HDX Direct and Network Telemetry Stop Working After VDA Upgrade to 2603 on Non-English Operating Systems

book

Article ID: CTX696662

calendar_today

Updated On:

Description

The following behavior may be observed after upgrading the VDA to version 2603:

  • HDX Direct connections fail to establish
  • Direct connection state remains unavailable
  • Sessions continue routing through Citrix Gateway
  • No TLS listener is started on TCP/UDP port 443 on the VDA
  • Network Telemetry functionality stops working after the upgrade

Running the following command on the VDA:

ctxsession -v

shows:

HDX Direct State : None

Additionally, the Citrix Certificate Manager Service (CtxCertManagerSvc) repeatedly logs the following error:

CertificateManager::UpdateDACL - Unable to configure the private key's ACL because the account is invalid. Please contact Citrix Technical Support.

Environment

"This software application is provided to you as is with no representations, warranties or conditions of any kind. You may use and distribute it at your own risk. CITRIX DISCLAIMS ALL WARRANTIES WHATSOEVER, EXPRESS, IMPLIED, WRITTEN, ORAL OR STATUTORY, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT. Without limiting the generality of the foregoing, you acknowledge and agree that: (a) the software application may exhibit errors, design flaws or other problems, possibly resulting in loss of data or damage to property; (b) it may not be possible to make the software application fully functional; and (c) Citrix may, without notice or liability to you, cease to make available the current version and/or any future versions of the software application. In no event should the software application be used to support ultra-hazardous activities, including but not limited to life support or blasting activities. NEITHER CITRIX NOR ITS AFFILIATES OR AGENTS WILL BE LIABLE, UNDER BREACH OF CONTRACT OR ANY OTHER THEORY OF LIABILITY, FOR ANY DAMAGES WHATSOEVER ARISING FROM USE OF THE SOFTWARE APPLICATION, INCLUDING WITHOUT LIMITATION DIRECT, SPECIAL, INCIDENTAL, PUNITIVE, CONSEQUENTIAL OR OTHER DAMAGES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. You agree to indemnify and defend Citrix against any and all claims arising from your use, modification or distribution of the software application."

Cause

This issue is caused by a change introduced in VDA version 2603 related to private key permission handling within CertificateManager.cpp.

The following call was introduced to broaden private key access permissions:

UpdateDACL(L"NT AUTHORITY\\LOCAL SERVICE", ...)

On non-English Windows operating systems, the NT AUTHORITY account name is localized by the Local Security Authority (LSA). Because of this, the hardcoded English account name:

NT AUTHORITY\LOCAL SERVICE

cannot be resolved successfully on localized operating systems and returns:

ERROR_NONE_MAPPED (1332)

As a result:

  • UpdateDACL() throws an exception
  • Certificate creation fails
  • TLS listener initialization fails
  • Direct HDX functionality becomes unavailable
  • Network Telemetry initialization and communication also fail due to the same certificate handling issue

Resolution

A private hotfix binary is attached to this article to address the issue.

The same hotfix resolves both:

  • HDX Direct failures
  • Network Telemetry failures

Follow the steps below to apply the hotfix:

  1. Stop the Citrix Certificate Manager Service.
  2. Navigate to the following directory:
C:\Program Files\Citrix\HDX\bin\
  1. Rename the existing file:
CtxCertManagerSvc.dll

to:

CtxCertManagerSvc.dll.origin
  1. Copy the hotfix binary attached to this article into the same directory.
  2. Start the Citrix Certificate Manager Service again.
  3. Launch a new session and verify that HDX Direct connectivity is established successfully.

Running the following command:

ctxsession -v

should now show a valid HDX Direct state instead of None.

Additionally, verify that Network Telemetry functionality resumes normal operation after applying the hotfix (if configured).

Issue/Introduction

After upgrading Citrix Virtual Delivery Agents (VDAs) to version 2603, HDX Direct connections and Network Telemetry functionality may fail to operate correctly.

This issue affects only VDAs running non-English native operating systems, such as:

  • German
  • Chinese
  • French
  • Japanese
  • Other localized Windows operating systems

As a result:

  • Sessions fall back to Gateway connectivity instead of establishing a Direct HDX connection.
  • Network Telemetry functionality may fail to initialize or report data correctly.

Attachments

CtxCertManagerSvc.dll.zip get_app