This message was deleted.
# citrix-vad
s
This message was deleted.
💯 1
👀 4
r
I just have to ask. You seeing this on new setups and upgrades?
j
Have you tried testing using the 1912 CU5 VDA?
b
Not with 2203 so far but had it with 2112 until the fix they released
c
No logonui.exe issues with 2203
f
I’m still seeing this issue on 1912CU5 but only on our 2019 servers
b
all of them upgrades, CR and LTSR. no issues on 1912 CU5 and 2112 + Hotfix.
s
2203 is not having the issue with logonui.exe
b
officially not...
rollback to 2112 + HF fixed it right now. 1912 CU5 is no option, customer is using teams heavily.
keep you informed about the ongoing cases, we got even a private fix --> unfortunately the same behavior
🙁 1
d
guess I spoke too soon. Saw this happen today to two accounts. cant sign them out and I tried to stop the search service and now it cannot start
b
search for the logonui.exe as in my screenshot above
d
yea i see them
I feel like I see loginui.exe often though
for your reference we are running citrix 2112 director/studio Server 2019 VDA 2203
n
Just got the 2203 CU1 EAR documentation, and this issue isn't mentioned at all. The KB doesn't mention 2203, either.
👍 4
r
I've just build new environment with 2203 and it's starting this if user leaves session and it goes into disconnected state they cant get back in, server 2019. latest FSlogix
💯 2
b
had same issue with 2112. this is what i did and it seemingly resolved it 99% of the time: Try to add the following two keys(idk which one works, maybe both required) HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\ Create new folder called Reconnect add these two Dword entries DisableGPCalculation with a 1 FastReconnect with a 0
r
thanks will try as its happening way to often for new build
m
Can confirm, this issue is hitting real hard since 2109 and still not entirely fixed. It's a nightmare. 2203 CU1 doesn't seem to help either, according to the release notes.
💯 1
r
This is very Disappointing issues are still floating around 😞
b
We got a private Fix and are evaluating the results. Fingers crossed
👏 1
🤞🏻 2
m
Oh, interesting. What is it? A custom DLL?
b
yes. RPM.dll is replaced and a reg key has to be created.
r
I have opened a case this morning, do you have Private fix details I can maybe speed up the call thanks
b
Sure, just refer to SR 81207877. The Steps are: 1) Create a blank ‘System32’ folder under ‘C:\Program Files (x86)\Citrix’ and paste the RPM.dll file 2) Create a blank ‘GroupPolicy’ hive in registry under ‘HKLM\SOFTWARE\Citrix\Ica\’ and create the ‘EnforceUserPolicyEvaluationSuccess’ DWORD key 3) Replace RPM.dll in ‘C:\Program Files\Citrix\HDX\bin’
r
Cool thanks
b
Issue still persists, but less often. A possible workaround would be a continuous check of the existing sessions on the DDC and all Worker. If a session is present on a worker but not visible in CTX Studio, the brokerservice has to be restarted on the VDA.
r
Does restarting effect other users on the server ?
b
not if LHC is activated :)
r
OK cool, I just see 2206 has been released and one of the fixed issues is active accounts showen in director may not match, going to test it and see will let you know how it goes next week when I get some users on it
p
It's not fixed in 2206.
r
No not fixed I had one user today for us seems to be related to a session getting disconnected by some network glitch they can't get back to session
r
This is insane.
c
Whats the workaround for now?
p
This is after manually killing logonui.exe processes for 35+ disconnected sessions with procexplorer this morning. and leaving the machine in maint mode for the remaining users to drain. I was on 2203 - had these issues, rebuilt with 2206, have these issues. Edit. Always get my procmon/explorer names mixed up..
Weirdly, director still thinks there are 35 users on this box. There are actually only 6 "sessions". 4 with the above 5 processes, myself, and one active user.
