Anyone having issues with the April patches (KB508...
# citrix-app-layering
n
Anyone having issues with the April patches (KB5082123) causing Server 2019 VDAs on PVS to not boot? Ours are failing to obtain an IP and never actually get to the PVS server to pull the image. Posted this in the other channel, but we are using App Layering for this image. Seems to be broken from the April patches onward for us since they're cumulative.
j
Yup. Secure boot is getting enabled and new certificates across the board.
n
Our S19 stuff, while on UEFI, does not have Secure Boot enabled, so this confuses me
Our App Layering template for the connector does seem to have Secure Boot enabled, but the VMware templates for PVS do not
@Jeff Riechers: Did you actually resolve your issue? We opened a ticket with Citrix, but I'm going through some testing now to see if I can figure anything out.
j
I haven't had it in my environment, but one of my engineers saw it in AHV, and they had to update their hypervisor to support it. And Broadcom posted an article about exporting the current key during the update process.
n
We're trying to get clarification from Citrix on whether or not all of this is required if we don't have Secure Boot enabled. I don't see why it would be, but you never know.
Image with new OS layer built off that new template is in a reboot loop. Goes from Getting ready... to reboot. More than I got 2 weeks ago, but Rich is seeing the same in his image. Gonna build a new Platform layer now (2402 CU4) using this new OS layer version as the base.
I need one of the ops guys to validate my findings, but it was a weird one. App Layering VMware Connector template used ESXi 8.0 U2+ hardware compatibility, but the PVS template used ESXi 7.0 U2 hardware compatibility. After a lot of digging I found a random post about how as of v20 (post-7.0 U2), PCI NICs would use slot 33, and 192 would be reserved for PCIe devices. Seems dumb, but whatever. So I built another AL VMware template using the older compatibility, and used that to create a new OS layer version with the latest May patches. Compiled the image, booted fine. I then built a new Platform layer based off that OS layer, compiled an image, booted fine. What a rabbit hole this was. I have no idea why just now that slot number seems to matter, but that's what appears to be the case for us.
s
April patches and server 2025 seem to be ok over here. Saw some evidence of what ur experiencing on reddit tho. What target device version are you on?
n
That post on Reddit was mine.
👍 1
We're still using 2203 CU5 for the PVS install (I know, I know).
I think Ops is delaying doing much with that until we move entirely to this new environment, currently running PVS 2507.1.