Forum Discussion
amolari_4313
Nimbostratus
Jan 24, 2014Citrix ICA file signing
Using APM for XenApp with webtop publishing. The bigip proxies/rewrites the ICA file.
If the requirement would be to configure clients to accept only signed ICA files from a trusted source.. any idea...
Michael_Koyfman
Cirrocumulus
Jan 24, 2014If you deploy APM 11.4.1 HF2 or later, it supports using STA tokens, and thus can be used with ICA signing feature, as ICA file rewrite is not needed in this case. Here is how to do this:
Documentation notes for this feature:
- Prerequisites:
-
Citrix Web Interface (WI) site working in Gateway Direct Mode and published via Citrix Access Gateway (AGEE)
-
Configuring APM
- Virtual Server (VS) is configured to provide ICA Proxy functionality either via iApp or as described in here: http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-citrix-integration-11-3-0.html
- Additional session variable named "session.citrix.sta_servers" must be added to the policy using the "Variable Assign" agent in Visual Policy Editor
- The value of "session.citrix.sta_servers" is the same as you would enter on Web Interface:
So the assignment will normally look like this:
session.citrix.sta_servers = return {http://mysta.company.com/scripts/ctxsta.dll}
- If there is more than one STA server, the individual URLs are delimited by a semicolon
amolari
Cirrostratus
Jan 24, 2014I thought ICA file rewrite was always necessary (change of IP address from internal to VS)...
The solution you describe is for when using WI servers and not publishing Apps on the APM webtop, right? No solution available if I do not want to use the WIs?
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects