LIMITED RELEASE - Hotfix XA600R02W2K8R2X64042 - For Citrix XenApp 6.0 for Windows Server 2008 R2 - English

LIMITED RELEASE - Hotfix XA600R02W2K8R2X64042 - For Citrix XenApp 6.0 for Windows Server 2008 R2 - English

book

Article ID: CTX138890

calendar_today

Updated On:

Description

Hotfix package name: XA600R02W2K8R2X64042.MSP
For: Computers running Windows Server 2008 R2 with Citrix XenApp 6, Hotfix Rollup Pack XA600W2K8R2X64R02 installed
Replaces: XA600R02W2K8R2X64004, XA600R02W2K8R2X64016, XA600R02W2K8R2X64024
Date: December, 2013
Languages supported: English (US), German (DE), Spanish (ES), French (FR), Japanese (JA), Simplified Chinese (SC)
Readme version: 1.01

Readme Revision History

VersionDateChange Description
1.01June, 2015Modified description of #LA0983
1.00December, 2013Initial release

Important Notes about This Release

  • Note: As a best practice, Citrix recommends that you install this and other hotfixes only if you are affected by the specific issues they resolve. Otherwise, Citrix recommends that you wait for the next hotfix rollup pack for your product release. Hotfix rollup packs consolidate most previously released hotfixes and allow you to update systems in a convenient, single installation.
  • Important: Installing this hotfix over an ICA session is not supported but you can install it through a remote desktop session using an administrator account.
  • Caution! This release may require you to edit the registry. Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Citrix cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk.

Important Disclaimer - Limited Release Hotfix

If the Download link is not available on this page and you wish to obtain this limited distribution release, visit our support site at http://www.citrix.com/support and open a support case using your Citrix account credentials, or contact your reseller at http://www.citrix.com/partners/locator.

Testing of this release was targeted only at the affected functionality, and regression and stress testing were minimal. Introduce this release to a test environment for evaluation before deploying it to a production environment.

TO THE EXTENT PERMITTED BY APPLICABLE LAW, CITRIX AND ITS SUPPLIERS MAKE AND YOU RECEIVE NO WARRANTIES OR CONDITIONS, EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE, AND CITRIX AND ITS SUPPLIERS SPECIFICALLY DISCLAIM WITH RESPECT TO THE HOTFIX ANY CONDITIONS OF QUALITY, AVAILABILITY, RELIABILITY, SECURITY, LACK OF VIRUSES, BUGS OR ERRORS, OR SUPPORT AND ANY IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, ANY WARRANTY OF TITLE, QUIET ENJOYMENT, QUIET POSSESSION, MERCHANTABILITY, NONINFRINGEMENT, OR FITNESS FOR A PARTICULAR PURPOSE. TO THE EXTENT PERMITTED BY APPLICABLE LAW, NEITHER CITRIX, NOR ITS SUPPLIERS SHALL BE LIABLE FOR ANY DIRECT, INDIRECT, SPECIAL, CONSEQUENTIAL, INCIDENTAL, MULTIPLE, PUNITIVE OR OTHER DAMAGES (INCLUDING, WITHOUT LIMITATION, DAMAGES FOR LOSS OF DATA, LOSS OF INCOME, LOSS OF OPPORTUNITY, LOST PROFITS, COSTS OF RECOVERY OR ANY OTHER DAMAGES), HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, AND WHETHER OR NOT FOR BREACH OF CONTRACT, NEGLIGENCE OR OTHERWISE, AND WHETHER OR NOT CITRIX, ITS SUPPLIERS, OR LICENSORS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Where to Find Documentation

This document describes the issue(s) resolved by this release and includes installation instructions. For additional product information, see Citrix Product Documentation.

New Fixes in This Release

  1. When using smart card authentication, sites in the Intranet zone do not prompt for credentials and fail to load if protected mode is enabled for the Intranet zone. To enable this fix, you must set the following registry keys:

    • On 32-bit Windows
      HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\SmartCard
      Name: SupLowIntegrityProc
      Type: REG_DWORD
      Data: 1
    • On 64-bit Windows
      HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Citrix\SmartCard
      Name: SupLowIntegrityProc
      Type: REG_DWORD
      Data: 1

    [From XA600R02W2K8R2X64042][#LA4501]

Fixes from Replaced Hotfixes

  1. A smart card cannot be read if a published desktop gets locked.

    To enable this fix, you must create the following registry key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\SmartCard
    Name: EnableCtxCleanup
    Type: REG_DWORD
    Data: 1

    [From XA600R02W2K8R2X64004][#LA2343]

  2. Sessions can become unresponsive when smart card services are running but no smart card reader is present.

    [From XA600R02W2K8R2X64016][#LA3469]

  3. Improperly terminated smart card transactions can leave orphaned sessions running on the server and cause new sessions to become unresponsive during logon. Several processes (winlogon.exe, csrss.exe, and logonui.exe) keep running in the orphaned sessions.

    To enable the fix, you must set the following registry keys:

    HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\SmartCard
    Name: TransactionTimeoutEnable
    Type: REG_DWORD
    Value: 1 (enable)

    HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\SmartCard
    Name: TransactionTimeoutValue
    Type: REG_DWORD
    Value: <this value should be at least 10 seconds more than the transactionTimeoutValue>

    HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\SmartCard
    Name: SendRecvTimeout
    Type: REG_DWORD
    Value: Minimum timeout value, in seconds; should be 30 seconds or more. Any lesser value defaults to 30 seconds. This value must be at least 10 seconds more than "TransactionTimeoutValue".

    [From XA600R02W2K8R2X64024][#LA0983]

  4. Two-factor USB token authentication for smart cards might fail with the following error message:

    "System could not log you on, requested key container does not exist on smart card."

