<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CTX-Blog</title>
	<atom:link href="http://ctxblog.gutzeit.ch/feed/langswitch_lang/en/" rel="self" type="application/rss+xml" />
	<link>http://ctxblog.gutzeit.ch</link>
	<description>powered by Ecki's Place</description>
	<lastBuildDate>Sun, 17 Oct 2010 20:54:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Missing XML file for Offline-Plugin 6.0.1 for Merchandising Server</title>
		<link>http://ctxblog.gutzeit.ch/2010/10/17/streaming_update_merchandising.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2010/10/17/streaming_update_merchandising.htm#comments</comments>
		<pubDate>Sun, 17 Oct 2010 20:54:05 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°Application Streaming]]></category>
		<category><![CDATA[°Clients]]></category>
		<category><![CDATA[°Merchandising Server]]></category>
		<category><![CDATA[°XenApp / Presentation Server]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[Offline-Plugin]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[XML]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=141</guid>
		<description><![CDATA[Wer bereits den Merchandising Server einsetzt, wird vermutlich ebenfalls über folgendes Problem gestolpert sein.

Citrix bietet ein Update für das Offline-Plugin an, welches 45 Fehler behebt. Als normaler Download steht das Update 6.0.1 seit einiger Zeit zur Verfügung. Wer aber im Merchandising Server das aktuelle Plugin sucht, wird es nicht finden. Auch eine manuelle  Aktualisierung findet das Update nicht :-(]]></description>
			<content:encoded><![CDATA[<p>If you are already working with Merchandising Server, you will probably know this problem.</p>
<p>Citrix provides an update for his Offline –Plugin that eliminates 45 bugs. The update 6.0.1 is available as regular download since many weeks now but if you try to find the update on your Merchandising Server you won’t find it. Even a manual rescan of the available plugins doesn’t help <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>The reason is a missing XML file, which Merchandising Server needs to control the installation and configuration of the plugins. Apparently Citrix won’t make this XML file available to the public, see <a href="http://community.citrix.com/display/ocb/2010/09/16/App+Streaming+-+6.0.1+LCM+Update">Citrix Blog: App Streaming-6.0.1 LCM Update</a></p>
<p>I have therefore taken the time to have a look at the following resources:</p>
<p>- <a href="http://www.citrix.com/tv/#videos/1447">Citrix-TV</a><br />
- <a href="http://support.citrix.com/proddocs/topic/merchandising-20/mer-metadata-wrapper.html">Citrix eDocs</a><br />
- <a href="http://community.citrix.com/display/receiver/Metadata+windows">Metadata Reference</a></p>
<p>and finally created my own XML file.</p>
<p>To save your time, I will provide you with the XML file needed here: <a href="http://ctxblog.gutzeit.ch/wp-content/uploads/XenAppStreamingMetaData.xml">XenAppStreamingMetaData.xml</a></p>
<p>On the Merchandising Server it is now possible to upload the actual Offline-Plugin together with the new XML file. After that step you can deploy the update through standard deliveries as usual.</p>
<p>Why Citrix doesn’t provide this file itself is a miracle to me. In fact this behavior doesn’t help to convince people to use Merchandising Server. I hope Citrix is rethinking the way they provide updates to Merchandising Server in the future…</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2010/10/17/streaming_update_merchandising.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>32bit icon option missing from the XenApp farm properties</title>
		<link>http://ctxblog.gutzeit.ch/2010/07/11/32bit-icons.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2010/07/11/32bit-icons.htm#comments</comments>
		<pubDate>Sun, 11 Jul 2010 17:51:41 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°XenApp / Presentation Server]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[AMC]]></category>
		<category><![CDATA[Bug]]></category>
		<category><![CDATA[Presentation Server]]></category>
		<category><![CDATA[Terminal Server]]></category>
		<category><![CDATA[XenApp]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=130</guid>
		<description><![CDATA[Ich bin vor kurzem über ein sehr seltsames Verhalten der Citrix AMC gestolpert, bei der die Option für 32bit Icon Support nicht angezeigt wurde, obwohl alle Prerequisites installiert waren. Nur durch einen Zufall sind wir auf die Lösung gekommen.

