

Q: Why does the Microsoft IISLockDown Tool break the STA? Q: How should IIS be configured to host the STA? Q: Can I share a Single STA with multiple Farms, Gateways, and Enumeration Servers? Troubleshooting Q: Can I use several STAs with Microsoft Network Load Balancing? Q: Do users logon through the gateway in the morning and run a single published application all day or do they launch several applications throughout the day? Q: How can we set the life time of STA Ticket, after which the ticket should be invalid? Scalability Q: What other information is required to Logon other than a valid STA Ticket?

Q: Can an Attacker send random Tickets to the Gateway to Log On? Q: How do I change the STA port from 80 to something else? Q: Must the STA always be addressed using a Fully-Qualified Domain Name? Q: How do I protect the STA Traffic with SSL? Q: Is it possible for someone to hijack a ticket? Q: Are Tickets ever written to Disk at the STA? Q: Is the Ticket validated against the Workstation? Q: What are the differences among different versions of the STA? Security

Q: Is there a version of the STA that does not require IIS? Q: What Citrix products interact with the STA? The questions are divided into following four categories: Overview This article answers some frequently asked questions regarding the Citrix Secure Ticket Authority (STA). Note: The same principles and concepts holds good for NetScaler Gateway as well.