Opened my own case on it. I should probably also open a case on why "open tickets" is permanently 0... 🤨
r
I have a case open and this is the behaviour they were expecting to issue a hot fix, I'm not seeing this though my users have a full session still connected as a disconnected session when they log on it creates a new local profile
Support is hard work at the moment for sure
r
@Ronnie and @Balint Oberrauch can you share your case numbers with me? Thanks
r
Sure mine is early stages no logs collected or anything gave a reg key fix but think it was finger in the air as it didn't really match the issue 😁 it's 81277746 I've only a small number of users so not to bad
r
Ok thanks
r
No worries.
b
A restart of the Brokeragent on the VDA brings back the session in CTX Studio. @Rody Kossen we have/had the following cases open: SR 810746781 SR 81207877 SR 81227627 SR 81224930 SR 81239231
@Marco Hofmann has one open as well
Primary Case we're working on is 81207877
p
Any consensus on a working VDA? I know 1912CU3 is fine, but it's a little old.
m
1912 CU3, That's the last know good VDA afaik. 90% of my customers use it, and I feel dirty for using such an old release.
s
2203 is also a good VDA for me it's working fine
n
That issue with 2203, it's multi-user VDA, no?
p
yeah. This whole thread is multi-user related.
s
@Paul Brown Which OS?
p
2016
m
Can confirm. 2203 has the exact same issue as every VDA since 2109, uncluding the latest CU for 1912. It's a PITA. Afaik only multi user VDA is affected.
s
I am using WS2019
m
Makes no difference. All my affected systems are 2019.
s
On WS2019 No issue observed
p
So, this kinda makes me wonder. How 'old' is your 2019 build @Salim Hurjuk Any long standing Citrix optimizations in group policy etc?
s
Latest Build with all Windows Patches
No Citrix Optimization on GPO
p
So a green field build with nothing optimized?
s
Citrix Optimizer applied
And Autorun and other necessary optimization recommended by Citrix... No VMWARE OPTIMIZATION APPLIED
c
Had also 2203 vdas in place with 2019 and latest patches. No issues. Citrix optimizer + bisf. Search Service disabled ….
s
Adobe Application related Optimization in Registry Key
Google & Edge Browser Optimization with GPO and Registry
Explorer related Optimization and Start Menu Customized for all user's
Shell and Userinit Optimization at Login time
That's it @Paul Brown
U have AV enabled? or security components on VMs?
p
I'm just wondering about old farms, with years worth of registry tweaks in group policy (like my own) that were ticking along quite nicely thanks very much until VDA 1912CU4 and above came along.
s
Do U have AV enabled? or security components on VMs? @Paul Brown
p
We run Crowdstrike corporate wide. Have done for about 8 years now.
s
Just disable for one HSD VM for one day & check
p
I'll get right on that. I'm sure our Cyber team will be cool about it. Again, running for 8 years. Last 6 or so months have had issues with recent VDAs. Our images do not change much.
s
Just for one VM one day can take an exception
p
FYI, i opened a ticket with Citrix support. Provided screenshots showing multiple sessions hung with 5 processes, for both VDA 2203 and VDA 2206, and detailed the issue is occurring with both VDA 2203 and VDA 2206 on Multi Session VMs. Was told "Ghost session issue has been fixed in 2203LTSR" and asked to "provide screenshot of installed UPM on VDA" I'm still trying to mentally process this.
r
Im still waiting on a reply from last week
m
@Paul Brown Do you know a Citrix SE who can help you escalate?
r
Yeah I do and have contacts is senior management in support, just been busy o other stuff. I've small user base and it's only happened once in the last week so still monitoring but to jus not reply I already had to send their manager a mail to see why I hadent replied initially
p
Yes. Though i'm trying to avoid bugging our SE for now. I bug him quite a bit as it is...
k
Maybe a CTP can help you out. I know they have ways to escalate cases
r
😁
b
Had a call with a CTX Engineer today, they're expecting to have fixed a part in 2203 CU1 and 2209. Basically the known issue related to rpm.dll. The dll resolves is at least for us just reducing the number of affected users.
k
Do you know why they reported the issue fixed in 2203?
m
I can confirm, that the private fix for 2203 CU0 (rpm.dll) does not fix the issue, it only appears less often.
r
Did you mention this in your support case? What is your case no?
b
The Escalation Engineer himself mentioned that it should have been fixed in 2203 and that there are different open root causes. Case No is 81207877
m
No. To be honest I gave up months ago, because we received no help :-/ The support case was: 81061515
r
Guy has just sent me a CTX article to modify a storefront setting and u me not using storefront 🤣
r
Thanks @Marco Hofmann for the case number. Sorry to hear that you had that experience
p
Anybody know what internal case number Citrix are tracking this on? Support are flat out stonewalling me currently. Going to contact my SE.