Das Problem betrifft alle XenApp Versionen die ich testen konnte, einschliesslich Presentation Server 4.5 und XenApp 5.0, sowohl für W2k3 als auch für W2k8.

Das Problem zeigt sich folgendermassen. In den Eigenschaften der Farm ist der Platz, an dem die 32bit Icon Option stehen sollte leer.]]></description>
			<content:encoded><![CDATA[<p>I recently stumbled uppon a really weired problem with 32bit icon support in XenApp. Under certain circumstances the AMC won&#8217;t show the option for 32bit icon support in the farm properties even if all prerequisites are perfectly met. We found out the reason for that behaviour only by accident.</p>
<p>The problem can be seen with all versions of Presentation Server 4.5 and XenApp 5.0 for w2k3 as well as for w2k8.</p>
<p>If the problem hits you, the farm properties won&#8217;t show the option for 32bit icon support, but there will only be a blank space <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p><img class="alignnone" title="No 32bit icon support in the AMC" src="http://ctxblog.gutzeit.ch/images/32bit-icons/32bit_icon_support_nok.jpg" alt="No 32bit icon support in the AMC" width="634" height="280" /></p>
<p>The reason for this odd behaviour can be found in the configuration of the farm-discovery. I sometimes use LOCALHOST as the hostname for discovery. This is helpful in situations where you have roaming profiles and IIS is not installed on the XenApp servers.</p>
<p>But if you configure discovery that way there will be no 32bit icon option in the AMC.</p>
<p><img class="alignnone" title="Configured with LOCALHOST" src="http://ctxblog.gutzeit.ch/images/32bit-icons/localhost_yes.jpg" alt="Configured with LOCALHOST" width="488" height="109" /></p>
<p>If you change the discovery option back to the local server</p>
<p><img class="alignnone" title="Konfiguriert mit &quot;Local Computer&quot;" src="http://ctxblog.gutzeit.ch/images/32bit-icons/localhost_no.jpg" alt="Konfiguriert mit &quot;Local Server&quot;" width="488" height="108" /></p>
<p>the missing option reappeares again.</p>
<p><img class="alignnone" title="32bit icon support available" src="http://ctxblog.gutzeit.ch/images/32bit-icons/32bit_icon_support_ok.jpg" alt="32bit icon support available" width="634" height="284" /></p>
<p>You can toggle that behaviour as you like. Admittedly this is not a common problem but it is odd and if you happen to see it, you will be warned&#8230;</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2010/07/11/32bit-icons.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Homedrive fails silently to mount at logon (Vista/Windows 7)</title>
		<link>http://ctxblog.gutzeit.ch/2010/05/04/homedrive-win7.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2010/05/04/homedrive-win7.htm#comments</comments>
		<pubDate>Tue, 04 May 2010 14:30:37 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[Windows]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Registry]]></category>
		<category><![CDATA[UAC]]></category>
		<category><![CDATA[Vista]]></category>
		<category><![CDATA[Windows 7]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=120</guid>
		<description><![CDATA[Nach dem Update auf Vista/Windows 7 wird das UserHome Verzeichnis beim Login nicht mehr verbunden. Alle anderen Drivemappings, welche über das Logonscript eingerichtet werden, funktionieren normal. Das passiert immer dann, wenn das UserHome über das AD Userobjekt und nicht über GPO gemappt wird. Es werden keine Fehler geloggt und auch sonst finden sich keinerlei Hinweise auf die Ursache des Problems :-(]]></description>
			<content:encoded><![CDATA[<p>After the update to Vista/Windows 7, mapping of the UserHome drive fails silently at logon. All other drive mappings made by a logon script are successful. This happens always if the UserHome is mapped through the AD user-object. UserHome mapping configured by GPO is not affected. There are no error messages logged and it is hard to find a reason for this behavior <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>Disabling UAC helps, but should not be the final solution, since it opens up many security holes.</p>
<p>Not really a Citrix problem but annoying if you happen to stumble upon it. Since it took me some time to find a solution, i thought it might be a good idea to post it here.</p>
<p>The following registry key allows again for a successful UserHome mapping: </p>
<blockquote><p>Windows Registry Editor Version 5.00</p>
<p>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System]<br />
&#8220;EnableLinkedConnections&#8221;=dword:00000001</p></blockquote>
<p>The original solution has been posted <a href="http://forums.techarena.in/vista-security/681760.htm">here</a>.</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2010/05/04/homedrive-win7.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Laptop and XenServer with GNOME on USB disk</title>
		<link>http://ctxblog.gutzeit.ch/2009/07/02/xenserver_usb.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2009/07/02/xenserver_usb.htm#comments</comments>
		<pubDate>Thu, 02 Jul 2009 20:08:04 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°XenServer]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[5.5]]></category>
		<category><![CDATA[GNOME]]></category>
		<category><![CDATA[Installation]]></category>
		<category><![CDATA[Notebook]]></category>
		<category><![CDATA[Tutorial]]></category>
		<category><![CDATA[USB]]></category>
		<category><![CDATA[XenCenter]]></category>
		<category><![CDATA[XenServer]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=77</guid>
		<description><![CDATA[Wäre es nicht toll, wenn man seine XenServer Umgebung auf einer USB Disk immer mit dabei haben könnte ?

