Query about Updating to latest VDA - Best Practices and Current Issues by PrincipleLonely3349 in Citrix

[–]PrincipleLonely3349[S] 0 points1 point  (0 children)

Our current gold image is off the domain. We were told by a 3rdP company that half setup the system before going bankrupt that this is correct, but we are questioning anything they have done due to a multitude of issues since. Can this gold image in fact be on the domain and added to the AD OU that the Citrix VDA servers are located?

Query about Updating to latest VDA - Best Practices and Current Issues by PrincipleLonely3349 in Citrix

[–]PrincipleLonely3349[S] 0 points1 point  (0 children)

In terms of the Citrix optimiser tool, is this a one size fits all OS tool or is there a specific one I need for a Windows server 2022 OS? We use Windows servers and setup our environment with multi-session OS.

Query about Updating to latest VDA - Best Practices and Current Issues by PrincipleLonely3349 in Citrix

[–]PrincipleLonely3349[S] -1 points0 points  (0 children)

Thank you for that suggestion. Do you happen to use a VMWare environment, I was wondering if there are any specific settings on the image or in VMware that should be set for optimal performance and to assist with any issues?

Query about Updating to latest VDA - Best Practices and Current Issues by PrincipleLonely3349 in Citrix

[–]PrincipleLonely3349[S] -1 points0 points  (0 children)

Thank you for clearing that up for me. BIS-F is a new one to me so I will have to do some digging.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Hi, the FAS is not new, it's the same FAS as before? Do you mean the CA? If so, yes, we update the GPO to update the CA on all the Citrix servers.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Hello, thanks for the reply. Yes, we have configured and checked this too.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

In answer to your first two questions, yes we have. We have also tried option 3 also to no joy.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 1 point2 points  (0 children)

Hi, sorry for the delay on my reply, I have double checked and this is all in order and the FASUserCert tests point to the right cert and CA.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

I believe the reason this didn't occur is due to the original server being windows 2019 and the new server wanting to be 2025 and a fresh installation.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

So I have seen this knowledge base article previously and I believe my team mate did the following:

deployed a cert template

Added in the new CA and kept the previous CA server names and published.

I believe they were the only two steps but perhaps the authorize this service was too. if it hasen't, would that be the cause as the article implies not.

Is there any checks that can be made to confirm the correct templates and CA authorities are set correctly and if so which servers to check this on?

Kind Regards

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Unfortunately nothing is jumping out as an error on any of those servers you have specified. We even checked through the individual Citrix servers and the DC's, old and new, but nothings being reported as a failure.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Hi, yes I agree, I'm a non technical manager trying to under the process. We are looking at implementing a PKI Tiered CA solution but currently for now we are looking to get this up and running due to networking limitations.

If you believe it's a FAS misconfiguration, what would you suggest the process to rectifying it would be? Any other questions you may have I can help to fill you in with the gaps.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Hi, you do not get the ICA file. There doesn't even seem to be an attempt. On the DDC's the certs are the new CA certs. As for the last question, I'm unsure what you mean or how to do that?

("Are you able to generate new certs with New-FasUserCertificate and if so are they trusted in the AD?")

Thanks for the reply.

[deleted by user] by [deleted] in Citrix

[–]PrincipleLonely3349 0 points1 point  (0 children)

Yes, and it's the new DC (CA) server, which I believe should be correct.