Archive for the ‘IGEL’ Category

Tip: Getting struggled with SHA2 certificates and the Citrix Linux Receiver?

Friday, September 5th, 2014

Hi Folks,

if you got issues with SHA2 certificates in the past and if used together with a Citrix environment you should try the latest IGEL 5.04.100 LX/OS firmware.

The new firmware contains a updated Citrix Receiver 13 version which comes now with SHA2 certificate support, important here: You must use the Citrix Receiver 13, no option to use Receiver Version 12 here! So it might be that you have to reconfigure your thin clients to work together with your environment and to get Receiver 13 to work.

Please test the new configuration in advance, do not just modify it to see what happens for all your users (otherwise they will hate you). 😉

Cheers

Michael

 

Release: Cloud-Client.info UMS Template Version 1.0.90

Friday, September 5th, 2014

Hello Folks,

a new cloud-client.info UMS Template is available. You can download the new template here: UMS Template Version 1.0.90

Changelog:

1.0.90
——
– Support for IGEL Universal Desktop LX V5 Firmware 5.04.100
– Support for IGEL Universal Desktop W7 Firmware 3.08.100
– Removed old firmwares
– Added Profile for IGEL Linux V5 to configure the Remote Desktop Gateway
– Added Profile for IGEL Linux V5 to configure other User credentials for the Remote Desktop Gateway than the regular user credentials
– Added Profile for IGEL Linux V5 to disable the Firefox Webbrowser splash screen
– Added Profile for IGEL Linux V5 to enable VNC Shadowing secure mode, requires SSL certificate deployed to the client in advance
– Added Profile for IGEL Linux V5 to enable the Toolbar in Microsoft RDS sessions
– Added Profile for IGEL Linux V5 to configure the Webbrowser Media cache memory to 32mb (default 64mb)
– Added Profile for IGEL Windows W7 to configure the general Audio settings
– Added Profile for IGEL Windows W7 to configure the Internet Explorer site security settings
– Modified Default Directory Rules for ARM and LX devices
– Renamed Quest vWorkspace settings to Dell vWorkspace
– Profiles Total 486

Cheers

Michael

 

Feature Highlight: Remote Desktop Gateway support coming with IGEL UD Linux 5.04.100

Thursday, September 4th, 2014

Hello Folks,

together with the Linux Version 5.04.100 IGEL has relased a lot of new features, one highlight here is the support for the Remote Desktop Gateway provided by Microsoft.

The Setup is quite simple and i would like to introduce the main setup steps to you, you can click on the picture to enlarge the view.

Step 1) Enter the public Gateway URL in the RDP Global Tab in the local IGEL Thin Client configuration, if you are using the IGEL Universal Management Suite read the release notes where you can find this setting. Don’t add a https to it, just the plan URL.

rdgwsetup1

 

Step 2) You have to configure the local login window, otherwise it might not work. The configuration is quite simple and can be also found in the RDP Global configuration. Don’t forget to enter the Domain Name here, the picture below shows the working configuration for my test environment at home.

rdgwsetup3

 

Step 3) By default the Remote Desktop Gateway will only work with certificates, i don’t want to deploy these certificate to the client so i disable the option in the RDP Global configuration (marked with red)

rdgwsetup2

 

Step 4) Now it’s time to perform the session configuration, in my scenario i’ve enabled the option to change the server url (fqdn) on demand but you can disable this option. Iam using the option to allow an external access also to my Hyper-V Servers or other Computers running at home (Administrative use of the RD Gateway feature… Marked in red.).

If you only want to allow users to access a regular session enter the DNS Name that points to the loadbalancer in your domain as FQDN. Please note: You have to setup a seperate Host entry in your DNS environment running in the company network to get the Loadbalancer (Remote Desktop Connection Broker, RDCB) to work right, do never never use the “real” RD Loadbalancer Hostname or you will only get a RD connection to the Loadbalancer Desktop. Error No.1 in the most RD environments!

rdgwsetup4

 

 

 

Step 5) Close the IGEL Setup and start the new created RD Session which appears on the IGEL Desktop. The local login window will pop up now. I can change the Server here, this was configured in Step 4 and it’s not required to use it (only my personal setup). Now enter your password and select “OK”.

rdgwsetup5

 

 

Step 6) The new IGEL RD Session start logo pops up.

rdgwsetup6

 

Step 7) Done… Iam now connected to my RD Environment at home (RemoteFX 8). 🙂

rdgwsetup7

 

 

Have fun, it really works very well for me so if you are using a Microsoft RD Environment it’s worth to get a look at the new IGEL solution.