Wenn die USB Disk direkt am eigenen Notebook laufen würde ?

Und wenn man nicht eine zusätzliche Maschine bräuchte, um den XenServer zu managen ?

Wie das geht, habe ich in einem einfachen Tutorial dokumentiert...]]></description>
			<content:encoded><![CDATA[<p>Wouldn&#8217;t it be nice to have your XenServer environment allways with you on a USB disk ?</p>
<p>Wouldn&#8217;t it be nice, if this USB disk would function with your own notebook ?</p>
<p>And that you don&#8217;t need a second machine to run XenCenter on it ?</p>
<p>That this is possible and how to achieve this, is documented in my last tutorial. In this tutorial we will install XenServer on a USB harddisk attached to a laptop, then install X server and GNOME on this disk and then run an RDP session to a VM running on the XenServer and providing us with XenCenter.</p>
<p>A &#8220;demo in a box&#8221; <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>The tutorial can be downloaded here: <a href="http://ctxblog.gutzeit.ch/wp-content/uploads/pdf/XenServer_and_Gnome_on_your_USB_disk_EN.pdf">&#8220;XenServer_and_Gnome_on_your_USB_disk_EN.pdf&#8221;</a><br />
<del datetime="2009-07-03T19:35:51+00:00">For the moment, this tutorial is availabel only in German, but i will upload an english version soon, so stay tuned&#8230;</del><br />
The english version is now available too&#8230;</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2009/07/02/xenserver_usb.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AAC and IE 8.0</title>
		<link>http://ctxblog.gutzeit.ch/2009/03/24/aac_ie8.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2009/03/24/aac_ie8.htm#comments</comments>
		<pubDate>Tue, 24 Mar 2009 19:50:12 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°AAC]]></category>
		<category><![CDATA[°Access Gateway]]></category>
		<category><![CDATA[°Internet Explorer]]></category>
		<category><![CDATA[°Web Interface]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[4.5]]></category>
		<category><![CDATA[AAC]]></category>
		<category><![CDATA[Access Gateway]]></category>
		<category><![CDATA[Advanced]]></category>
		<category><![CDATA[CAG]]></category>
		<category><![CDATA[HotFix]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[LogonPoint]]></category>
		<category><![CDATA[Optimierung]]></category>
		<category><![CDATA[Update]]></category>
		<category><![CDATA[Web Interface]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=51</guid>
		<description><![CDATA[Vor wenigen Tagen wurde der IE 8.0 offiziell zum Download freigegeben. Da er demnächst auch als Windows Update verfügbar sein wird, werden schnell viele User mit diesem Browser auf bestehende AAC Deployments zugreifen wollen. Dies gestaltet sich in der Defaulteinstellung jedoch leider als problematisch. So sieht eine AAC Portalseite mit dem IE 8.0 aus:]]></description>
			<content:encoded><![CDATA[<p>Some days ago, Microsoft officialy released IE 8.0. Since IE 8.0 will be available trough Windows Update soon, more and more users will hit existing AAC deployments with this browser. Unfortunately this is not working as expected. This is, how an AAC portal page looks like in IE 8.0 with default settings:</p>
<p><img src="http://ctxblog.gutzeit.ch/images/aac_ie8/portal_ctx.jpg" alt="Portal" /><br />
<img src="http://ctxblog.gutzeit.ch/images/aac_ie8/portal_owa.jpg" alt="OWA" /></p>