s
fyi: we are having the same behavior with the black logon screen and user sessions not disconnecting on different citrix and also rds farms with w2k16 workers and it looks like in our case the last windows update KB5015808 caused the issue. https://www.reddit.com/r/fslogix/comments/w8ies1/fslogix_failed_to_acquired_logon_lock_on_server/
f
Yeah, the July update break FSLogix on WS2016
😡 2
b
so many bugs out there right now. not funny at all
m
Yes I can confirm, CU7/2022 breaks FSL on Server 2016, we rolled back our MCS Images to CU06/2022. BUT that's a whole different topic and has nothing to do with the sessions vanishing from Studio/Director with users being unable to reconnect.
👍 1
k
Why are you guys on 2016? App compatibility?
m
I currently have three 2016 MCS environments, if I recall correctly. One for App compatibility, and the other two are planned to upgrade to 2019 as soon as I have time.
👍 1
r
I'm just curious if you guys made any progress on the logonUI issue? Just curious. I guess this is the temp happens less often fix? “1) Create a blank ‘System32’ folder under ‘C:\Program Files (x86)\Citrix’ and paste the RPM.dll file 2) Create a blank ‘GroupPolicy’ hive in registry under ‘HKLM\SOFTWARE\Citrix\Ica\’ and create the ‘EnforceUserPolicyEvaluationSuccess’ DWORD key 3) Replace RPM.dll in ‘C:\Program Files\Citrix\HDX\bin’”
p
Just went through the changelog of 2203 CU1. The only fix related to session/connection is this one: The TermService permission on the registry key HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Ica\Session might not be restored during the installation of a VDA on Citrix Virtual Apps and Desktops 1912 CU resulting in sessions failures Is this the fix for this issue or did i just miss something?
r
Hi, Quick question, does anybody have this policy active
Copy code
User Configuration\Administrative Templates\System\Ctrl+Alt+Del Options\Remove Lock Computer
https://support.citrix.com/article/CTX330692/windows-10-multisession-reconnected-session-still-shows-as-disconnected-on-cloud-studio-and-monitor
b
Customer confirmed that this policy is unconfigured
m
We also don't use that policy.
r
Thanks for confirmation. Is anybody willing to help me with getting a CDF Trace?
d
https://discussions.citrix.com/topic/416494-temporary-profiles-with-fslogix-in-xenapp-7-2203/page/2/#comment-2092932 @Ray Davis Sounds like this is the same temp fix that will (maybe) be included in future releases...right? "You may be able to get a private fix to add a feature flag to disable the new feature by opening a technical support case and mentioning CVADHELP-20129. "
r
would setting this to 11work with the wifi disconnect similar to what I was seeing for a MAC user https://support.citrix.com/article/CTX136339/applications-launched-from-within-published-desktop-disconnects
r
Just reposting here: Anyone willing to work with me on gather CDF traces for this issue so I can forward them internally?
r
Hi Rody it hasent happened to us internally in a week or so hoping it's fixed but can't be sure a lot off on holidays . Take it u need the trace when it happens ?
r
Yes so we need a trace from the moment the user initially logs on until the issue happens with reconnect/ghost session
r
Ok unlikely I'd be able to get as can't really produce if it starts happening over the next week or so I'll come back to you and see what settings needed in trace
👍 1
p
@Rody Kossen In effect you are asking for CDF trace to be running from server start until a time when the issues appear, which could be 8 hours hundreds of users later...
r
Yeah.. I don't know if you could repro it with a user in less than 8 hours..
p
Tricky. I'm back from vacation so can see about setting up a sacrificial server.
b
@Rody Kossen do you have access to the CDF Traces, which are already uploaded? We submitted 2 CDF Traces with the SR I've mentioned before.
r
@Balint Oberrauch Yes I have access to that. Do they contain the initial user login as well?
p
@Rody Kossen I have a new Server 2016 MCS image with VDA 2206. Published to a single test VM and has been running since yesterday. Not triggered the issue yet, will be monitoring it during the day. Its cycled though 73 unique user sessions so far. One difference with this image compared to our standard build is it does not have the CQI package installed.
s
do you guys have Fslogix deployed in Master Image ?
