13.07.2015 Views

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Go to Document Center Chapter 5 Configuring Features Common to the <strong>Client</strong>s 51Important SSPI requires XML Service DNS address resolution to be enabled <strong>for</strong>the server farm, or reverse DNS resolution to be enabled <strong>for</strong> the Active Directorydomain. For more in<strong>for</strong>mation, see the MetaFrame Presentation Server<strong>Administrator's</strong> <strong>Guide</strong>.Configuring Kerberos AuthenticationThe client, by default, is not configured to use Kerberos authentication whenlogging on to the server. You can set the client configuration to use Kerberos withor without pass-through authentication. Using Kerberos without pass-throughauthentication is more secure than using Kerberos with pass-throughauthentication.• Kerberos without pass-through authenticationWith this configuration the user logs on using Kerberos authentication only. IfKerberos Logon fails <strong>for</strong> any reason, the user is prompted <strong>for</strong> credentials.Kerberos can fail due to a missing operating system requirement, such as therequirement that the server be trusted <strong>for</strong> delegation. This configuration issupported only <strong>for</strong> Web Interface or Custom ICA Connections made throughProgram Neighborhood. For Program Neighborhood Application Sets and theProgram Neighborhood Agent, the user is prompted <strong>for</strong> credentials. Toconfigure Kerberos logon <strong>for</strong> the Web Interface, see the Web Interface<strong>Administrator's</strong> <strong>Guide</strong>.To deploy Kerberos without pass-through authentication, <strong>Citrix</strong> recommendsthat you create a "Kerberos only" client package using the MetaFramePresentation Server <strong>Client</strong> Packager. To create a client package, you can executeAutorun.exe on the Components CD and select the option to Create a custom<strong>Windows</strong> client installation package. During Setup, configure clients to use thelocal name and password <strong>for</strong> logging on and select the option to Use Kerberosonly.Tip During the client packager Setup, you can select dialog boxes that youwant to be displayed to users. You should accept the default configuration thatthe "Single Sign On" dialog box is Hidden. Otherwise, users can override yourconfiguration and set their client configuration to use pass-throughauthentication (single sign-on).You can also configure Kerberos by modifying the settings of the Wfclient.inifile in the <strong>Citrix</strong>\ICA <strong>Client</strong> directory on a client device. For this method ofconfiguration, you must modify Wfclient.ini on each client device <strong>for</strong> whichyou want to use Kerberos without pass-through authentication.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!