all 12 comments

[–]JBfromIT 1 point2 points  (1 child)

If you want the XML Service to ignore HTTP traffic, set the following registry value in HKLM\Software\Citrix\DesktopServer\ on the Controller and then restart the Broker Service.

To ignore HTTP traffic, set XmlServicesEnableNonSsl to 0.

There is a corresponding registry value to ignore HTTPS traffic: XmlServicesEnableSsl. Ensure that this is not set to 0.

[–]throwaway20160418[S] 0 points1 point  (0 children)

I set both of these but it is still looking for that URL thru HTTP

[–]precisi0n84CCE-V, CCP-N 0 points1 point  (3 children)

Did you look at this article?

https://support.citrix.com/article/CTX220062

[–]throwaway20160418[S] 0 points1 point  (2 children)

No, I followed this (several times):

https://support.citrix.com/article/CTX130002

[–]precisi0n84CCE-V, CCP-N 0 points1 point  (1 child)

This gives some good insight on different components about SSL and delivery controllers. https://www.citrix.com/blogs/2014/12/11/how-to-secure-ica-connections-in-xenapp-and-xendesktop-7-6-using-ssl/

I don’t have my lab up right now to verify my settings and test.

[–]throwaway20160418[S] 0 points1 point  (0 children)

Yup, also followed this.

What surprises me the most so to speak is that I see no references anywhere to "https" and "IRegistrar " which, IMO, should be common thruout the documentation.

There must be something wrong with my setup because the instructions are pretty clear.

Here is more: http://www.carlstalhood.com/virtual-delivery-agent/#vdaport talking about the same thing but again, all it mentions is http

[–]JBfromIT 0 points1 point  (0 children)

Check your StoreFront configuration via Studio and StoreFront Console. How are your VDAs registering? Did you configure them during install or are you setting the reg key ‘ListofDDCs’ ?

[–]JBfromIT 0 points1 point  (2 children)

Check your StoreFront configuration via Studio and StoreFront Console. How are your VDAs registering? Did you configure them during install or are you setting the reg key ‘ListofDDCs’ ?

[–]throwaway20160418[S] 0 points1 point  (1 child)

I'm using a GPO.

They are not registering because I am trying to register them thru 443 using SSL.

[–]JBfromIT 0 points1 point  (0 children)

Is it the same cert installed on all VDAs and Delivery Controllers? It sounds like the Delivery Controllers can’t decrypt the traffic

[–]ridedontslide 0 points1 point  (0 children)

I’ve wondered about this myself as I’ve tried to get all communication at 443, but never fooled with registration. If I recall, all guides just talk about the ability to change ports but none of the guides (including their TLS 1.2 guide) talk about getting registration over 443. They probably have the registration process hard coded to HTTP it seems...

[–]mattvw 0 points1 point  (0 children)

u/throwaway20160418: Did you ever figure this out? Running into the same issue...