<p>The layout is crushed, links are missing and OWA is nearly unusable <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>A small change in the file <strong><em>C:\Inetpub\wwwroot\CitrixSessionInit\NUI.aspx</em></strong> solves the display issue by forcing IE 8.0 into IE 7.0 compatibility mode.</p>
<p>It is sufficient to add the following line in the header of the NUI.aspx file:</p>
<p><strong><em>&lt;meta http-equiv=&#8221;X-UA-Compatible&#8221; content=&#8221;IE=EmulateIE7&#8243; /&gt;</em></strong></p>
<p>Your header might look like this after the change:</p>
<p><code><em>&lt;html xmlns="http://www.w3.org/1999/xhtml"&gt;<br />
&lt;head&gt;<br />
&lt;title&gt;Citrix Access Gateway&lt;/title&gt;<br />
<span style="color: #ff0000;"><strong>&lt;meta http-equiv="X-UA-Compatible" content="IE=EmulateIE7" /&gt;</strong></span><br />
&lt;meta name="GENERATOR" content="Microsoft Visual Studio .NET 7.1" /&gt;<br />
&lt;meta name="CODE_LANGUAGE" content="C#" /&gt;<br />
&lt;meta name="vs_defaultClientScript" content="JavaScript" /&gt;<br />
&lt;meta name="vs_targetSchema" content="http://schemas.microsoft.com/intellisense/ie5" /&gt;<br />
&lt;link rel="SHORTCUT ICON" href="themes/default/images/favicon.ico" type="image/vnd.microsoft.icon" /&gt;<br />
&lt;base id="baseElement" href="" runat="server" /&gt;<br />
&lt;link id="cssElement" rel="stylesheet" href="" runat="server" /&gt;<br />
&lt;!--[if IE]&gt;<br />
&lt;style type="text/css"&gt;</em></code></p>
<p>Immediately your portal is rendered again as it should be <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><img src="http://ctxblog.gutzeit.ch/images/aac_ie8/portal_ctx_fixed.jpg" alt="Portal" /><br />
<img src="http://ctxblog.gutzeit.ch/images/aac_ie8/portal_owa_fixed.jpg" alt="OWA" /></p>
<p>This is not a final solution for the problem, but until Citrix releases a fix for this issue it will do&#8230;</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2009/03/24/aac_ie8.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Smart Card Single Sign On with PNAgent</title>
		<link>http://ctxblog.gutzeit.ch/2008/10/21/smartcard_sso.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2008/10/21/smartcard_sso.htm#comments</comments>
		<pubDate>Tue, 21 Oct 2008 13:51:00 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°Clients]]></category>
		<category><![CDATA[°Web Interface]]></category>
		<category><![CDATA[°XenApp / Presentation Server]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Authentifizierung]]></category>
		<category><![CDATA[Client]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Passthrough]]></category>
		<category><![CDATA[Passthru]]></category>
		<category><![CDATA[PNAgent]]></category>
		<category><![CDATA[Presentation Server]]></category>
		<category><![CDATA[Single Sign On]]></category>
		<category><![CDATA[Smart Card]]></category>
		<category><![CDATA[SmartCard]]></category>
		<category><![CDATA[XenApp]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=50</guid>
		<description><![CDATA[Alle verfügbaren Dokumentationen zum Thema "Single Sign On" oder "Credential passthrough" mit SmartCard und Citrix Clients beschränkt sich leider auf den Gebrauch der Program Neighborhood, wie folgende Anleitung von <a title="Brianmadden" href="http://www.brianmadden.com/content/article/Configuring-Smart-Card-authentication-for-Citrix-Presentation-Server" target="_blank">Brianmadden </a> beispielhaft zeigt. Diesen Client setze ich bei Kundenprojekten aber seit Jahren nur noch in Ausnamefällen ein. Statt dessen verwende ich meistens den PNAgent, oder den Web Client.