k
@Salim Hurjuk yes 🙂
s
I am using WS2019 with VDA 2203 and FSL is holding the session disconnected state
b
2203 CU1.1 contains the rpm.dll fix and the registry keys "DisableGPCalculation" + "FastReconnect" regarding to CTX Support
c
For sure ?
b
I will compare the registry keys + the hash of rpm.dll in my lab next week, as I'm OOO.
m
So regarding to our tests @Balint Oberrauch that would mean, the issue would be less severe with 2202 CU1.1, than with all previous versions since 2109, but still not fixed, right?
b
correct
m
That's funny and sad at the same time
s
I am using WS2019 with VDA 2203 and FSL is holding the session disconnected state with 4-5 process - anyone facing this issue?
@Paul Brown @Marco Hofmann @Balint Oberrauch @Ronnie
m
What makes you sure FSL is the root cause?
p
@Salim Hurjuk We have FSL for app masking, not profiles. But we also have some VDA's without it at all that see the same zombie session issues.
s
In my environment, it's fixed now for me observed from last 4 days no issues reported...
What I did - I have app masking configured, I have removed the rules configured to hide Microsoft XPS Printer and Start Menu - Windows Security
@Paul Brown and @Marco Hofmann do you have above two rules in your app masking?
p
@Salim Hurjuk Not here. And as i said i have VDAs without FSL at all seeing the same ghost user issues.
s
on WS2019?
p
2019 and 2016
s
Your defender is On or Off
p
Curious why that would matter. We have pools of VMs that do differing things. But the majority of them are all built the exact same way, via Applayer. So we can (and have done, MANY times recently) swap out the platform layer for differing VDA builds. Everything else remains the same, just the different VDAs, and every VDA i have tried from 1912_CU3 on has some weird issue that results in zombie user sessions. 2203 CU1 being the worst, as it also broke director. Every time we swap back to the 1912_CU3 VDA, we gain stability.
💯 2
s
Okay I am nor using AppLayer
The Process which are holding the session in disconnected state...What do you see in Analyze Wait Chain Screenshot for reference
d
@Paul Brown We are seeing the same thing here with zombie sessions and mappings. We keep attempting to upgrade but clients suffer too much and we have to roll back. We try to get support from Citrix, but they have been reluctant to work on anything because we aren't on the latest release. Test systems that only have one or two users at a time don't seem to have the same issues to getting support has been trying. We recently signed on for higher level support (paid) and seem to at least have support listening to us now and hopefully try to help. We shall see.
🍺 1
Also, we don't use AppLayering, PVS, MCS, or FSLogix. Our builds are all static and try to be at vanilla as possible to prevent issues.
m
@Dennis Parker Maybe you can reference all the cases @Balint Oberrauch and @Paul Brown created? @Paul Brown How are your cases going?
p
@Marco Hofmann My cases stalled out. We are a very small team trying to manage a global deployment and just do not have the time to burn testing Citrix's product for them.
m
I can relate to that. We are also very small, and that's one reason I abandoned my case in February 😢 And we have the exact problem you described, everything since 1912 CU3 just 🔥 I had such high hopes, since the bug shipped with 2203 LTSR, this would get some big attention, but so far it didn't work out.
p
Citrix should be embarrassed. 1912_CU3 is not 100% clear, but i'm talking 5 or 10 sessions vs 100s of sessions with the later releases.
It bugs me greatly that the default stance is "upgrade or we won't support / work your ticket" when upgrading is literally walking into a fire. Upgrading even a single VDA still affects hundreds of users over the course of the time it is running.
m
n
That's my thread 🫡 we’re about to go live with Server 2019 for OneDrive with FSLogix and VDA 2203 CU1. This disconnect issue has been driving us crazy. Looks like based on this thread 1912 CU3 maybe our safest bet to avoid issues? We do have teams but aren't heavy users. Our current environment is Server 2016, 1912 CU5 but we're using UPM so we haven't really received calls. I did open a ticket and submit CDF traces, etc. happy to help if I can.
m
@Rody Kossen Maybe the CDF traces from @Nick Patel are what you've been looking for?
r
@Nick Patel can you share your support case no?
