13.07.2015 Views

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

Client for 32-bit Windows Administrator's Guide - Citrix Knowledge ...

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Go to Document Center Chapter 5 Configuring Features Common to the <strong>Client</strong>s 57Certificate Revocation List CheckingWhen certificate revocation list checking is enabled, the <strong>Client</strong>s check whether ornot the server’s certificate is revoked. This feature improves the cryptographicauthentication of the server running MetaFrame Presentation Server and improvesthe overall security of the SSL/TLS connections between a <strong>Client</strong> and a serverrunning MetaFrame Presentation Server.You can enable several levels of certificate revocation list checking. For example,you can configure the client to check only its local certificate list or to check thelocal and network certificate lists. In addition, you can configure certificatechecking to allow users to log on only if all Certificate Revocation Lists areverified.To enable certificate revocation list checking1. On the server running the Web Interface, locate and open the Template.ica file.2. Configure the SSLCertificateRevocationCheckPolicy setting to one of thefollowing options:• NoCheck - No certificate revocation list checking is per<strong>for</strong>med• CheckWithNoNetworkAccess - The local list is checked• FullAccessCheck - The local list and any network lists are checked• FullAccessCheckAndCRLRequired - The local list and any network listsare checked; users can log on if all lists are verifiedIf you do not set SSLCerticicationRevocationCheckPolicy, it defaults toNoCheck <strong>for</strong> <strong>Windows</strong> NT 4. For <strong>Windows</strong> 2000 Server and <strong>Windows</strong> XP, thedefault setting is CheckWithNoNetworkAccess.User-to-User ShadowingNo client-side configuration is required to use this feature. You shadow a user froma client device using the published Shadow Taskbar.For in<strong>for</strong>mation about using the Shadow Taskbar, see the Shadow Taskbar help. Forin<strong>for</strong>mation about enabling and configuring this feature, see the MetaFramePresentation Server <strong>Administrator's</strong> <strong>Guide</strong>.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!