Diese Clients entzogen sich aber bisher dem Passthrough der SmartCard PIN, da sie die APPSRV.INI ignorierten und daher die notwendigen Einstellungen nicht übernahmen.]]></description>
			<content:encoded><![CDATA[<p>All available documentation regarding &#8220;Single Sign On&#8221; or &#8220;Credential pass-through&#8221; with Smart Card and Citrix clients is limited to the Program Neighborhood client only, as can be seen exemplarily at <a title="Brianmadden" href="http://www.brianmadden.com/content/article/Configuring-Smart-Card-authentication-for-Citrix-Presentation-Server" target="_blank">Brianmadden </a>. I don&#8217;t use this client in customer projects for a couple of years now but use the PNAgent or the Web client instead.</p>
<p>With these clients, a pass-through of the Smart Card PIN didn&#8217;t work, because they do not read their settings from the APPSRV.INI, which would allow for the neccessary settings.</p>
<p>Since client version 10.0, an Active Directory Group Policy Template can be found in every client installation directory, named &#8220;icaclient.adm&#8221;. All clients, starting with 10.0 now read the policy settings first and make use of the APPSRV.INI only in case, no policy is defined. This new feature allows now for a &#8220;Single Sign On&#8221; with SmartCard and PNAgent.</p>
<p>Here is, what you need to do, to get it up and running:</p>
<p><strong>1. On the Presentation Server /XenApp Server</strong></p>
<ul>
<li>Confirm proper operation by logging in to a full desktop on the Citrix server. Insert a Smart Card and it should begin reading it. Enable “<strong>Trust requests sent to the XML Service</strong>”. This is necessary if using smart card pass through logon.</li>
</ul>
<p><strong>2. On the Web Interface Server</strong></p>
<ul>
<li>SSL must be configured and active (a web server certificate has to be installed) and the  &#8220;<strong>Directory Service Mapping</strong>&#8221; has to be activated. This option can be found in the IIS Manager below the properties of the &#8220;Web Sites&#8221; folder:</li>
<p><img style="vertical-align: baseline;" src="http://ctxblog.gutzeit.ch/images/smartcard_sso/WebSites01.jpg" alt="Web Sites properties" width="311" height="269" /><img style="vertical-align: baseline;" src="http://ctxblog.gutzeit.ch/images/smartcard_sso/DirectoryServiceMapper.jpg" alt="Directory Service Mapper" width="363" height="314" /></p>
<li>The Web Interface site itself must now be configured. Open the Citrix Access Suite Management Console on the Web Interface server and run discovery if necessary to find the Web Interface site you wish to work with.<br />
Under “Configure Authentication” select “<strong>Smart Card with Passthrough</strong>”.
</li>
</ul>
<p><strong>3. Registry</strong></p>
<ul>
<li>Check HKLM\System\CurrentControlSet\Control\TerminalServer\WinStations\ICA-tcp the value for &#8220;<strong>UseDefaultGina</strong>&#8221; should be 0 (1 disables the CtxGina).</li>
</ul>
<p><strong>4. Active Directory Policy</strong></p>
<ul>
<li>Import the ADM template into a Policy</li>
<li>Go to the &#8220;<strong>User Configuration</strong>&#8221; of the policy, leave the Computer part set to “not configured”. The following settings have to be enabled:</li>
<p><img src="http://ctxblog.gutzeit.ch/images/smartcard_sso/Policy01.jpg" alt="Citrix Policy" width="550" height="364" /></p>
<li>&lt;PolicyName&gt;\User Configuration\Administrative Templates\Citrix Components\Presentation Server Client\User Authentication\Smart Card Authentication has to be &#8220;<strong>Enabled</strong>&#8221; and &#8220;<strong>Allow Smart Card Authentication</strong>&#8221; and &#8220;<strong>Use pass-through authentication for PIN</strong>&#8221; have to be activated. </li>
</ul>
<ul>
<li>Leave everything else to &#8220;Not Configured&#8221;, provided that you are testing just Smart Card and PIN pass-through. </li>
</ul>
<p>Now &#8220;Single Sign On&#8221; with Smart Card and PNAgent should work <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>Unfortunately these instructions only work for Windows XP and Server 2003. At the moment, no Citrix client, including 11.0, allows for PIN pass-through with Vista and 2008 Server <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>Here are some more interesting links:</p>