n
Yes, one sec
Case #81360053
🙏 2
🙏🏻 1
I uploaded a zip file with CDF traces from the sever when the issue happened and from the server where the new session started
Time stamps are going to be between 4:17 PM and 4:35 PM EDT in those logs. The issue happened to me and this is what I witnessed: 1) I came back to my computer and saw the connection interrupted (Session Reliability) 2) A second new Citrix Viewer session automatically opened up 3) I was presented with the Windows login page for my session (not normal) 4) When entering in my credentials, the screen become stuck and did not proceed any further 5) I disconnected from that session and tried to launch the Citrix viewer again from the Cloud Storefront page 6) I was connected to a brand new session and in Director my existing session disappeared 7) My old session was still on the server even though Director showed no existing session 8) Had to log off that session in order to reconnect back successfully
For step 3 and 4, I went back into the event logs and saw it had an rpm error “non-brokered ICA connection request denied because the user is not in the Direct Access group”
b
@Nick Patel maybe your CDF Traces are more helpful! fingers crossed 🤞
👍 2
n
Looks like we’ll be ripping out VDA 2203 CU1 and replacing it with 1912 CU3 before our production deployment, at least until we can get this fixed. We have a separate delivery group for our IT staff so will keep the CDF tracing running and troubleshoot with us.
👍 2
k
Why 1912CU3 over 2106?
r
@Kai Zastrutzki are you able to read the whole thread?
k
Yeah, guess I missed something? Sorry. I came in from the reddit thread, where it was stated 2106 and 1912CU3 are the last known good ones.
b
correct. This nightmare started with 2019 and 1912 CU4
r
No need to be sorry, I was just making sure you were able to read it all. It has been a ride for sure. I can't image how @Balint Oberrauch feels right now
k
Okay, so my question still stands, why choose 1912cu3 over 2106? I'm looking into downgrading a deployment that has the issue.
m
As of today, both are unsupported. As the problem started 1912 CU3 was still supported, I guess. While 2106 as a CR was not supported for so long time? Now I think it really doesn't matter that much.
👍 1
n
When you downgrade, make sure you reinstall all the components. We had to reinstall the VDA, WEM, and Workspace App.
k
Ok. Do I have to downgrade the WEM client as well? My guess would be no...
r
WEM isn't dependent on a CVAD version. So no unless your want to
k
Thanks folks. This deployment has been stuck in the testing phase for far too long.
👍🏽 1
n
Our WEM version is 2106 and Workspace 2203 CU1 so confirmed it's not dependent
Haven't have a chance to upgrade WEM yet
m
Tomorrow I will update the one customer who is not on LTSR 1912 CU3, to LTSR 2203.1100 with the Registry Key:
HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Ica\GroupPolicy
Name: EnforceUserPolicyEvaluationSuccess
Type: REG_DWORD
Value: 0 (enables the current fix)
https://docs.citrix.com/en-us/citrix-virtual-apps-desktops/2203-ltsr/whats-new/cumulative-update-1/fixed-issues.html#vda-for-multi-session-os
👍 3
r
Looks like there is a bit of reg keys they added fix things. I wonder why they wouldn't bake it in the installer? Unless they are giving options.
n
I think there's multiple issues going on here as well. It looks like we have a LogonUI bug, Mac client bug, GP bug, (anymore?) and they all have the same behavior when they occur with the sessions not reconnecting properly.
⤴️ 1
r
Actually that's a good point. I was reading it all again trying to understand all the issues.
b
We've implemented 2203 CU1 + the reg key since a week and it seems stable (until now)🤞
👍 3
r
@Balint Oberrauch Good to hear that you stabilized the environment with the regkey 🙂
d
I’m testing it out with one of our VDA’s 🤞
c
Can someone give me please an overview , what exactly should the regkey fix now ? Only the reconnect problem or also the Logonui issue ? Thanks
m
I would expect the Fix to fix the Ghost sessions, aka session is visible as disconnected in Task Manager, but not in Studio/Director. So user would get a new session, which fails to load, if you use FSLogix, as the VHDX is still in use.
j
Same as @Christian Jöns - does this regkey fix logonUI.exe. Our long standing issue has been related to logonUI.exe preventing a clean user login.
d
@Jakspurs I’ve not had that issue really with 2203. What we have experienced is a duplicate session is created so you have to disconnect, then reconnect to get the original session.
