Pages

Friday, 17 September 2010

AppSense News - User Rights Management is released today (AM and AMC 8.1)

Application Manager 8.1 and AppSense Management Center 8.1 have been release today on the AppSense web site.

Visit  myAppSense on  http://www.appsense.com/    to download the 8.1 releases of these two products. Performance Manager and Environment Manager are still on version 8.0.759.0 and 8.0.905.0 respectively.

The changes can be found in the release notes of AM and AMC. But the major change of note is the User Rights Management in Application Manager that we presented at the last event. The ability to make all users non administrators and elevate their rights to administrator for certain applications. I encourage you to have a play with this exciting new feature as it generated quite a bit of interest at the last event.

Application Manager 8.1


Application Termination

·    Enables Application Manager to shutdown running applications based on several triggers such as IP address change, a change to connecting device and change to configuration meaning that any application that is now prohibited that is running will be shutdown with various options to prevent loss of work.

Process Rules

·    Moving Trusted Applications into the rules structure and giving Application Manager an application centric edge by allowing network restrictions to be based on the application itself rather than by user, groups and devices, etc.

Application Groups

·    We have removed Signature Groups and Network Connection Groups and created Application Groups which give the ability to group any kind of rule item in a central library that can then be applied to our rules.

Disengaging functionality

·    Now you can turn off particular functionality from within AM, for example if you only want to control network access, you can disengage other areas such as Application Access Entitlement or User Rights Management, and leave ANAC enabled. Should you only want to enable User Rights Management then simply disengage the other areas.

User Rights Management

·    Elevation of user privileges for running applications: Allow an administrator to specify the applications run with administrator privileges. The user does not need an administrative account but is able to run specific applications with administrative privileges as defined by the Application Manager administrator.
·    Elevation of user privileges for running Control Panel applets: Many roaming users need to install printers, wireless networks, some users need to be able to change network and firewall settings, even simple tasks like changing the time & date, add / remove programs require Control Panel applets to be run as an administrator. User Rights Management can elevate privileges for individual applets, meaning a non administrator standard user can still make the changes they need to do their job.
·    Reducing privileges to restrict application rights: Allow an administrator to specify the applications run with reduced privileges. The user has administrator privileges by default, but is forced to run specific applications as non-administrator. Reducing rights can be a better option to removing administrator rights across the board and can mean a phased roll out. By running certain applications as an administrator, for example Internet Explorer, the user is able to change many undesirable settings, install applications and potentially open up the desktop to the Internet. User Rights Management can restrict an admin level user into running IE in a standard user mode, safe-guarding the desktop.
·    Reducing privileges to restrict access to system settings: Preventing an administrator from carrying out certain tasks can be advantageous. User Rights Management will give a higher level system administrator the ability to stop an administrative user from altering settings that they should not change. This could include firewall settings or to prevent the stopping of certain services. User Rights Management would take a user that has administrative privileges and reduce those privileges for certain processes. Although the user has administrator rights, the system administrator retains control of the environment.

Management Center

Membership Rules

·    Enabling the ability to provide dynamic rules where you can specify the criteria that determine automatically what deployment groups your machines join, items such as NetBIOS name, Active Directory information including Active Directory Security groups can be used to discover and add machines to deployment groups.
·    Console Integrated CCA installation
·    The functionality of the previous “CCA deployment tool” has now been integrated into the Management Console. This enables you to install the CCA from the Deployment Group’s computer page.


Computer Visibility

·    Giving the administrator visibility into how well the deployment of configuration and agents is going, how many computers are currently offline and what alerts processed.

Thursday, 16 September 2010

New Citrix Offline Client 6.0.1 released

I have recently had an issue when upgrading a Citrix farm including an upgrade to the offline client. This was a Windows 2003 x86 with XenApp 4.5/5 HFRP4. The install required an upgrade to HFPR06, Feature Pack enable, etc, etc.
The streamed apps all of a sudden stopped working and the Streaming Debug was not a great deal of help. Citrix have come to the rescue with a new Offline Client 6.0.1 which specifically fixed the problem I had. The link is below.


Issue Resolved
When streaming a profiled package to Version 5.2 of the plug-in, the following error message might occur: "An error occurred while importing the registry settings for your application."

I would strongly recommend applying this update.

XenApp 5 on Windows 2003 x86 - VMwareUser.exe

If you install HFRP06 onto the Windows 2003 x86 XenApp servers in VMware then when you launch a published desktop you may receive the error.

VMwareUser.exe. The Application failed to initialize properly (0x06d007e).

If you get this then you need to install an additional hotfix available here:

Wednesday, 15 September 2010

Overland Storage SnapSAN S2000 Is Verified as Citrix Ready

Overland Storage SnapSAN S2000 Is Verified as Citrix Ready. This is a new iSCSI SAN Solution Optimized for Virtualized Server Environments Is Trusted to Enhance Citrix Networking and Virtualization Solutions.


Depending on pricing this could be an interesting contender in the virtualisation space.

Product Overview:
Form Factor
S2000: 2U rackmount | E2000: 2U rackmount
http://www.overlandstorage.com/images/spacer.gif
System Scalability
SAS: 1.2TB - 57.6TB | SATA: 12TB - 192TB
Support for 300GB SAS, 500GB SATA, and D-Drive
http://www.overlandstorage.com/images/spacer.gif
Processing
Quad Core Intel Xeon Processor
http://www.overlandstorage.com/images/spacer.gif
Drive Types
S2000: Up to 12 SATA or SAS drives | E2000 Expansions: Up to 12 SATA or SAS drives (sold in 4-packs)
http://www.overlandstorage.com/images/spacer.gif
RAID Levels
0, 1, 5, 6, 10, 50, 60
http://www.overlandstorage.com/images/spacer.gif
Access Method
Access as a local device via iSCSI
http://www.overlandstorage.com/images/spacer.gif
Capabilities
Remote Management, Windows Integration, Mirroring, Replication, Snapshots, Auto-Provisioning, VMware Plugin
http://www.overlandstorage.com/images/spacer.gif

http://www.overlandstorage.com/images/spacer.gif

Tuesday, 14 September 2010

Delivery Services Console Discovery fails.

I have recently updated an existing XenApp 5 farm to FP2 then FP3. As a result of the install the Delivery Services Console fails to discover the XenApp farm.
I tried several remedial actions such as repairing the installation, etc but no fix.
The article from Citrix details the issue and recommends repairing the .Net Framework 2 installation. If this doesn’t work then a process of re-registration of the codebase was required. This is not a very pretty solution.


I found that the cause of the problem was actually a .Net Framework Hotfix.

In order to resolve my issues I simply did the following:
Uninstall KB976576
Reboot
Repair the “Citrix – XenApp Administration”


I hope this helps others who see this issue.

XenServer SR-IOV Support for Provisioning Services Virtual Machines

As companies virtualize more and more of their server infrastructure they are increasingly interested in virtualizing Provisioning Services hosts. However, the significant level of network IO that occurs on a Provisioning Services host can be challenging for the virtualization platform. This article describes how to virtualize Provisioning Services hosts with maximum performance and scalability by leveraging Single Route I/O Virtualization (SR-IOV) capabilities of Intel Niantic Network Interface Cards (NICs) with XenServer (versions 5.6 and later).