<ul>
<li><a title="ERROR: SmartCard Support is not allowed on pass through servers" href="http://support.citrix.com/article/CTX115521" target="_blank">Error: Smartcard support is not allowed on pass through servers</a></li>
<li><a title="Internet Explorer 7 Known Issues" href="http://support.citrix.com/article/CTX111625" target="_blank">Internet Explorer 7 Known Issues</a></li>
<li><a title="Readme for Web Interface 4.6 for Presentation Server - German" href="http://support.citrix.com/article/CTX113745" target="_blank">Readme for Web Interface 4.6 for Presentation Server &#8211; German</a></li>
</ul>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2008/10/21/smartcard_sso.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Update &#8211; AAC tuning, part 4</title>
		<link>http://ctxblog.gutzeit.ch/2008/07/29/update_aac_tuning_teil_4.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2008/07/29/update_aac_tuning_teil_4.htm#comments</comments>
		<pubDate>Tue, 29 Jul 2008 20:53:25 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°AAC]]></category>
		<category><![CDATA[°Access Gateway]]></category>
		<category><![CDATA[°Web Interface]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[4.5]]></category>
		<category><![CDATA[AAC]]></category>
		<category><![CDATA[Access Gateway]]></category>
		<category><![CDATA[Advanced]]></category>
		<category><![CDATA[CAG]]></category>
		<category><![CDATA[LogonPoint]]></category>
		<category><![CDATA[Revision]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=49</guid>
		<description><![CDATA[Das Dokument wurde ein wenig erweitert, nachdem ein Kunde einen sehr dunklen Blauton für den farbigen Querbalken verwenden wollte. Die Beschriftung des Balkens war daraufhin nicht mehr lesbar. Daher musste die Schriftfarbe innerhalb des Balkens auf Weiss gesetzt werden, um wieder für den nötigen Kontrast zu sorgen. Wie das geht wurde nun dem Dokument hinzugefügt.]]></description>
			<content:encoded><![CDATA[<p>I had to upgrade the document, because a customer wanted to set the color of the bar to a dark blue. The caption inside the bar could not be read anymore after this change, so we had to change the color of the caption to white. This way we got the contrast needed back. How to do that is added to the document now.</p>
<p>The howto is written in german. A translation into english is not available at the moment. Since the pdf utilizes a lot of pictures, you might be able to understand it anyway. As soon as i find the time, i will provide a translated version. Until then, you can download the german version here: <strong><a href="http://ctxblog.gutzeit.ch/wp-content/pdf/AAC4_5_CustomizeLogonPoint_Rev1.1_DE.pdf">AAC4_5_CustomizeLogonPoint_Rev1.1_DE.pdf</a></strong></p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2008/07/29/update_aac_tuning_teil_4.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>AAC tuning, part 4</title>
		<link>http://ctxblog.gutzeit.ch/2008/07/12/aac_tuning_4.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2008/07/12/aac_tuning_4.htm#comments</comments>
		<pubDate>Sat, 12 Jul 2008 21:29:09 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°AAC]]></category>
		<category><![CDATA[°Access Gateway]]></category>
		<category><![CDATA[°Web Interface]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[4.5]]></category>
		<category><![CDATA[4.5.7]]></category>
		<category><![CDATA[AAC]]></category>
		<category><![CDATA[Access Gateway]]></category>
		<category><![CDATA[Advanced]]></category>
		<category><![CDATA[CAG]]></category>
		<category><![CDATA[LogonPoint]]></category>
		<category><![CDATA[Parameter]]></category>
		<category><![CDATA[SAC]]></category>
		<category><![CDATA[Secure Access Client]]></category>
		<category><![CDATA[Tuning]]></category>
		<category><![CDATA[web.config]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=47</guid>
