This message was deleted.
# citrix-vad
s
This message was deleted.
r
Do you only have a single domain? I have seen that error when cross domain authentication is not configured. Check your fas gpos make sure the order matches and that there are no spaces in the lines with server names.
f
Hello Rob, Yes it's a single domain and for the moment there is only one FAS and one CA and the name is correct (same GPO applied on OUs containing FAS, SF and VDAs). The thing i cannot reproduce to compare in a lab for the moment is that the root CA has still a sha1 signature i don't if there can be an impact.
r
If you arent getting an error on the domain controller where the logon is happening then thats probably not an isuse but im not sure about that. You do have a domain controller or Kerberos client authentication certificate on your domain controllers that includes smartcard logon in Enhanced Key Usage
f
Yes the customer has several certificates for his AD server including one with this usage.
r
Ok our FAS engineers dont think the root CA using SHA1 would be an issue
f
unfortunately already tried and no issue CRL vas sucessfully verified from the VDA. I've also set the key in prevention but no more success !
r
BTW there is a gpo to always prompt for password you should ensure you dont have that set
And you said you get no errors on the VDA event logs
among many possible errors on the vda you could see something like this if the domain controller is not trusting the FAS certificate
There woudl also be an error on the domain controller
f
I've asked the customer to double check as he has lots of GPOs. Yes i already had this kind of errors for others customer but it's not the case for the moment. The problem is that i don't know which additionnal logs to activate
r
all of the fas loggin is in the even viewer
the only other logging is the kerberos stuff on the VDA which it sounds like you jave done
if you really dont see errors on the vda event logs then I woudl think the gpo to rpomtp for password is the culprit but you should be able to see that in the RSOP
it is hard to look through the audit logs of course because there are so many entries
f
Yes i hope, i'll keep you informed. I've also found that we can activate capi2 logs to investigate about CA issues.
r
Good Luck FAS can be quick and easy or take a long time to get going. Sounds like your in the later.
f
Yes thank you for you help, i really appreciate.
Hello Rob, little update: My customer has tried with published desktop instead of published app and he got the prompt for login password. So I've asked to check further the presence of the GPO for "always prompt" and i'm waiting for his feedback. In parallel, he also found an article interesting but not necessarly relevant in our case: https://support.citrix.com/article/CTX479236/fas-information-about-microsoft-kb-kb5014754cve202234691-cve202226931-and-cve202226923 I share it here for the information.
Little update, still the issue with the GPO disabled, so next step is to investigate in CAPI logs.