Connections Cannot be Established on XenApp/XenDesktop Servers over HTTPS

Connections Cannot be Established on XenApp/XenDesktop Servers over HTTPS

book

Article ID: CTX200194

calendar_today

Updated On:

Description

Connections cannot be established on XenApp/XenDesktop Servers over https.

Event ID 0: An SSL connection could not be established: None of the SSL cipher suites offered TLS_RSA_WITH_RC4_128_SHA, TLS_RSA_WITH_RC4_128_MD5, TLS_RSA_WITH_3DES_EDE_CBC_SHA, TLS_RSA_WITH_AES_128_SHA, TLS_RSA_WITH_AES_256_SHA were accepted by the server. 
This message was reported from the Citrix XML Service at address. 
The specified Citrix XML Service could not be contacted and has been temporarily removed from the list of active services.

Event ID 4003: All the Citrix XML Services configured for farm <FarmName> failed to respond to this XML Service transaction.

Resolution

Install the following Microsoft update:
KB2292611MS14-066: Vulnerability in SChannel could allow remote code execution


Problem Cause

The issue occurs after applying Microsoft patch KB 2919355 on DDC servers.
Note: Certain cipher suites are not accepted by XenApp/XenDesktop 7.x from StoreFront 2.x.

Issue/Introduction

StoreFront HTTPS Connection Failures

Additional Information

CTX141715 - Microsoft Security Patch Validation Report November 2014
Microsoft Support - Windows RT 8.1, Windows 8.1, and Windows Server 2012 R2 Update: April 2014
Microsoft Download -  Windows 8.1 Update (KB2919355)