 

Cheers

Michael

 

Release: IGEL Universal Desktop LX/OS 5.04.100

Wednesday, September 3rd, 2014

IGEL Universal Desktop OS 2
===========================
Version 5.04.100
Release date 2014-09-03
Last update of this document 2014-08-26
====================
Versions:
====================
Clients:
– 2X Client 10.1-1263
– Cisco VPN Client 4.8.02.0030-k9
– Citrix Access Gateway Standard Plug-in 4.6.3.0800
– Citrix HDX Realtime Media Engine 1.4.103-956
– Citrix Receiver 12.1.8.250715
– Citrix Receiver 13.0.3.274243
– Client for RedHat Enterprise Virtualization Desktops 3
– Dell vWorkspace Connector for Linux 7.7
– Ericom PowerTerm 9.2.0.6.20091224.1-_rc_-25848
– Ericom Webconnect 5.6.0.4000-rel.20413
– FabulaTech USB for Remote Desktop 5.0.4
– Firefox 17.0.11
– IBM iSeriesAccess 7.1.0-1.0
– IGEL Legacy RDP Client 1.0
– IGEL RDP Client 2.1
– Imprivata OneSign ProveID Embedded
– Leostream Java Connect 2.4.57.0
– NCP Secure Client (Enterprise) 3.25-rev15580-i686
– NX Client 3.5.0-7
– Oracle JRE 1.7.0_65
– Thinlinc Client 3.2.0
– ThinPrint Client 7.0.59
– Totem Media Player 2.30.2
– Virtual Bridges VERDE Client 7.1.1_rel.24005
– VMware Horizon View client 2.3.4-1880356
– Voip Client Ekiga 3.2.7

Dictation:
– Driver for Grundig Business Systems dictation devices
– Driver for Olympus dictation devices
– Legacy Philips Speech Driver 5.0.10
– Philips Speech Driver 12.0.9

Smartcard:
– PKCS#11 Library A.E.T SafeSign 3.0.93
– PKCS#11 Library Athena IDProtect 623.07
– PKCS#11 Library Gemalto IDPrime 1.1.0
– PKCS#11 Library SecMaker NetID 6.1.1.21
– Reader Driver ACS CCID 1.0.5
– Reader Driver HID Global Omnikey CCID 4.0.5.4
– Reader Driver MUSCLE CCID 1.4.13
– Reader Driver Omnikey CCID legacy-3.6.0
– Reader Driver Omnikey RFID legacy-2.7.2
– Reader Driver REINER SCT cyberJack 3.99.5final.SP03
– Reader Driver Safenet / Aladdin eToken 8.1.0-4
– Reader Driver SCM Microsystems CCID 5.0.27
– Resource Manager PC/SC Lite 1.8.9

System Components:
– Graphics Driver ATI 6.14.99_git20111219
– Graphics Driver NVIDIA 304.60
– Graphics Driver INTEL 2.17.0
– Graphics Driver VIA 5.76.52.92-126076
– Kernel 3.2.46 #48.74-udos-r1120
– Xorg X11 Server 1.11.4
– Xorg Xephyr 1.7.6
====================
Information:
====================
IMPORTANT:
This releases integrates two Citrix Receiver versions 12 and 13.
You can only choose to run either of the versions.
The old 12 Citrix Receiver is still available for compatibility reasons and
activated by default. Version 13 of the Citrix Receiver can be activated at
the local setup of the device or through a UMS profile configuration.

