Julian Jakob

@julianjakob.com

Microsoft MVP | Hybrid Cloud Consultant | Blogger at https://www.julianjakob.com

Are you gonna enabling Post-Quantum Cryptography (PQC) with @citrix #NetScaler ? And or also use TLS 1.3 for SSL-Backend-Profile Connections? ❗ See some performance and offloading changes (for SDX / MPX) and a huge recommendation for 14.1 Build 73.30 www.julianjakob.com/netscaler-pe...

NetScaler - Performance Impact for Post-Quantum Cryptography (PQC)

Planning to use Post-Quantum Cryptography (PQC) with NetScaler? See how this impacts your Packet Engine (PE) CPU and how you should size.

julianjakob.com

Microsoft announced a change in Conditional Access via Message Center - I'm talking about Entra's Baseline scope settings enforcement. OIDC Apps like Citrix DaaS or NetScaler might be affected. Checkout: www.julianjakob.com/microsoft-en...

Microsoft Entra - CA Baseline changes affecting Citrix Authentication

Entra ID's Conditional Access is going to enforce Policies which use OIDC baseline scopes, affecting Citrix Applications like DaaS / NetScaler

julianjakob.com

At the moment, public CA SSL/TLS-Certificates use a maximum Lifetime of 199 Days. Until March 2029, it will be reduced to 47 Days. Use Zero-Touch Certificate Management with Auto-Renewal, powered by NetScaler Console or NetScaler Console Service. www.julianjakob.com/netscaler-ze...

NetScaler - Zero Touch Certificate Management (ZTCM)

Learn how to configure a Zero Touch Certificate Management (ZTCM) with NetScaler Console for all your NetScaler's including Auto Renewal.

julianjakob.com

I'm talking about two new Expressions which are using X-Forwarded-For (XFFIP) as a help to get Source-IP informations to protect against Cookie Hijacking with #NetScaler Read more here and why it isn't working out of the box with ICA-Proxy. www.julianjakob.com/netscaler-se...

NetScaler - Session Hijack Protection X-Forwarded-For

Prevent Session-Hijacking of NetScaler's NSC_AAAC / NSC_TMAS Cookie with the simple usage of a Responder Policy with X-Forwarded-For (XFF)

julianjakob.com

Finally, I did some tests with maxing out Windows App for Web (HTML5). In the past, HTML5-based solutions primary were an alternate or fallback possibility to connect to it's EUC-solution, when the main native Client wasn't available. #MVPBuzz www.julianjakob.com/windows-clou...

Windows Cloud - Windows App for Web (HTML5)

Test results from the new Windows App for Web with both AVD and Windows 365 Cloud PC with vGPU, compared to the old HTML5 Portal from AVD.

julianjakob.com

In the past, filtering published Apps visibility on Citrix #DaaS with Entra ID groups was only possible when linked to application groups. Now, you can add the filter on the published app, directly. But watch out regarding a minimum VDA version. www.julianjakob.com/citrix-daas-...

Citrix DaaS - Filtering Published Apps with Entra ID Groups

Using Entra ID groups as a filtering mechanism for published apps on Citrix DaaS can result in failed app launches. Learn why.

julianjakob.com

HEVC (H.265) is finally GA for Azure Virtual Desktop and was also added with additional support in the latest Version of Windows App (2.0.503.0) I did some Tests with Windows 365 and AVD - both with vGPU - comparing EVC (H.264) with HEVC (H.265) #MVPBuzz www.julianjakob.com/windows-clou...

Windows Cloud - AVD and Cloud PC GPU Workload

A Post about some technical Tests with HEVC (H.265) workload with vGPU on both Azure Virtual Desktop and Windows 365 CloudPC.

julianjakob.com

“Try again after some time or contact your help desk” isn't a helpful error-message for Endusers trying to logon to your #NetScaler Gateway or AAA Pages. On the other side, giving to much detailed informations to public is harming your safety. www.julianjakob.com/netscaler-en...

NetScaler - Enhanced Authentication Feedback Template

Using a simple Template for Enhanced Authentication Feedback on NetScaler for better Enduser-Understanding without the lack of Security.

julianjakob.com

1/2 Watch out when using NetScaler integrated WAF for AAA and NSGW: There's an issue (NSCXLCM-7372 - confirmed for 14.1 Build 38.53, but I am able to reproduce it also with 34.42 and 29.72) where WAF configured for "AUTH and VPN" is blocking all NSGW Traffic after a HA-Failover took place.

QQ on Entra ID CBA - why is the User-group filter not working? Everyone get the option to use Cert when enabling CBA (tried include and exclude group filtering) @merill.net any ideas? I don't want all users to be able to use that auth-method on the sign-in page. Thank you

BildBild