Secure

Secure HDX™

Starting with version 2408, Secure HDX is supported. Secure HDX is an Application Level Encryption (ALE) solution that prevents any network elements in the traffic path from being able to inspect the HDX traffic. It does this function by providing true End-to-End Encryption (E2EE) at the application level between the Citrix Workspace™ app (client) and the VDA (session host) using AES-256-GCM encryption.

Prerequisites

The minimum VDA version must be 2503 for this feature to function.

Configurations

Secure HDX is disabled by default. You can configure this feature using the Secure HDX setting in the Citrix policy:

  • Secure HDX: Defines whether to enable the feature for all sessions, only for direct connections, or disable it.

For more information, see Secure HDX in the Citrix DaaS documentation.

Security settings

Citrix® recommends using stores that are secure. Besides, it’s a good practice to have HTTP strict transport security (HSTS) setting enabled for secure stores.

Do the following steps to enable the HSTS setting:

  1. In Citrix StoreFront, under Stores, click the link of the particular store to enable the security settings.
  2. The Manage Receiver for Web Sites dialog box appears.
  3. Click Configure.
  4. The Edit Receiver for Web site dialog box appears.
  5. Click the Advanced Settings tab and select Enable strict transport security.

Security settings

Secure