:45:29 +0000</pubDate></item><item><title>Questions about existing CCE-AppDS certification</title><link>https://community.citrix.com/forums/topic/258465-questions-about-existing-cce-appds-certification/</link><description><![CDATA[<p>Hello all</p><p>My CCE-AppDS certification is due to expire at the end of the year and I'm trying to understand the current Cloud/Citrix/Netscaler policy for recertifying.</p><p>Previous resources <a rel="external nofollow" href="https://elearning.citrix.com/">https://elearning.citrix.com/</a> and <a rel="external nofollow" href="https://training.citrix.com/">https://training.citrix.com/</a> which contained a bunch of useful information about exams, different available certification paths, preparation resources and docs describing the topics of exams are not available anymore and the only resource I found is <a rel="external nofollow" href="https://www.citrix.com/training-and-certifications/">https://www.citrix.com/training-and-certifications/</a> which contains too few information (or I failed to find it) and doesn't give the clear understanding.</p><p>Also I didn't find a way to ask Cloud/Citrix/Netscaler directly about the questions I worry about, the provided link suggests to ask a question to Webassessor support but I don't think they can answer to questions, not related to exam technical problems. So I'm trying to ask the questions here with the hope the community could help :)</p><ul><li><p>Do I understand correctly "Citrix Certified Expert – App Delivery and Security (CCE-AppDS)" certification doesn't exist anymore and "the top" certificate now is "Citrix Certified Professional – App Delivery and Security (CCP-AppDS)", which previously was just the middle step?</p></li><li><p>Does having actual CCE-AppDS certificate the valid and enough prerequisite for passing CCP-AppDS exam or it's necessary to pass some training (or start from CCA-AppDS)??</p></li><li><p>Which topics are covered by the current CCP-AppDS related exam -  are there the same as "old" CCP-AppDS or "old" CCE-AppDS or it's smth new?  Is it possible to find somewhere the official document with the topics of the current exams like the ones existed previously on Training and E-Learning resources?</p></li></ul><p>Thanks in advance,</p><p>Aleksei</p>]]></description><guid isPermaLink="false">258465</guid><pubDate>Thu, 18 Sep 2025 09:42:15 +0000</pubDate></item><item><title>CVE-2025-5777 on Netscaler software platforms</title><link>https://community.citrix.com/forums/topic/256672-cve-2025-5777-on-netscaler-software-platforms/</link><description><![CDATA[<p>I wanted to know whether the security bulletin published regarding CVE-2025-5777 (<a rel="external nofollow" href="https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX693420&amp;articleTitle=NetScaler_ADC_and_NetScaler_Gateway_Security_Bulletin_for_CVE_2025_5349_and_CVE_2025_5777">CITRIX | Support)</a> also relevant to software platforms like CPX and VPX, or just for physical appliances?</p><p>If it is, is there a plan to publish an updated CPX image for 14.1?</p><p></p><p>Thanks!</p>]]></description><guid isPermaLink="false">256672</guid><pubDate>Tue, 08 Jul 2025 15:32:12 +0000</pubDate></item></channel></rss>
