Jump to content

Secure HDX

Secure HDX is an Application Level Encryption (ALE) solution that prevents any network elements in the traffic path from being able to inspect the HDX traffic. It does this by providing true End-to-End Encryption (E2EE) at the application level between the Citrix Workspace app (client) and the VDA (session host) using AES-256-GCM encryption. Secure HDX is disabled by default and can be enabled via Citrix policy.

Prerequisites:

The following are the requirements to use Secure HDX within Citrix environments:

  • Citrix DaaS or Citrix Virtual Apps and Desktops 2402+
  • Virtual Delivery Agents - Windows 2402 or later/Linux 2402 or later
  • Citrix Workspace app 2402 or later
  • Citrix Workspace or Citrix StoreFront 2402 or later

Why enable Secure HDX?

Secure HDX enabled administrators to securely maintain the data in transit when users are within their Citrix sessions, even when the network is not controlled. This can prevent bad actors and intermediary devices from looking at your enterprise data, even using NetScaler Gateway or the Citrix Gateway service.

Enable Secure HDX

Secure HDX is enabled via Citrix Policy.

  1. From Citrix Web Studio, go to Policies > Create Policy.
  2. Go to ICA > Secure HDX.
  3. Click Edit.
  4. Uncheck "Use default value: Disabled" and select Enabled from the drop-down menu.
  5. Click Save.
  6. Click Next, and choose how to apply the policy, either All users and computers or Filtered users and computers, using the following options:
    1. Delivery Group
    2. Delivery Group type
    3. Organizational Unit (OU)
    4. Tag
  7. Click Next, provide a name for the Policy, and click Finish.

Confirm Secure HDX is Active

To validate that Secure HDX is active within your Citrix session, use ctxsession.exe utility on the VDA machine.

  1. Open a command prompt
  2. Run ctxsession.exe -v
  3. When the results are displayed, look for ICA Encryption: SecureHDX AES-256 GCM

image.png

References

Secure HDX Product Documentation


User Feedback

There are no reviews to display.


×
×
  • Create New...