IMPORTANT:
Dual monitor configuration for “unsupported hardware” works only if “native
driver support” works properly. It is a prerequisite to assure that the
native driver is really working, as the fallback VESA driver does not provide
any dual monitor configuration. Have a look at Application Launcher’s
“About tab->Hardware-Graphics Chipset”. If VESA is listed there the native
driver does not work and dual monitor configuration is not functional.
====================
Known issues:
====================
[ICA/Citrix Receiver 13 only]
– Currently Kerberos is not supported, so Kerberos passthrough will not work
with ICA sessions and Citrix XenApp/StoreFront.
Workaround: configure “Passthrough authentication”
– Smartcard authentication is supported for ICA sessions created on the IGEL
device (supported with Citrix servers up to version 6.5). Kerberos
passthrough and Citrix XenApp/StoreFront login are not supported.
– Only the “User name and password” StoreFront authentication method is supported.
– During Citrix XenApp/StoreFront logoff the logoff for running desktop sessions
does not work.
– Com-port redirection is not supported.
– Webcam redirection is not supported with H.264 hardware and software encoding,
still legacy theora encoding is supported.
– Persistent cache is not working and therefore completely disabled.

[RDP/IGEL RDP Client 2 only]
– RDP sessions freeze sporadically, if RD Gateway support is enabled.

[RDP/IGEL Legacy RDP Client 1.0 only]
– Fabulatech USB Redirection is not supported with IGEL Legacy RDP Client 1.0.
Please use IGEL RDP Client 2 – RDP legacy mode can be deactivated under
“IGEL Setup->Sessions->RDP->RDP Global->Options”.

[Dell vWorkspace Connector]
– With dual view configuration flash redirected windows can appear on wrong screen.
– Ctrl/Alt/Winkey combinations only work if the session grabs the keyboard by setting
“Override local windowmanager keyboard shortcuts”.
This key is either set globally at “IGEL Setup->Sessions->RDP->RDP Global->Keyboard”
or sessions-wise at “IGEL Setup->Sessions->vWorkspace Client->vWorkspace Client Sessions
->[session name]->Keyboard”.
This issue affects also seamless sessions: e.g. switch to the next window of
the local desktop (with Ctrl+Shift+Tab). When you switch with the mouse from a
seamless app to a local window it is possible that the keyboard focus is not
handed over to the local window again.
– After the start of a seamless session the window is initially maximized before
being resized to the correct size.
– Windows 7/8: The Alt-key must be pressed twice to show shortcut keys as a tool tip
in applications.
– Windows XP sessions might not work properly anymore.
– Only standard 105 keys PC keyboards are supported.
Not supported anymore: Trimodal, Sun Type 6 or IBM 122 keys.
– Mapping of drives to a dedicated drive letter is not possible anymore.
– If Com-port redirection is enabled all linux serial ports (/dev/ttySx) will be mapped.
– If printer mapping is enabled all printers configured in CUPS are mapped.
– For Multimedia Redirection sound redirection with WMV/WMA streams is not working.
– USB Redirection does not work reliable.

[Virtual Bridges VERDE]
– Sessions using NoMachine’s NX protocol are not supported.

[NVIDIA graphics support]
– In dual screen configurations DPMS monitor saving mode creates display content
corruptions on secondary VGA display after resume of the device from suspend.

====================
New features:
====================
[ICA]
– Updated Citrix HDX RealTime Optimization Pack for Lync to version 1.4.103-956.
– Added support to restrict ICA sessions with workarea window mode to a single
monitor at
“IGEL Setup->Sessions->Citrix->ICA Sessions->[session name]->Window->Start Monitor”.
The value “No Configuration” expands the windows over all monitors without
hiding the taskbar.

[ICA/Citrix Receiver 13 only]
– Updated Citrix Receiver to version 13.0.3.274243
– Added support for SHA-2 based certificates.

