The following behavior may be observed after upgrading the VDA to version 2603:
Running the following command on the VDA:
ctxsession -v
shows:
HDX Direct State : None
Additionally, the Citrix Certificate Manager Service (CtxCertManagerSvc) repeatedly logs the following error:
CertificateManager::UpdateDACL - Unable to configure the private key's ACL because the account is invalid. Please contact Citrix Technical Support.
"This software application is provided to you as is with no representations, warranties or conditions of any kind. You may use and distribute it at your own risk. CITRIX DISCLAIMS ALL WARRANTIES WHATSOEVER, EXPRESS, IMPLIED, WRITTEN, ORAL OR STATUTORY, INCLUDING WITHOUT LIMITATION WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE AND NONINFRINGEMENT. Without limiting the generality of the foregoing, you acknowledge and agree that: (a) the software application may exhibit errors, design flaws or other problems, possibly resulting in loss of data or damage to property; (b) it may not be possible to make the software application fully functional; and (c) Citrix may, without notice or liability to you, cease to make available the current version and/or any future versions of the software application. In no event should the software application be used to support ultra-hazardous activities, including but not limited to life support or blasting activities. NEITHER CITRIX NOR ITS AFFILIATES OR AGENTS WILL BE LIABLE, UNDER BREACH OF CONTRACT OR ANY OTHER THEORY OF LIABILITY, FOR ANY DAMAGES WHATSOEVER ARISING FROM USE OF THE SOFTWARE APPLICATION, INCLUDING WITHOUT LIMITATION DIRECT, SPECIAL, INCIDENTAL, PUNITIVE, CONSEQUENTIAL OR OTHER DAMAGES, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. You agree to indemnify and defend Citrix against any and all claims arising from your use, modification or distribution of the software application."
This issue is caused by a change introduced in VDA version 2603 related to private key permission handling within CertificateManager.cpp.
The following call was introduced to broaden private key access permissions:
UpdateDACL(L"NT AUTHORITY\\LOCAL SERVICE", ...)
On non-English Windows operating systems, the NT AUTHORITY account name is localized by the Local Security Authority (LSA). Because of this, the hardcoded English account name:
NT AUTHORITY\LOCAL SERVICE
cannot be resolved successfully on localized operating systems and returns:
ERROR_NONE_MAPPED (1332)
As a result:
UpdateDACL() throws an exceptionA private hotfix binary is attached to this article to address the issue.
The same hotfix resolves both:
Follow the steps below to apply the hotfix:
C:\Program Files\Citrix\HDX\bin\
CtxCertManagerSvc.dll
to:
CtxCertManagerSvc.dll.origin
Running the following command:
ctxsession -v
should now show a valid HDX Direct state instead of None.
Additionally, verify that Network Telemetry functionality resumes normal operation after applying the hotfix (if configured).
After upgrading Citrix Virtual Delivery Agents (VDAs) to version 2603, HDX Direct connections and Network Telemetry functionality may fail to operate correctly.
This issue affects only VDAs running non-English native operating systems, such as:
As a result: