Pages

Thursday, 30 September 2010

New Release: XenServer 5.6 Feature Pack 1 Beta "Project Cowley"

The entire XenServer product team is pleased to announce the release of XenServer 5.6 Feature Pack 1 Beta “Project Cowley” to MyCitrix.com. The landing page for this release can be found here and contains links to all relevant resources for this release. The ISO downloads, Virtual Appliances, Beta license file and the beta documentation can all be found at the appropriate downloads section on MyCitrix.com. For external communication the use of the landing page URL is preferred.

What’s New in this release


Feature highlights for this beta release are:

·    Distributed Virtual Switching Integrated, Open vSwitch technology provides distributed fine-grained networking configuration and control policies – increasing visibility into XenServer virtual networks and providing a centralized Controller for administration of multiple vSwitches and cross-host internal networks. The open vSwitch also includes support for jumbo frames configuration on storage networks.

·    VM Protection and Recovery Policy based snapshotting and archiving of selected VMs across a XenServer resource pool enables administrators to schedule and recover when needed from the XenCenter management console.

·    Web Self-Service Portal Allows XenServer administrators to delegate VM rights to select individuals and enables users to request and access VMs via a simple to use web-based portal.

·    XenDesktop performance improvements Further enhances the best-in-class performance for XenDesktop on XenServer including local storage caching for better TCO and increased scalability via performance tuning in the control domain (requires a future version of XenDesktop to use).

·    Enhanced XenCenter Including StorageLink configuration entirely within XenCenter, workload reporting for VM utilization and chargeback.

·    Boot from SAN with multi-pathing support Boot XenServer hosts with Fibre Channel and iSCSI HBAs from a SAN, with multi-pathing support.

·    HA Restart Priority Configure HA policies to restart specific VM(s) first, such as StorageLink Gateway VMs or the Distributed vSwitch Controller VM.

·    Enhanced guest OS support for Windows 7 SP1, Windows Server 2008 R2 SP1, RHEL 6.0 (RTM), CentOS 6.0 (RTM), Oracle Enterprise Linux 6.0 (RTM), Debian Squeeze (32 and 64-bit), and SLES 11 SP1. Generic RHEL 5.x support..RHEL / CentOS / Oracle Enterprise Linux 5.0- 5.5 support with a generic “RHEL 5” template.



Please read the release notes and documentation for more details.



Support

Partner and customer support for this beta will be provided through the Cowley support forums which will be monitored by several members of the PM and engineering teams. The external bugtracker will also be utilized for collecting information from the field (see the announcement section on the forum for more details).



Post-Beta Deliverables

We are currently working hard to have an updated Evaluation Virtual Appliance available which will include the latest WLB and SL components as well as a pre-installed beta license file. We expect that the updated EVA will be available over the next couple of days.

Wednesday, 29 September 2010

Virtual Reality Check - Phase III Released

In this whitepaper Windows XP and Windows 7 are extensively compared. Specifically, the I/O behavior of Windows XP and Windows 7 is investigated in detail
The new whitepaper can be downloaded from the following link.
http://www.virtualrealitycheck.net/

Friday, 24 September 2010

Application Virtualization Smackdown

Great article by Ruben Spruijt and a link to another great white paper. This time its the Application virtualisation products that are under the microscope. A worthwhile read for anyone who deal with application delivery on a daily basis.

http://www.brianmadden.com/blogs/rubenspruijt/archive/2010/09/23/application-virtualization-smackdown-head-to-head-analysis-of-endeavors-citrix-installfree-microsoft-spoon-symantec-and-vmware.aspx

Thursday, 23 September 2010

Password Manager - What happens when a certificate expires?

Well the answer is lots of errors, some event log entries and a pretty un-usable Password manager solution.
I have just seen this in a customer site where an Internal Certifcate Authority server had been used to create the web certificates for the web interface and password manager servers. The certificates expired after a year and Password Manager stopped functioning.

In order to resolve the issue a new certificate was issued from the CA server and assigned to the relevent servers.
We then needed to resign the data following the guidelines in the following admin guide. Pages 316/317

In simple terms:
1. Create a new certificate.
Run CtxCreateSigningCert.exe from %ProgramFiles%\Citrix\MetaFrame Password Manager\Server folder. Enter the public key file name, the private key file name, and the time, in months, before the signing certificate expires. The new certificate is created.
Example:
ctxcreatesigningcert “C:\PublicKeyCert.cert” “C:\PrivateKeyCert.cert” “36”

2. Resign data at central store using the ctxsigndata command.
Example.
ctxsigndata -r mpmserver.mycompany.com/MPMService "C:\PrivateKeyCert.cert" mycompany.com AD

3. Verify data signatures at central store using the ctxsigndata command.
Example.
ctxsigndata -v mpmserver.mycompany.com/MPMService “https://mpmserver.mycompany.com/MPMService” mycompany.com AD

Done!

XenDesktop & XenApp: Next generation access security that fits your business

I am looking forward to the Citrix webinar this afternoon.
http://www.citrix.com/English/NE/events/event.asp?eventID=2303876

Should be an interesting session.

Friday, 17 September 2010

AppSense News - User Rights Management is released today (AM and AMC 8.1)

Application Manager 8.1 and AppSense Management Center 8.1 have been release today on the AppSense web site.

Visit  myAppSense on  http://www.appsense.com/    to download the 8.1 releases of these two products. Performance Manager and Environment Manager are still on version 8.0.759.0 and 8.0.905.0 respectively.

The changes can be found in the release notes of AM and AMC. But the major change of note is the User Rights Management in Application Manager that we presented at the last event. The ability to make all users non administrators and elevate their rights to administrator for certain applications. I encourage you to have a play with this exciting new feature as it generated quite a bit of interest at the last event.

Application Manager 8.1


Application Termination

·    Enables Application Manager to shutdown running applications based on several triggers such as IP address change, a change to connecting device and change to configuration meaning that any application that is now prohibited that is running will be shutdown with various options to prevent loss of work.

Process Rules

·    Moving Trusted Applications into the rules structure and giving Application Manager an application centric edge by allowing network restrictions to be based on the application itself rather than by user, groups and devices, etc.

Application Groups

·    We have removed Signature Groups and Network Connection Groups and created Application Groups which give the ability to group any kind of rule item in a central library that can then be applied to our rules.

Disengaging functionality

·    Now you can turn off particular functionality from within AM, for example if you only want to control network access, you can disengage other areas such as Application Access Entitlement or User Rights Management, and leave ANAC enabled. Should you only want to enable User Rights Management then simply disengage the other areas.

User Rights Management

·    Elevation of user privileges for running applications: Allow an administrator to specify the applications run with administrator privileges. The user does not need an administrative account but is able to run specific applications with administrative privileges as defined by the Application Manager administrator.
·    Elevation of user privileges for running Control Panel applets: Many roaming users need to install printers, wireless networks, some users need to be able to change network and firewall settings, even simple tasks like changing the time & date, add / remove programs require Control Panel applets to be run as an administrator. User Rights Management can elevate privileges for individual applets, meaning a non administrator standard user can still make the changes they need to do their job.
·    Reducing privileges to restrict application rights: Allow an administrator to specify the applications run with reduced privileges. The user has administrator privileges by default, but is forced to run specific applications as non-administrator. Reducing rights can be a better option to removing administrator rights across the board and can mean a phased roll out. By running certain applications as an administrator, for example Internet Explorer, the user is able to change many undesirable settings, install applications and potentially open up the desktop to the Internet. User Rights Management can restrict an admin level user into running IE in a standard user mode, safe-guarding the desktop.
·    Reducing privileges to restrict access to system settings: Preventing an administrator from carrying out certain tasks can be advantageous. User Rights Management will give a higher level system administrator the ability to stop an administrative user from altering settings that they should not change. This could include firewall settings or to prevent the stopping of certain services. User Rights Management would take a user that has administrative privileges and reduce those privileges for certain processes. Although the user has administrator rights, the system administrator retains control of the environment.

Management Center

Membership Rules

·    Enabling the ability to provide dynamic rules where you can specify the criteria that determine automatically what deployment groups your machines join, items such as NetBIOS name, Active Directory information including Active Directory Security groups can be used to discover and add machines to deployment groups.
·    Console Integrated CCA installation
·    The functionality of the previous “CCA deployment tool” has now been integrated into the Management Console. This enables you to install the CCA from the Deployment Group’s computer page.


Computer Visibility

·    Giving the administrator visibility into how well the deployment of configuration and agents is going, how many computers are currently offline and what alerts processed.

Thursday, 16 September 2010

New Citrix Offline Client 6.0.1 released

I have recently had an issue when upgrading a Citrix farm including an upgrade to the offline client. This was a Windows 2003 x86 with XenApp 4.5/5 HFRP4. The install required an upgrade to HFPR06, Feature Pack enable, etc, etc.
The streamed apps all of a sudden stopped working and the Streaming Debug was not a great deal of help. Citrix have come to the rescue with a new Offline Client 6.0.1 which specifically fixed the problem I had. The link is below.


Issue Resolved
When streaming a profiled package to Version 5.2 of the plug-in, the following error message might occur: "An error occurred while importing the registry settings for your application."

I would strongly recommend applying this update.