[RDP/IGEL RDP Client 2 only]
– Added RD Gateway support for RDP sessions and RD Web Access:
configurable at “IGEL Setup->Sessions->RDP->RDP Global->Gateway”,
“IGEL Setup->Sessions->RDP->RDP Sessions->[session name]->Gateway” and
“IGEL Setup->Sessions->RDP->Remote Desktop Web Access->Server location”
registry keys:
– rdp.winconnect.enable-gateway, default: disabled
– rdp.winconnect.other-gateway-credentials, default: disabled;
disabled means: the credentials of the RDP login are also used for the gateway.
The following Gateway Credentials are only effective if
rdp.winconnect.other-gateway-credentials parameter is enabled:
* rdp.winconnect.gateway-user
* rdp.winconnect.gateway-crypt_password
* rdp.winconnect.gateway-domain
– sessions.winconnect<NR>.option.enable-gateway, default: Global setting;
Global setting means, the “RDP Global” configuration is effective.
The following Gateway configuration is only effective, if
sessions.winconnect<NR>.option.enable-gateway is configured to “Session setting”:
* sessions.winconnect<NR>.option.gateway-url
* sessions.winconnect<NR>.option.other-gateway-credentials, default: off
The following Gateway Credentials are only effective, if
sessions.winconnect<NR>.option.other-gateway-credentials is “on”:
* sessions.winconnect<NR>.option.gateway-user
* sessions.winconnect<NR>.option.gateway-crypt_password
* sessions.winconnect<NR>.option.gateway-domain
– rdp.rd_web_access.browseraddress<NR>.enable-gateway, default: Global setting;
the following Gateway address configuration is only effective,
if rdp.rd_web_access.browseraddress<NR>.enable-gateway
is configured to “Session setting”:
* rdp.rd_web_access.browseraddress<NR>.gateway-url
– Improved RDP Remote Apps: Tray icons and tooltips can be used.
– Added workarea mode support at “IGEL Setup->Sessions->
RDP->RDP Global->Window->Window Size” as a global setting.
You can also configure workarea mode session-specific at “IGEL Setup->Sessions->
RDP->RDP Sessions->[session name]->Window->Window Size”.
Please note that either workarea mode or the toolbar can be used.
Workarea mode superseeds toolbar configuration.
– Added a startup splash screen that is shown while connecting to a RDP server.

[ICA/RDP]
– Updated Grundig dictation driver with a better stability of the audio channel.
The following devices are not supported anymore:
– Grundig SoundBox 820
– DigtaSonic Mic I
– ProMic 840

[FabulaTech]
– Updated FabulaTech USB for Remote Desktop to version 5.0.4

[Browser]
– Added parameter to disable the firefox splash screen at
“IGEL Setup->Sessions->Browser->Browser Global->Show browser splash screen”
(registry key: browserglobal.app.showsplash, default: on).
– Updated flash player download URL to version 11.2.202.400.

[VMware Horizon View]
– Updated Horizon View Client to version 2.3.4.

[Appliance Mode]
– Added device reboot capability with a hotkey in XenDesktop,
VMware Horizon View, Spice and Imprivata Appliance mode.
The reboot hotkey is configured at
“IGEL Setup->Accessories->Commands->Reboot Terminal”

[UMS]
– Added information about network speed and duplex mode of Thin Client in the
system information pane along with other Thin Client specific properties.

[Shadowing/VNC]
– Updated VNC Server to version 0.9.13
– Added VNC secure mode, based on a SSL-encrypted VNC connection. The SSL
connection uses a special certificate located in the directory /wfs/ca-certs.
This feature requires the Universal Management Suite (UMS) to be involved,
to handle the shadowing permissions and double check whether the connection
is allowed or not. In addition the UMS is used to assure a secure credential
exchange between the TC and the UMS console.
IMPORTANT: The UMS must have the version 4.07.100 or higher!
The feature can be enabled at “IGEL Setup->System->Shadow->Secure Mode”
(registry key: network.vncserver.secure_mode, default: disabled)

[RedHat Enterprise Virtualization client]
– Updated spice/virt-viewer client to version 0.5.6.

[Virtual Bridges VERDE]
– Updated Virtual Bridges VERDE client to version 7.1.1 rel.24005.
The client supports RDP (IMPORTANT: IGEL Legacy RDP Client 1.0 is used)
and Spice client sessions.
VERDE Client sessions can be configured at
“IGEL Setup->Sessions->VERDE Sessions”
(registry keys: sessions.vbclient%)
The browser plugin is working without additional configuration.

[Dell vWorkspace Connector]
– Updated Dell vWorkspace Connector for Linux to version 7.7
– Added switch to enable bidirectional audio at “IGEL Setup->Sessions->
RDP->RDP Global->Sound->Audio capture” for global configuration or
or session-specific at “IGEL Setup->Sessions->
vWorkspace Client Sessions->[session name]->Mapping->Enable Microphone mapping”
(registry keys:
– rdp.winconnect.rdpeai.enable, default: disabled
– sessions.qrdesktop<NR>.option.enable-microphone, default: disabled)
– Added switch for font-smoothing at “IGEL Setup->Sessions->
RDP->RDP Global->Performance->Enable Font smoothing” for global configuration
or session-specific at “IGEL Setup->Sessions->
vWorkspace Client Sessions->[session name]->Performance->Enable font smoothing”.
(registry keys:
– rdp.winconnect.enable-font-smoothing, default: disabled
– sessions.qrdesktop<NR>.option.enable-font-smoothing, default: disabled)
– Added switch for vWorkspace connection bar at “IGEL Setup->Sessions
->RDP->RDP Global->Enable Toolbar” for global configuration
or session-specific at “IGEL Setup->Sessions->vWorkspace Client Sessions->
[session name]->Window->Display the connection bar when in full screen mode”.
(registry keys:
– rdp.winconnect.enable-toolbar, default: disabled
– sessions.qrdesktop<NR>.option.conbar_fullscreen, default: enabled)

[Smartcard]
– Updated SafeSign smart card PKCS#11 library to version 3.0.93.

[Network]
– Added parameter for DHCP user class option (see RFC 3004) at
“IGEL Setup->Network->DHCP Client->Standard Options->User Class”.
(registry key: network.dhcp.user_class, default: empty, which disables the option)
Non-printable bytes can be specified as \ooo, where each o is an octal digit,
or \xhh, where each h is a hexadecimal digit. ‘\’ and ‘”‘ must be escaped by prepending ‘\’.
– Added parameters for DHCP client identifier options (see RFC 2132):
(registry keys:
– network.interfaces.ethernet.device0.dhcp_client_id, default: empty, which disables the option
– network.interfaces.ethernet.device1.dhcp_client_id, default: empty, which disables the option
– network.interfaces.wirelesslan.device0.dhcp_client_id, default: empty, which disables the option)
Non-printable bytes can be specified as \ooo, where each o is an octal digit,
or \xhh, where each h is a hexadecimal digit. ‘\’ and ‘”‘ must be escaped by prepending ‘\’.
Example values:
– \x00host.example.org (a FQDN with type byte 0 prepended),
– \x01\x00\x11\x22\x33\x44\x55 (the MAC address 00:11:22:33:44:55 with type byte 1 prepended)

[base system]
– Added custom timezone support. Custom timezone files must be located at /wfs/zoneinfo/ directory
to be considered.
– Updated common CA certificates to ubuntu version ca-certificates_20140325.
The list of integrated certificates is available at:
http://myigel.biz/index.php?dir=IGEL_UNIVERSAL_DESKTOP_CONVERTER/updates/UDC2_V5/
– Updated timezone data to version 2014e-0ubuntu0.12.04.
– Updated Gstreamer plugins:
– Fluendo MPEG demuxer to version 0.10.81
– Fluendo MP3 decoder to version 0.10.29.
– Updated TC Setup to version 4.8.3
– Added webcam test application configuration at
“IGEL Setup->Accessories->Webcam Information”

[Java]
– Updated Java Runtime Environment to version 1.7.0 U65.

[PowerTerm]
– Added registry key “powerterm.autosavekeymapscript” default: enabled, to control
automatic saving of keyboard mapping changes and scripts within PowerTerm sessions.
Disabling this parameter avoids data transfer to UMS, however changes of keyboard mapping
and scripts within PowerTerm sessions are not reboot- or reconfiguration-safe.

