SSH control
Citrix Secure Private Access is integrated with Chrome Enterprise Premium to enable secure SSH sessions directly within the browser. This integration enhances security and streamlines access for administrators and users.
Organizations require secure remote administration of SSH-based systems. Traditional methods using standalone SSH clients pose risks by exposing endpoints to unmanaged environments and lacking robust Data Loss Prevention (DLP) enforcement, making compliance challenging.
The SSH sessions are now launched within the Chrome browser instead of standalone SSH clients, reducing dependency on local installations and improving compliance.
Note:
This feature is applicable for Chrome Enterprise Premium integrated Secure Private Access setup for hybrid and cloud deployments. For details, see the following topics:
You must have admin rights to configure Secure Private Access and Chrome Enterprise Premium policies.
Connections to FreeBSD servers are not supported.
Benefits of this integration
This integration offers the following key benefits:
- Enhanced security: Eliminates reliance on unmanaged SSH clients, reducing exposure to security risks.
- Simplified access: Provides browser-native access, removing the need for additional software installations.
- Compliance: Enforces corporate DLP policies directly within the browser, helping meet regulatory requirements.
- Operational efficiency: Reduces IT overhead associated with endpoint management and client deployment.
Use cases
This feature supports various use cases such as:
- Healthcare kiosks: Enables secure SSH access for device troubleshooting without installing native clients.
- IT administration: Allows administrators to securely access Linux servers from managed Chrome browsers with enforced DLP policies.
- Contractor access: Provides temporary SSH access for third-party vendors without compromising the organization’s security posture.
System requirements
Ensure that your environment meets the following requirements:
- Latest version of Chrome Enterprise Premium.
- Citrix Secure Private Access is configured for the integration.
- Access policies to allow SSH traffic must be created in the Secure Private Access admin console.
Prerequisites
Ensure that the following prerequisites are met for enabling secure access to SSH applications:
- Citrix Secure Private Access is configured with Google Chrome Enterprise Premium integration. For details, see Integration with Google Chrome Enterprise Premium.
- The end user has installed the latest Google Chrome browser with the Citrix Secure Access browser extension.
- For the deployment specific prerequisites, see the following topics:
- Cloud deployment - Get started with Citrix Secure Private Access
- Hybrid deployment – System requirements and prerequisites
Configure Secure Private Access for SSH access
- Log in to Citrix Cloud and then click Secure Private Access.
- In the admin console, Click Applications > App Configuration, and then click Add an app.
-
Configure the SSH app as a TCP/UDP app within Secure Private Access.
- The app can have an exact IP address or a range, FQDN, or host name of the server.
- SSH is supported over default and non-default ports.
- Assign access to relevant user groups.
For detailed information on creating a TCP/UDP app, see the following topics.
- Cloud deployment - Support for TCP/UDP apps
- Hybrid deployment – Support for TCP/UDP apps
Configure the SSH policy
- Log in to the Secure Private Access admin console.
- Go to Policies > Browser Policies, and then click Create browser policy.
- Select SSH, and then click Manage.
- Click Add Rule to add rules for the users to enable SSH.
- Enter the name for the rule and click Next.
- Select conditions based on your requirement such as user or group. 1. You can also add conditions such as Geo-location, Network location, and Device posture check.
- Click Next.
- Click Save.
The number of rules configured for the anti-keylogging policy appears in the Browser Policies > SSH tab.