		<description><![CDATA[Die Optik eines AAC Logon Points ist leider nicht so leicht an die CI einer Firma anpassbar, wie das Citrix Web Interface. Wie es trotz fehlender Assistenten geht, möchte ich in diesem Beitrag zeigen.]]></description>
			<content:encoded><![CDATA[<p>To adjust the look of an AAC LogonPoint at the CI of a company is not as easy as it is with a Citrix Web Interface deployment. In the following PDF i will show you a way to get there anyway.</p>
<p>The howto is written in german. A translation into english is not available at the moment. Since the pdf utilizes a lot of pictures, you might be able to understand it anyway. As soon as i find the time, i will provide a translated version. Until then, you can download the german version here: <strong><a href="http://ctxblog.gutzeit.ch/wp-content/pdf/AAC4_5_CustomizeLogonPoint_Rev1.1_DE.pdf">AAC4_5_CustomizeLogonPoint_Rev1.1_DE.pdf</a></strong></p>
<p>This is, what your LogonPoint could look like after reading this document:<br />
<img src='http://ctxblog.gutzeit.ch/images/aac_tuning_4/customized_logonpoint_01.jpg' alt='Angepasster LogonPoint - Login' class='alignleft' /><img src='http://ctxblog.gutzeit.ch/images/aac_tuning_4/customized_logonpoint_02.jpg' alt='Angepasster LogonPoint - Portal' class='alignright' /></p>
<p>Additional documentation about customizing an AAC LogonPoint can be found here:</p>
<li><a href="http://support.citrix.com/article/CTX108617" target="_blank">Basic Customization of the Advanced Access Control 4.x Logon Point</a></li>
<li><a href="http://support.citrix.com/article/CTX116751" target="_blank">How to Customize the Default View for Web Interface 4.6 When it is Embedded in Access Gateway Advanced Edition</a></li>
<p>And here you can find a currently very interesting article about AAC and FireFox 3.0:</p>
<li><a href="http://support.citrix.com/article/CTX117620" target="_blank">Access Interface Appears Incorrectly with Firefox 3.0</a></li>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2008/07/12/aac_tuning_4.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IE kiosk mode</title>
		<link>http://ctxblog.gutzeit.ch/2008/06/18/ie_kiosk_mode.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2008/06/18/ie_kiosk_mode.htm#comments</comments>
		<pubDate>Wed, 18 Jun 2008 18:49:34 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°XenApp / Presentation Server]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[Windows 2003 Server]]></category>
		<category><![CDATA[GPO]]></category>
		<category><![CDATA[Internet Explorer]]></category>
		<category><![CDATA[Kiosk]]></category>
		<category><![CDATA[Parameter]]></category>
		<category><![CDATA[Presentation Server]]></category>
		<category><![CDATA[Registry]]></category>
		<category><![CDATA[SmartCard]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=48</guid>
		<description><![CDATA[Ich musste gerade bei einem Kunden dafür sorgen, dass der Internet Explorer ohne Navigationsleisten und sonstige Benutzerschnittstellen startet, um eine browserbasierte Applikation zum SmartCard Rollout zu veröffentlichen. Die Suche nach einer Lösung gestaltete sich hierbei schwieriger als erwartet...]]></description>
			<content:encoded><![CDATA[<p>I recently had a customer that wanted Internet Explorer to be published as a locked down version without toolbars and userinterface. The goal was to publish a browser based application to allow for a smart card rollout and not allowing users to browse away from this site. The search for a solution was harder than expected.</p>
<p>The solution most frequently found with Google was the built in &#8220;kiosk mode&#8221; of Internet Explorer. This mode can be activated by appending the parameter -k to the IE shortcut. For more details see <a href="http://support.microsoft.com/kb/154780">http://support.microsoft.com/kb/154780</a>. In this mode the IE starts in full screen mode, but without the ability to access the navigation panes, toolbars and menus as it would be possible when switching to full screen view by pressing F11. To end such a session, the user is forced to use the Alt. + F4 hotkey and all navigation in IE has to be done through hotkeys too. Not the solution we wanted for standard users <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>The next approach were Microsoft Group policies, but they too had too many constraints and issues. One issue here was, that there is no way, to hide the standard toolbars through group policies. It would have been therefore inevitable to manipulate the HKCU branch of the users registry at logon. This is a subject, where the otherwise &#8220;overloaded&#8221; IE policies are not detailed enough <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_sad.gif' alt=':-(' class='wp-smiley' /> </p>