====================
Resolved issues:
====================
[ICA]
– Fixed Citrix XenApp/StoreFront with multi monitor configuration for window
placement if “Sessions->Citrix->ICA Global->Window->Multi Monitor Fullscreen Mode”
is set to “Restrict fullscreen session onto one monitor”.
For this setup configure “IGEL Setup->Sessions->
Citrix->ICA Global->Citrix XenApp/StoreFront Start Monitor”
(registry: “ica.pnlogin.xineramamonitor”, default: 1st monitor).
– Fixed matching of application names in Citrix XenApp/StoreFront autostart list
at “IGEL Setup->Sessions->Citrix->Citrix XenApp/StoreFront->Logon->
Start following applications automatically…”.
– Fixed closing ICA sessions, if a USB headset is plugged in or out.
– Fixed HDX Flash Redirection to work with enabled server-side content
fetching (SSCF)

[ICA/Citrix Receiver 13 only]
– Fixed Copy/Paste and focus issue with new Citrix Receiver version 13.0.3.

[ICA/Citrix Receiver 12 only]
– Fixed persistant cache

[RDP]
– Fixed local logon window to customize the Server-URL within the logon window (changeable Server-URL).

[RDP/IGEL RDP Client 2 only]
– Fixed Remote Desktop Web Access login mechanism:
– IGEL Setup is not blocked, while the Remote Desktop Web Access
login is running.
– Handle more than one server in a correct way.
– Fixed English(International) keyboard layout.
– Fixed access of files via drive mapping: search for existing files in a case
insensitive way.
– Improved Windows Server 2003 handling with a color depth of 16 bpp.
– Fixed crash if connecting to a Windows Server 2003 with activated NLB
(Network Load Balancing).
– Fixed double mapped drives and printers.
– Fixed DNS Round Robin loadbalancing feature.
– Fixed termination of RDP sessions if IGEL Smartcard is removed.
– Fixed audio redirection for Remote Apps started by Remote Desktop Web Access.
– Fixed drive mapping in RDP sessions not to lock CDROM drives permanently.
CDs can be ejected at any time.
– Fixed playback of compressed audio frames used in Windows 2012 Server sessions.
– Fixed program crash on hardware without SSE4.1 instruction set,
if RemoteFX is enabled.
– Fixed window position on unsupported UDC hardware,
if VESA fallback graphics mode is active.

[Browser]
– Firefox crashed the system while playing videos due to vast memory consumption.
Memory usage can be limited with registry keys:
– browserglobal.app.media_cache_size, default: 64000 (=64MB)
– browserglobal.app.browser_cache_offline_capacity, default: 64000 (=64MB)

[Network/WiFi]
– Fixed not working registry keys:
– network.interfaces.ethernet.device0.hide_progress,
– network.interfaces.ethernet.device1.hide_progress and
– network.interfaces.wirelesslan.device0.hide_progress are no longer ignored.
Setting the values to “always” or in case of WiFi to “reconnect” results in fewer
notification messages on desktop.
– Fixed handling of PKCS#12 (PFX) files for 802.1X authentication.
– Fixed Broadcom 44xx/47xx (b44) ethernet driver.
– Fixed broken WiFi roaming between multiple SSIDs.
– Improved NetworkManager: Connection data is not stored in
/etc/NetworkManager/system-connections/ anymore.
– Fixed network notification window to disappear after boot process.
– Improved dynamic DNS registration with method DNS.
– Fixed 802.1X authentication together with SCEP certificate management.
– Fixed logon method (e.g. Kerberos logon) after resuming the device from suspend.
After the resume the device asks again for the login credentials (i.e.
for WPA Personal or 802.1X authentication) to ensure the login policy is enforced.

[Dell vWorkspace Connector]
– Fixed vWorkspace sessions with preconfigured credentials to not show the local login
window again during session start.

[FabulaTech]
– Fixed redirection of mass storage devices.
– Fixed Fabultech USB redirection to be available with IGEL IZ-HDX devices.

