Citrix Receiver 4.1 and Desktop Pass Through - Simple.... Or so you would have thought! SSONSVR.exe has other ideas!
So, you have a Citrix XenApp environment and you want the users to just be able to log in to their workstation and run their published apps without having to do anything special such as launching the Citrix Receiver client logging into it and then running a published app. In this way the users don't even need to know or care that their published apps aren't even installed on their machine but on some server in a distant land!
This is exactly what I needed to achieve in our customers new Windows 8.1 Citrix XenDesktop 7.5 VDI environment, where there is a mixture of applications delivery via MS SCCM 2012 R2 and also Citrix XenApp 7.5. However, we found that there were issues along the way that had us scratching our heads. This eventually turned out to be an issue with the latest Citrix Receiver 4.1 client, namely SSONSVR.exe that was failing to start and was installed into the Gold Image.
Below, I will detail the steps that are necessary to get Domain User Pass-Through working and specifically if you get the issue with the Citrix 4.1 client.
Server Side Config
Now on my Windows 8.1 Client VDI's I had the Citrix 4.1 receiver already installed as part of the Workstation image. I had wrongly assumed that enabling the pass-through on the server and deploying .adm files in a GPO would be all there was to it. However, I was wrong. When I ran the Citrix Receiver and clicked on 'Applications' I would be presented with an error that the published applications weren't available and to try again later'. I discovered that SSONSVR.exe was not being started by the Receiver client as it should be, and this is the necessary mechanism that is used to force pass-through (See Citrix KB) . After searching through various websites and forums I was able to find reference to this very issue and how others fixed it which I have detailed below.
Client Side Config
This is exactly what I needed to achieve in our customers new Windows 8.1 Citrix XenDesktop 7.5 VDI environment, where there is a mixture of applications delivery via MS SCCM 2012 R2 and also Citrix XenApp 7.5. However, we found that there were issues along the way that had us scratching our heads. This eventually turned out to be an issue with the latest Citrix Receiver 4.1 client, namely SSONSVR.exe that was failing to start and was installed into the Gold Image.
Below, I will detail the steps that are necessary to get Domain User Pass-Through working and specifically if you get the issue with the Citrix 4.1 client.
Server Side Config
- Right Click 'Authentication' and check 'Domain Pass-through' and click 'OK'
- From one of your workstations that has the Citrix Receiver Client installed browse to "%programfiles%\Citrix\ICA Client\Configuration" and copy the ICACLIENT.adm file to a DC in your environment
- Create a new GPO or add this adm file to an already existing GPO.
- Within the GPO, browse to 'Computer Configuration/Policies/Administrative Templates/Classic Administrative Templates/Citrix Components/Citrix Receiver/User Authentication'
- Select 'Local User Name and Password' select enable and check 'Enable Pass-Through authentication and 'Allow pass-through authentication for all ICA connections.
- Ensure that this policy applies to the computers in your organisation that require the pass-through
- In the properties of the XenApp packages that you create, under the descriptions and keywords field type in 'KEYWORDS:Auto' . This will ensure that the application is automatically subscribed into the receiver for the user. If this isn't done then the application WILL NOT appear in the start menu until you manually fire up the receiver and add it to the main screen within the receiver.
Now on my Windows 8.1 Client VDI's I had the Citrix 4.1 receiver already installed as part of the Workstation image. I had wrongly assumed that enabling the pass-through on the server and deploying .adm files in a GPO would be all there was to it. However, I was wrong. When I ran the Citrix Receiver and clicked on 'Applications' I would be presented with an error that the published applications weren't available and to try again later'. I discovered that SSONSVR.exe was not being started by the Receiver client as it should be, and this is the necessary mechanism that is used to force pass-through (See Citrix KB) . After searching through various websites and forums I was able to find reference to this very issue and how others fixed it which I have detailed below.
Client Side Config
- On a test machine installed Citrix Receiver 3.4
- Browse to '%programfiles%\Citrix\ICA Client' and copied 'pnsson.dll' and 'ssonsvr.exe' to the desktop
- Uninstalled the Citrix Receiver 4.1 client.
- Installed Citrix Receiver 4.1 from the command line using the following switches \\YourServerName\apps$\citrixreceiver.exe /includeSSON ENABLE_SSON="Yes" UseCategoryAsStartMenuPath="True" StartMenuDir="\Citrix Applications" STORE0="Store Service;https://YourServerName.FQDN/Citrix/Store/discovery;on;Store Service" (NOTE Where it says 'Store Service' replace this with the name of your Citrix 'STORE' as shown on the Store Front Server under 'Stores' The URL is also shown in the same section. For more detailed information under the stores menu select 'Export Provisioning file' and view the info that it contains. StartMenuDir="This is the heading that you want in Your users start menu for their published apps so change accordingly")
- Created a 'Windows Start up' shortcut for the 'All Users' profile to auto start Citrix Receiver so the user does not automatically have to run the Receiver manually before the start menu auto populates. The shortcut contains the following '%programfiles%\Citrix\SelfServicePlugin\SelfService.exe -poll' and placed in 'C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp'
- Added the above into our Gold Image and redeployed the image to our users. However, reimaging is not always practical so you could script the reinstall of the client and replace the older versions of the SSONSVR.exe and pnsson.dll
I hope this helps others who are needing this to function in their environment. I can only assume that there must be a bug in the 4.1 Receiver that prevents the SSONSVR.exe from starting correctly, although I have heard (but not tested) that it starts correctly in a non-pass-through environment!
cheers
Stolly
Comments
Post a Comment