Security Basics mailing list archives

RE: Is Citrix safe?


From: "Tuttle, Jim" <Jim.Tuttle () wesd org>
Date: Wed, 4 Jun 2003 14:02:24 -0700

Citrix is not safe. End of story.

You can implement the Citrix Secure Gateway and Transaction Authority
for added protection. Get ready to do some serious group policy work
though. The key is to secure your servers in the farm, set up the CSG,
run it all over 128bit encryption thru your SSL Nfuse gateway.

That's what I do.

Jim Tuttle
Willamette ESD
Network Security Analyst


-----Original Message-----
From: Jesper Sobol [mailto:jesper () sobol dk] 
Sent: Wednesday, June 04, 2003 6:30 AM
To: security-basics () securityfocus com
Subject: Is Citrix safe?


As far as I know, Citrix is based on SSL which is not considered very
safe, but unfortunately I dont know enough about Citrix. Could anyone
please comment on the security in regards to Citrix?

- AAA
- SSL encryption
- Digital Certificates
- Man-in-middle attack

What is the generel opinion, and why? I need arguments for and against
Citrix, if any?

Regards,
Jesper Sobol



------------------------------------------------------------------------
---
------------------------------------------------------------------------
----

---------------------------------------------------------------------------
----------------------------------------------------------------------------


Current thread: