This message was deleted.
# citrix-vad
s
This message was deleted.
r
If you use spaces it wont failover the spaces mean in datacenter A only use Storefronts and Fas servers in datacenter A and in datacenter b use only the ones in B. If a user is routed to datacenter B they should be able to use datacenter A VDAs as long as the vda GPO has all of the fas servers listed. The idea behind that design is that two storefronts and two fas servers in each datacenter are sufficient redundancy.
IN Cloud there is a concept of a backup fas server and you coudl define the other datcenter fas servers as backup
d
I understand that it won't fail over data centers. I'm ok with that. I just have an issue when a server is patching or the FAS service is having other issues, but still on the network, it won't use the secondary server. If I power off the server so it is not available on the network at all, the failover works properly. These seems like a bug to me. If the first attempt fails. it should make an attempt to the secondary server.
r
Yes if one of two is in mm storefront should go to the other. Do you see errors in storefront.
d
Yes. These are with the FAS service stopped on the server that would normally serve my account certificate:
Log Name:      Citrix Delivery Services
Source:        Citrix Store Service
Date:          7/31/2023 9:40:09 AM
Event ID:      1
Task Category: (1264)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      <StoreFront FQDN>
Description:
The Federated Authentication Server at: <FAS FQDN> generated an exception for method AssertIdentity
System.ServiceModel.CommunicationObjectFaultedException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
The communication object, System.ServiceModel.Channels.ServiceChannel, cannot be used for communication because it is in the Faulted state.
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.Channels.ServiceChannelFactory.OnClose(TimeSpan timeout)
`at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnClose(TimeSpan timeout)`
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.OnClose(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.System.IDisposable.Dispose()
`at Citrix.Authentication.UserCredentialServices.FederatedAuthenticationServer.AssertIdentity(String userPrincipalName, SecurityIdentifier sid, String userRole, String securityContext, String disposition, List`1 evidence)`
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
Event Xml:
<Event xmlns="<http://schemas.microsoft.com/win/2004/08/events/event>">
<System>
<Provider Name="Citrix Store Service" />
<EventID Qualifiers="0">1</EventID>
<Level>2</Level>
<Task>1264</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2023-07-31T16:40:09.554456300Z" />
<EventRecordID>117858</EventRecordID>
<Channel>Citrix Delivery Services</Channel>
<Computer><StoreFront FQDN></Computer>
<Security />
</System>
<EventData>
<Data>The Federated Authentication Server at: <FAS FQDN> generated an exception for method AssertIdentity
System.ServiceModel.CommunicationObjectFaultedException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
The communication object, System.ServiceModel.Channels.ServiceChannel, cannot be used for communication because it is in the Faulted state.
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.Channels.ServiceChannelFactory.OnClose(TimeSpan timeout)
`at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnClose(TimeSpan timeout)`
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.OnClose(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.System.IDisposable.Dispose()
`at Citrix.Authentication.UserCredentialServices.FederatedAuthenticationServer.AssertIdentity(String userPrincipalName, SecurityIdentifier sid, String userRole, String securityContext, String disposition, List`1 evidence)`
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
</Data>
</EventData>
</Event>
---and---
Log Name:      Citrix Delivery Services
Source:        Citrix Store Service
Date:          7/31/2023 9:40:09 AM
Event ID:      28
Task Category: (2001)
Level:         Warning
Keywords:      Classic
User:          N/A
Computer:      <StoreFront FQDN>
Description:
Failed to launch the resource '<application launched> ' using the Citrix XML Service at address '??'. An unknown error occurred interacting with the Federated Authentication Service. See the inner exception for more details.
Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.Diagnostics.FasException, Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider, Version=3.23.0.0, Culture=neutral, PublicKeyToken=null
An unknown error occurred interacting with the Federated Authentication Service. See the inner exception for more details.