👍🏻 2
Initial tests seem to indicate this reg key seems to help with the later with the duplicate sessions being created.
n
I got a reply from my escalation engineer late today: “Citrix engineering share an update that Microsoft Terminal Service does not call LogonNotify and that is when the issue occurs.” Guess I'll find out more soon.
🤔 1
😉 1
🤦‍♂️ 1
n
Are all of these issues happening on Server OS? I can't recall if anyone saw them on W10 single-session VDAs, and we're looking to move to 2203 CU1 by the end of the year.
👀 1
m
I can't tell you for 100%, as we don't use Single User VDA for VDI, just for RemotePC access.
n
@Nick Panaccio I think it's happening on Win 10 too according to this: https://worldofeuc.slack.com/archives/CKJADBQM6/p1662911111355239
m
As it's DaaS im quite sure they use Win10 MultiUser.
n
Support got back to me today, pushed back but this was their response: Citrix engineering has seen similar cases to this issue and reviewed the data. On Citrix engineering review the issue is related to the LogonNotify (https://learn.microsoft.com/en-us/windows/win32/api/wtsprotocol/nf-wtsprotocol-iwrdsprotocolconnection-logonnotify) not being called on login. For a similar case at Citrix the customer's onside support has opened a case with MS. The first recommendation from MS was to ensure that the FSLogix is up-to-date.
r
Thanks for the update. Hopefully they can address it with MS.
n
Just had the issue happen to me this evening, have some interesting findings: 1) My session auto disconnected due session idle timeout (this may not matter). 2) I reconnected, and was brought into a new session on another server in the pool and the FSLogix locked profile error was thrown. 3) Remoted into the server where my original session was disconnected and restarted the Citrix Desktop Service. 4) My original session reappeared as disconnected in Director with my UPN instead of sAMAccountName. 5) Launched the published desktop, and I was connected back to my original session. 6) Disconnected the session, and once again it disappeared in Director. 7) On the server where my original session was, I added the 2203 CU1 registry key fix HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Ica\GroupPolicy Name: EnforceUserPolicyEvaluationSuccess Type: REG_DWORD Value: 0 [CVADHELP-20129] 8) Restarted Citrix Desktop Service again. 9) Repeated step 5 and 6, but this time my session did not disappear from Director, and switched between Active/Disconnected states as expected. 10) Disconnected and reconnected several times with no issues. 11) Checked the System Event log on the original server and saw the a GP error when I was connecting back into my session: Processing of group policy failed for reason 0x80070005, this may align with [CVADHELP-20135], which is the same fix as [CVADHELP-20129] 12) Deleted the registry key fix and restarted the Citrix Desktop Service. 13) Disconnected and reconnected a few times. The first time I was able to connect back successfully, the second time my session disappeared again from Director and step 2 came back. 14) Repeated steps 7-9, and was connected back successfully every time.
💪 1
m
After upgrading to 2203.1100 + regkey, today we had the same error as always: User had a disconnected session, which was invisible in Director/Studio and therefore he was unable to reconnect, as his VHDX was locked.
n
There’s definitely multiple causes, is this a Windows or Mac user?
m
Windows
b
Citrix Support confirmed that the following keys are required on top of 2203 CU1: - Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect DWORD DisableGPCalculation 1 - Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect DWORD FastReconnect 0
n
Did you try restarting the Desktop Service to see if the old session returned?
So we need three reg fixes now? Lol
👍🏻 1
p
@Balint Oberrauch is that OS agnostic?
b
@Paul Brown I think so. customer is using WServer 2019
👍 1
n
Are there any side effects from enabling those keys?
I know DisableGPCalculation might stop Citrix policies from refreshing upon reconnect
b
that's correct. GPO's (ex. Drives or Printers based on location) are not recalculated on a reconnect
n
Not sure if that's an issue anyway, those are connected on initial launch
They don't disappear do they?
m
So if DisableGPCalculation is „bad“ do we know if only setting FastConnect would help?
n
Actually support just told me that today
At least to try it
I checked the related CVAD case - and I am checking if you can test w/ fast connect disabled too and then share the results of your testing, please. [HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect] "FastReconnect"=dword:00000000 ref: https://support.citrix.com/article/CTX256900/ica-session-reconnection-fails-on-2019-servers-with-vda-installed-if-reconnection-is-attempted-after-4550-minutes
On page 2 of this thread a bunch of people did the same, https://discussions.citrix.com/topic/416254-2203-ltsr-issues/ Andy on that thread also has a private fix for a non windows issue and says his issue seems resolved between all these fixes
FastReconnect is a 2019 feature so logical to disable that next before the GP Calculation
p
Looks like VDA 2209 is coming soon. Various cloud settings mention it. I hope it includes fixes for all these issues.