<p>The solution came through a VBS object. Internet Explorer can be addresses and controlled through VBS. This gave me the possibility to adjust the user interface of the IE and to hide all toolbars, navigation panes and menues, without disabling basic functionality. The following code starts IE with a predefined URL and makes it much more difficult for users to break out of the predefined environment <img src='http://ctxblog.gutzeit.ch/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p><code>DIM IE<br />
Set IE = CreateObject("InternetExplorer.Application")<br />
IE.Navigate "http://this.is.the.url.to.be.shown"<br />
IE.Visible=True<br />
IE.Toolbar=no<br />
IE.Menubar=no<br />
IE.Statusbar=no<br />
IE.Width=750<br />
IE.Height=600<br />
IE.Resizable=yes<br />
'IE.Top=5<br />
'IE.Left=5</code></p>
<p>The entry <em>IE.Navigate</em> stands for the target URL. Take care that the whole URL is surrounded by double quotes. Optional parameters are for the windows size <em>(IE.Width/IE.Height)</em> and the windows position on the users desktop <em>(IE.Top/IE.Left)</em>.</p>
<p><img src="http://ctxblog.gutzeit.ch/images/ie_kiosk_mode/ie_kiosk_mode_01.jpg" alt="IE kiosk mode" /></p>
<p>This script works perfect under Windows XP and 2003 Server. With Vista and 2008 Server administrative privileges are required!</p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2008/06/18/ie_kiosk_mode.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CAG hotfix 4.5.7 Rev. A available</title>
		<link>http://ctxblog.gutzeit.ch/2008/05/15/cag_hotfix_457_rev_a.htm</link>
		<comments>http://ctxblog.gutzeit.ch/2008/05/15/cag_hotfix_457_rev_a.htm#comments</comments>
		<pubDate>Thu, 15 May 2008 20:01:31 +0000</pubDate>
		<dc:creator>ecki</dc:creator>
				<category><![CDATA[°Access Gateway]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[4.5.5]]></category>
		<category><![CDATA[4.5.6]]></category>
		<category><![CDATA[4.5.7]]></category>
		<category><![CDATA[Access Gateway]]></category>
		<category><![CDATA[CAG]]></category>
		<category><![CDATA[HotFix]]></category>
		<category><![CDATA[Revision]]></category>
		<category><![CDATA[SSL-VPN]]></category>
		<category><![CDATA[Update]]></category>

		<guid isPermaLink="false">http://ctxblog.gutzeit.ch/?p=46</guid>
		<description><![CDATA[Seit wenigen Tagen stehen eine aktualisiert Version des Hotfix AG2000_v457 bei Citrix zum Download bereit. Diese Aktualisierung beseitigt eine Sicherheitslücke in der Access Gateway Implementierung der 4.5er Reihe. Es stehen Fixes für CAG 4.5.5, 4.5.6 und 4.5.7 zur Verfügung.

Vor allem Nutzer der SSL VPN Komponente des Access Gateways sollten den Fix schnellstmöglich einspielen.]]></description>
			<content:encoded><![CDATA[<p>A few days ago, Citrix released the hot fix AG2000_v457 Rev. A. This release fixes a security issue found in all 4.5 releases of the Access Gateway. Fixes for Access Gateway 4.5.5, 4.5.6 and 4.5.7 are available for download.</p>
<p>Especially if you use the SSL VPN feature of the Access Gateway, it is recommended to install this fix as soon as possible.</p>
<p>The download and readme for CAG 4.5.7 Rev. A can be found here: <a title="Download  hot fix AG2000_v457 Rev. A" href="http://support.citrix.com/article/CTX117001" target="_blank">CTX117123, Hot fix AG2000_v457 Rev. A<br />
</a></p>
<p>Regards<br />
Ecki</p>
]]></content:encoded>
			<wfw:commentRss>http://ctxblog.gutzeit.ch/2008/05/15/cag_hotfix_457_rev_a.htm/feed/langswitch_lang/en/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