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
at com.citrix.wing.core.mpssourceimpl.MPSFarmFacade.GetVdaLogonData(Context context)
`at com.citrix.wing.core.mpssourceimpl.MPSFarmFacade.GetAddress(Context ctxt, String appName, String deviceId, String clientName, Boolean alternate, MPSAddressingType requestedAddressType, String friendlyName, String hostId, String hostIdType, String sessionId, NameValuePair[] cookies, ClientType clientType, String retryKey, LaunchOverride launchOverride, Nullable`1 isPrelaunch, Nullable`1 disableAutoLogoff, Nullable`1 tenantId, String anonymousUserId, List`1 zoneIds)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.GetAddress(Context env, String appName, String deviceId, String clientName, Boolean alternate, MPSAddressingType requestedAddressType, String friendlyName, String hostId, String hostIdType, String sessionId, NameValuePair[] cookies, ClientType clientType, String retryKey, LaunchOverride launchOverride, Nullable`1 isPrelaunch, Nullable`1 disableAutoLogoff, Nullable`1 tenantId, String anonymousUserId, List`1 zoneIds)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.LaunchRemoted(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.applyaccessprefs.AAPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.clientproxyprovider.CPPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.connectionroutingprovider.CRPLaunch.LaunchInternal(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams, Boolean useAlternateAddress)` `at com.citrix.wing.core.connectionroutingprovider.CRPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.bandwidthcontrolprovider.BCPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at Citrix.DeliveryServices.ResourcesCommon.Wing.WingAdaptors.OverrideIcaFileLaunch.Launch(Dictionary`2 launchParams, Context env, AppLaunchParams appLaunchParams)`
at Citrix.DeliveryServices.ResourcesCommon.Wing.WingAdaptors.LaunchUtilities.IcaLaunch(IRequestWrapper request, Resource resource, LaunchSettings launchSettings, String retryKey, ICasTicketService casTicketService)
System.ServiceModel.CommunicationObjectFaultedException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
The communication object, System.ServiceModel.Channels.ServiceChannel, cannot be used for communication because it is in the Faulted state.
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.Channels.ServiceChannelFactory.OnClose(TimeSpan timeout)
`at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnClose(TimeSpan timeout)`
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.OnClose(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.System.IDisposable.Dispose()
`at Citrix.Authentication.UserCredentialServices.FederatedAuthenticationServer.AssertIdentity(String userPrincipalName, SecurityIdentifier sid, String userRole, String securityContext, String disposition, List`1 evidence)`
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
Event Xml:
<Event xmlns="<http://schemas.microsoft.com/win/2004/08/events/event>">
<System>
<Provider Name="Citrix Store Service" />
<EventID Qualifiers="0">28</EventID>
<Level>3</Level>
<Task>2001</Task>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2023-07-31T16:40:09.570092800Z" />
<EventRecordID>117859</EventRecordID>
<Channel>Citrix Delivery Services</Channel>
<Computer><StoreFront FQDN></Computer>
<Security />
</System>
<EventData>
<Data>Failed to launch the resource '<application launched> ' using the Citrix XML Service at address '??'. An unknown error occurred interacting with the Federated Authentication Service. See the inner exception for more details.
Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.Diagnostics.FasException, Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider, Version=3.23.0.0, Culture=neutral, PublicKeyToken=null
An unknown error occurred interacting with the Federated Authentication Service. See the inner exception for more details.
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
at com.citrix.wing.core.mpssourceimpl.MPSFarmFacade.GetVdaLogonData(Context context)
`at com.citrix.wing.core.mpssourceimpl.MPSFarmFacade.GetAddress(Context ctxt, String appName, String deviceId, String clientName, Boolean alternate, MPSAddressingType requestedAddressType, String friendlyName, String hostId, String hostIdType, String sessionId, NameValuePair[] cookies, ClientType clientType, String retryKey, LaunchOverride launchOverride, Nullable`1 isPrelaunch, Nullable`1 disableAutoLogoff, Nullable`1 tenantId, String anonymousUserId, List`1 zoneIds)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.GetAddress(Context env, String appName, String deviceId, String clientName, Boolean alternate, MPSAddressingType requestedAddressType, String friendlyName, String hostId, String hostIdType, String sessionId, NameValuePair[] cookies, ClientType clientType, String retryKey, LaunchOverride launchOverride, Nullable`1 isPrelaunch, Nullable`1 disableAutoLogoff, Nullable`1 tenantId, String anonymousUserId, List`1 zoneIds)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.LaunchRemoted(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.mpssourceimpl.MPSLaunchImpl.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.applyaccessprefs.AAPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.clientproxyprovider.CPPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.connectionroutingprovider.CRPLaunch.LaunchInternal(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams, Boolean useAlternateAddress)` `at com.citrix.wing.core.connectionroutingprovider.CRPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at com.citrix.wing.core.bandwidthcontrolprovider.BCPLaunch.Launch(Dictionary`2 parameters, Context env, AppLaunchParams appLaunchParams)` `at Citrix.DeliveryServices.ResourcesCommon.Wing.WingAdaptors.OverrideIcaFileLaunch.Launch(Dictionary`2 launchParams, Context env, AppLaunchParams appLaunchParams)`
at Citrix.DeliveryServices.ResourcesCommon.Wing.WingAdaptors.LaunchUtilities.IcaLaunch(IRequestWrapper request, Resource resource, LaunchSettings launchSettings, String retryKey, ICasTicketService casTicketService)
System.ServiceModel.CommunicationObjectFaultedException, System.ServiceModel, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089
The communication object, System.ServiceModel.Channels.ServiceChannel, cannot be used for communication because it is in the Faulted state.