🤞🏻 1
🤞 3
n
Anyone been trying the multiple registry fixes? I haven’t had the issue happen to me yet with just FastReconnect off. Might expand testing and add that with the documented CU1 key.
j
Hello, So to fix the issue, we have just to put this reg key ? [HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect] "FastReconnect"=dword:00000000 I have the problem on Windows 2016, in my mind FastReconnect what a Windows 2019 feature.
r
Are the registry keys the final "fix", or are they going to add a fix to the next CU?
m
Guess we’ll now when the next version/CU hits.
Hehe
r
This caught my eye! When you attempt to connect to a VDA running version 2203 on a multi-session OS, the logonui.exe process might become unresponsive with a black screen or get terminated. However, event logs might appear. [CVADHELP-20338]
s
@Marco Hofmann did u applied 2203 CU2?
m
Omg no. It released yesterday. I’m not that kind of admin.
😂 2
s
Okay
m
What is going to be really interesting is which of the three registry keys Would still need to apply with cu2.
s
which one
m
HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Ica\GroupPolicy "EnforceUserPolicyEvaluationSuccess"=dword:00000000
HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect "FastReconnect"=dword:00000000
HKEY_LOCAL_MACHINE\SOFTWARE\Citrix\Reconnect "DisableGPCalculation"=dword:00000001
The question is, do we still need these ^ with 2203 CU2.
b
I figured out that "DisableGPCalculation" isn't needed on 2203 CU1. I've updated my lab today to 2203 CU2, the registry keys above are not merged in the new release.
m
I can confirm, I also don't use
DisableGPCalculation
for CU1.
p
Hello darkness my old friend...
🤣 1
best part is this is an upgrade from Cu1.
n
What the heck you doing in your environment 😂 we had no issues with 5 images
p
Nothing. This is a standalone VM.
Ran the cleanup wizard - validated that nothing exists... Run the install again and fails with the same error.
r
At times I do a normal uninstall, reboot, then run vda cleanup. Reboot, and install. But that is only when I have crazy issues
p
Spent a while on this and all i get is the same results, variations on this failure.
Uninstalled and ran VDA cleanup for the umpteenth time, and installed 1912 CU5 without issue. 🤷.
n
Stupid Q, but what security software do you use?
p
Crowdstrike. But i'm struggling to understand this error message.
Copy code
Product: Citrix HDX App Experience ×64 -- Uninstall the currently installed version of this package to proceed with a new installation.
It's not installed, so how is one to uninstall it?
n
Might be something left over in the registry such as the uninstall string. I would run the temporarily disable Crowdstrike, run the VDA cleanup utility again, make sure Workspace App is completely uninstalled, and try again 2203 CU2 installer.
p
we never install the workspace app on VDAs.
n
Might be on to something
I googled and see Return Value 3 before the 1708 could be “The system cannot find the path specified.”
p
ok. I think i'm gonna pass on this release. Followed the steps in the above ctx article and it won't install manually.
s
@Paul Brown do you have FSL Rules in this VM?
r
@Paul Brown can you DM me the install logs?
s
2203 CU2 is working for me well at customer production environment... Usually i use to face randomly machine was getting in to Unregistered stage...
👍 2
p
Ignore my issues above. Seems to be a single machine problem. Sister machine installed no issues....
