Virtual Apps and Desktops FIPS 140-2 Compliance

Virtual Apps and Desktops FIPS 140-2 Compliance

book

Article ID: CTX296901

calendar_today

Updated On:

Description

Looking to verify Citrix Virtual Apps and Desktops is FIPS 140-2 compliant

Resolution

Citrix Virtual Apps and Desktops are compatible with FIPS 140-2 level cipher suites and encryption levels.
  • Users can specify only FIPS level encryption on the Server OS the VDA agent is installed on through Microsoft GPO
  • You can also force locally installed Workspace App to use only FIPS level encryption instead of default open security compliance mode through Microsoft GPO

Problem Cause

FIPS 140-2 level compliance is OS level and must be enforced on that level. Any software installed on top of the OS must comply to be functional.

Additional Information

https://www.citrix.com/content/dam/citrix/en_us/documents/about/fips-140-2-sample-deployments-for-citrix-virtual-apps-and-desktops.pdf

https://docs.microsoft.com/en-US/windows/security/threat-protection/fips-140-validation#using-windows-in-a-fips-140-2-approved-mode-of-operation

https://docs.citrix.com/en-us/citrix-workspace-app-for-windows/secure-communication.html#tls