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.Channels.ServiceChannelFactory.OnClose(TimeSpan timeout)
`at System.ServiceModel.Channels.ServiceChannelFactory.TypedServiceChannelFactory`1.OnClose(TimeSpan timeout)`
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.OnClose(TimeSpan timeout)
at System.ServiceModel.Channels.CommunicationObject.Close(TimeSpan timeout)
at System.ServiceModel.ChannelFactory.System.IDisposable.Dispose()
`at Citrix.Authentication.UserCredentialServices.FederatedAuthenticationServer.AssertIdentity(String userPrincipalName, SecurityIdentifier sid, String userRole, String securityContext, String disposition, List`1 evidence)`
at Citrix.DeliveryServices.FederatedAuthenticationService.VdaLogonDataProvider.FasLogonDataProvider.GetVdaLogonData(IClaimsPrincipal claimsPrincipal, HttpContextBase httpContext)
</Data>
</EventData>
</Event>
r
error 28 is that storefront cant contact any fas servers are you sure you have both defined in your gpo check HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Citrix\Authentication\UserCredentialService\Addresses on the fas server. In your FSA rule on the FAS server thats not working make sure you have both storefronts in the permissions for storefront servers
d
If I power off the FAS server that has my normal certificate, the failover is successful. If the normal server for my certificate is available on the network, but the FAS service itself is not available. It does not fail over properly. While the Error 28 may be saying that it couldn't contact any FAS servers, the Error 1 prior seems to be the issue that it only attempts to contact my normal FAS server. The SF server can talk to both FAS servers, and does so on a regular basis. The issue is that if the primary server is on the network, but the FAS service itself is not available for some reason, in this case it is intentional for testing, but there are other times it is not, the SF server doesn't attempt to connect to the backup FAS server for the user. I will take this up with Citrix as this is a bug. I just wanted to know if anybody else had seen the issue and if it is resolved in newer releases.
r
Ok im with you in my lab if i stop the FAS service on one fas server after logging on and getting a cert from that server then i cant launch new resources. If i log out and back in I can launch again so it appears FAS is nto finding the working server when logged in and trying to launch a new resource which I think it i supposed to do.
d
Thanks for the verification. Seems like a bug.
r
Ok I found the answer unfortunately what you are seeing is by design" StoreFront does not maintain a list of recently failed FAS servers, so it will not automatically skip over a FAS server that was found to be unavailable. If the administrator removes a FAS server from the GPO (e.g. by replacing its FQDN with a space), the load balancing algorithm will yield different results, rather than simply re-distributing users away from the failed server. When the user logs on to StoreFront, a working FAS server will be selected for the user, and bound to the user's StoreFront authentication token. This binding makes failover more efficient, because FAS server selection only takes place at the point where the user is logging on to StoreFront. However, if the FAS server subsequently becomes unavailable, application launches will fail until either the FAS server is restored to working order, or the user re-logs on to StoreFront. This limitation only applies to on-prem (StoreFront); cloud (Workspace) tracks the availability of all FAS servers
d
Ah, got it. So my testing was slightly invalid as well for the powered off machine. I didn't have a chance to re-test today, but this is very helpful. Maybe they will consider including that functionality in a future release. Thanks for the verification!
j
Is it an option to put FAS behind a LB so it can be down when the service is down?
r
No storefront uses a hashing algorithm to determine which FAS severs to use and the VDA has to know which one was chosen
🙏 1
👍 1
j
Thanks for the clarification Rob
v
also if one CA is having issues eg certificate service not running for some reason, there would be no failover from the FAS using that CA to the next FAS which has no issues talking to the CA it is configured with.
r
No you need two CAs defined in each FAS config