💪 1
🙈 1
😅 2
d
Any update on the ghost sessions from someone updated to CU2? #Asking4aFriend 🙄
s
No Ghost session observed from last two days
👍 2
c
No ghost Sessions
👍 1
b
@Salim Hurjuk and @Christian Jöns: Do you have applied the reg keys as well?
s
No
b
nice!
c
No regkeys in place
r
Is there a CR due with these fixes as well?
b
Seems to be that CVAD 2212 is gonna be released soon.
r
Yeah just seen that mail 😁
r
Well, the 12 in 2212 is December 😛
r
😁
b
🤪
m
Bit late to the party, but I can also finally confirm, that I do not longer have issues with 2203.1100, if I apply those two registry keys on the VDA. We still had a huge problem with sessions hanging during logging off, but we finally found out that it was caused by Microsoft Defender, that didn't like the customers document management system.
p
I hope this is not true... So far 2203 CU2 seems to be working great in limited testing... https://discussions.citrix.com/topic/417794-since-updating-vda-to-2203-and-even-2203-cu2-users-have-ghost-sessions/
n
Without registry fixes?
n
Yeah, just read that this morning. Hopefully that's just a one-off.
s
This ghost may b due to FSL with App Masking may be properly not implemented
p
I'm testing with 2016 and no reg fixes with a test group of 4 VMs under heavy user rotation. So far everything coming up Milhouse - then read the above...
r
maybe someone should respond to the poor guy that it's been happening since 2008R2
😂 1
n
I just requested 2203 CU2 to be packaged for MCS persistent (W10) testing, which I expect to kick off in the next few weeks. I would also expect non-persistent W10 VDI testing to start soon, too. Hope that goes better, as they apparently had crashing issues, though I still think that was likely a thin client issue and not the VDA.
r
i still can't get the damn thing to install on the XDC and have all the services start. 😕
2203 CU2 on Server 2022
n
Have you tried rebooting
😂 2
r
42 times now
n
F8, with safe mode
n
slick smile
😂 1
s
OK 2008 @Ryan Gallier i think 2203 is not supported
r
What do you mean?
s
U mentioned above 2008 somewhere
n
I think he was referring to somebody else.
p
He said the zombie issues have been since 2008R2...
s
2203 CU2 I have tested from one week... working perfectly fine
Ok Nick
n
I have 2203 CU2 installed on my work VDA (W10, MCS persistent), and so far it has been flawless. Also had zero issues with CU1.
s
Okay Paul
p
I'm going to let my 4 servers bake over the weekend. Like most all in this thread been burned pretty hard before with supposed fixed VDAs.
👍 1
👍🏻 1
n
Thank you for your service...
s
:)
n
I’m curious to see if it fixes the LogonUI ghost sessions, only real issue we have from CU1 after the registry fixes were applied. It will be going live this weekend in our environment.
Server 2019 environment with FSLogix
s
@Nick Patel are u using Fslogix App Masking?
n
No
s
Anyway Hiding Windows Security from Start Menu?
c
s
@Christian Jöns actually I was asking @Nick Patel that he is hiding Windows Security from Start Menu?
n
We hide a lot of the control panel items and administrative tools options
s
Check anything from start menu
n
What are you referring to?
s
Windows Security or any system components if you try to hide then you may facing ghost session or disconnected session issue
n
Honestly, hiding Windows Security is just dumb anyway. Block access to the app via GPO and go about your day.
💯 1
There's a policy specifically for this (I don't mean AppLocker).
s
Yes i saw one wrote a blog article on it
r
I do like the blog by @Dennis. Very handy ( off topic)
n
@Marco Hofmann and @Balint Oberrauch: Going back to some previous comments, did either of you set the FastReconnect registry entry that was used prior to CU2? One of our IS execs had that same reconnect issue in 2203 CU2, and said that setting both FastReconnect and DisableGPCalculation resolved it for them.
n
We use the FastReconnect and EnforceUserPolicyEvaluationSuccess keys
Both with CU1 and 2
I think I’ve had one user with an issue since implementing those two keys
n
But not the DisableGPCalculation one?
n
Correct
n
Interesting, thanks.
c
@Nick Panaccio @Nick Patel wmi Filters are in place ?
n
WMI filter for?
n
Yeah, what WMI filters?
c
Found out that in environments with wmi filters, I need to set disablegpcalculation. Otherwise the reconnect takes relatively long 2-5 minutes
n
WMI filters on AD GPOs? I imagine that'll be a lot of places, unfortunately.
c
Jep for AD GPOs
r
good find @Christian Jöns
m
Just wanted to let you guys know, that we had to revert all 2203.2000 environments back to 1912.3000 as the UPS printing issues were getting out of hand, we had to act immediately: https://worldofeuc.slack.com/archives/CK6TCV3JN/p1676898039393609