    [From XA600R02W2K8R2X64024][#LA3620]

  5. The smart card tile might fail to appear after dismissing the Windows logon banner message. As a result, only the option of "Other User" is available for users to select.

    [From XA600R02W2K8R2X64024][#LA4001]

Installing and Uninstalling This Release

Notes:

  • This hotfix is packaged with Microsoft Windows Installer 3.0 as a .msp file. For more information about deploying .msp files, see Microsoft article 884016 or visit the Microsoft Web site and search on keyword msiexec.
  • This installer program complies with Microsoft User Account Control (UAC). If UAC is enabled, you must run the installer program in elevated mode; that is, with administrative privileges enabled. For more information about UAC, see Microsoft TechNet or visit the Microsoft Web site and search on keyword UAC.
  • To install this hotfix successfully, servers must not have registry modification restrictions in place.
  • Slipstreaming - installations of the XenApp Server base product packaged with one or more individual hotfixes - is not supported and might leave servers in an unstable state.
  • You must restart the server after the installation of this hotfix completes. However, if you are installing multiple hotfixes at the same time, there is no need to restart the server after the installation of each hotfix. It is sufficient to restart the server after the installation of the final hotfix completes.
  • If the need arises to restore the original settings and functionality provided by this hotfix, you must uninstall the hotfix before reinstalling it according to the installation instructions below.

To install this hotfix:

  1. Copy the hotfix package to an empty folder on the hard drive of the server you want to update.
  2. Close all applications.
  3. Run the executable.
  4. Restart the server. This ensures that the installation completes and that the hotfix is added to the hotfix inventory list of the Delivery Service Console.

To uninstall this hotfix:

  1. From the Start menu, select Control Panel > Programs and Features.
  2. Highlight the hotfix you want to uninstall and click Uninstall.
  3. Follow the directions on-screen.

Files Updated (All Dates/Times UTC)

File Name

Date

Time

Size

complus_ca.dll
08/29/2013
17:06
841,128
CPatch.exe
08/29/2013
17:06
444,328
Cpatchbackup_Files.vbs
08/29/2013
17:06
3,082
CpatchRestore_Files.vbs
08/29/2013
17:06
3,537
CtxHfLoader.dll
08/29/2013
17:06
288,728
ctxsfoinst_ca.dll
08/29/2013
17:06
194,488
CtxSmartCardSvc.dll
08/29/2013
17:05
1,684,712
IcaperfCustomActions.dll
08/29/2013
17:06
103,864
ima_msi_ca.dll
08/29/2013
17:06
1,218,480
mf_mm_ca.dll
08/29/2013
17:06
2,954,656
msi50ca.dll
08/29/2013
17:06
432,080
Parra_RunTime_Xml.xml
08/29/2013
17:06
1,354
scardhook64.dll
08/29/2013
17:05
1,581,288
Error.idt (en)
08/29/2013
17:06
35,850
CtxSmartCardSvc.dll (x32)
08/29/2013
17:05
884,456
scardhook.dll (x32)
08/29/2013
17:05
831,208
CPatchUI.dll (x32\de)
08/29/2013
17:06
13,232
CPatchUI.dll (x32\en)
08/29/2013
17:06
12,720
CPatchUI.dll (x32\es)
08/29/2013
17:06
13,744
CPatchUI.dll (x32\fr)
08/29/2013
17:06
13,744
CPatchUI.dll (x32\ja)
08/29/2013
17:06
11,696
CPatchUI.dll (x32\zh-cn)
08/29/2013
17:06
11,184
 
File Name

MD5 Checksum

XA600R02W2K8R2X64042.msp
D83FAF9B23E8E20D7902A840133F953A
complus_ca.dll
828AC9897B8D6BE445372742FCBC76CA
CPatch.exe
E0130509E4A61B8E225AB4DCE121BA8F
Cpatchbackup_Files.vbs
0EB9234E7FF2ED9E72337FF26F46AE0E
CpatchRestore_Files.vbs
F64D03B0DC4D0137C3A101B31084D880
CtxHfLoader.dll
1ECC53C0D7C97BE04EEC0F8F1CE3F353
ctxsfoinst_ca.dll
BAC7527CBD92FD0B4F5B495DDAAA32C8
CtxSmartCardSvc.dll
03A727AF108E653652C822D7591BA7E2
IcaperfCustomActions.dll
11D4A91E8FB2BB274838C45250AB727E
ima_msi_ca.dll
98F1E1808E1922B85B1AEF3B7174FEE4
mf_mm_ca.dll
A9225A273854EE0D43C0B4DE3F58FABD
msi50ca.dll
5075A9961245798FF95E678DB455C43C
Parra_RunTime_Xml.xml
149B41A05D92BFF44C6A26EFAFA99724
scardhook64.dll
7D317DCB7A7AC71892C0954390138D55
Error.idt (en)
48633A51D4A647553FFABC72739AAB33
CtxSmartCardSvc.dll (x32)
0E2BCE101A06AF53CB355817E2AA0D13
scardhook.dll (x32)
5AD4DF20317A6E18428B25609E208744
CPatchUI.dll (x32\de)
1E3916C350F8BFF385A1DE5220456555
CPatchUI.dll (x32\en)
7500103A935F0D723C461F49A70FBB60
CPatchUI.dll (x32\es)
417641F83EE48F58FB5BCA333AE9B41D
CPatchUI.dll (x32\fr)
541F401CBCFF1734A81C78FC02BA136E
CPatchUI.dll (x32\ja)
2589B3D17004BF673DE60B164F6F168F
CPatchUI.dll (x32\zh-cn)
351BDC93974F93289CA7F21D653AAD2C