[Smartcard]
– Improved driver for HID Global Omnikey smart card reader OMNIKEY CardMan (076B:3022) 3021
by new driver version 4.0.5.4.
– Fixed reading of DATEV smart cards with Omnikey smart card readers.
The setting of registry key scard.pcscd.omnikey_mhzrequired is effective again.

[Desktop]
– Fixed Ctrl+Alt+Up/Down window focus cycling shortcut to work as expected.
– Fixed hotkeys for switching additional keyboard layouts.
– Fixed localisation of system programs that were started from start menu or desktop.
– Fixed keyboard focus of 802.1X authentication dialog:
When a logon screen (e.g. for Kerberos logon) and the network authentication dialog
were displayed at the same time the last one did not get the keyboard focus.
– Enabled LVDS output on radeon graphics chipsets by default, when a laptop
with battery is detected.
The registry key x.drivers.ati.ignore_lvds_output is ignored in that case.
This fixes black screens on laptops with ATI/Radeon graphics chipsets.
– Fixed a crash in radeon graphics driver, when LVDS output is ignored
with registry key x.drivers.ati.ignore_lvds_output and LVDS output is present.

[base system]
– Fixed chinese input method in GTK2 programs.
– Restricted RPC access: RPC informations are only reported to localhost now.
– Fixed OpenSSL 1.0.1 security issues: CVE-2014-0224, CVE-2014-0195, CVE-2014-0221,
CVE-2014-3470, CVE-2010-5298, CVE-2014-0198
– Fixed OpenSSL 0.9.8 security issues: CVE-2014-0224, CVE-2014-0221, CVE-2014-0195,
CVE-2013-0169, CVE-2013-0166, CVE-2012-2333, CVE-2012-0884.
– Added security patch to fix CVE-2014-0196.
– Added missing parameter at “IGEL Setup->Sessions->Citrix->ICA Global->Mapping->
Device Support->Grundig MMC Channel for Dictation with Grundig Devices”.
– Fixed changing passwords when logging on with Active Directory/Kerberos
and specifying Domain Controller manually at
“IGEL Setup->Security->Active Directory/Kerberos->Domain X”.
– Fixed reboot on Dell OptiPlex 760 and 755 UDC hardware.
– Added support for Realtek SD Card Reader in Acer Veriton 260G UDC hardware.

[UMS]
– Fixed UMS configuration if the connection is established via Cisco VPN client.

[Imprivata]
– Fixed Login dialog in multi monitor environments.
– Fixed issue with Imprivata partition.

Whitepaper: How to use the IGEL Linux together with the Microsoft Remote Desktop Connection Broker

Friday, August 29th, 2014

Hi Folks,

very often i’ve been asked how to setup the RDP Client coming with the IGEL Linux to use the Microsoft Remote Desktop Connection Broker in the right way.

So here is a new Whitepaper how to setup this step by step, the Whitepaper is based on a Windows Server 2012 R2 environement and the current IGEL Linux Firmware 5.03.190.

The download is available here: Download

Cheers

Michael

Info: Holiday end and back in business

Wednesday, August 27th, 2014

Hello Folks,

not much updates here during the last weeks, reason is quite simple: I was in vacation and got a lot of work on my table after i was back in the office. 🙂

Since the upcoming firmware releases from IGEL a new category will be added. In the category “New feature highlight” i will introduce you new “cool” features coming with the latest firmware or other important changes coming with a release.

Stay tuned

Michael

Release: cloud-client.info UMS Appliance for Microsoft Hyper-V and Oracle Virtual Box 2.8

Friday, July 25th, 2014

Hello Folks,

a new Version of the cloud-cient.info UMS Appliance for Microsoft Hyper-V and Oracle Virtual Box is available for download, Version 2.8 can be downloaded here for free: Download

cloud-client.info UMS Appliance 2.7

 

2.8

– Updated Ubuntu Subsystem
– Updated IGEL Universal Management Suite to 4.07.110

 

Cheers

Michael

Info: UMS Live is updated to Version 4.07.110

Thursday, July 24th, 2014

Hello Folks,

i just updated the UMS Live Server to 4.07.110 (our public UMS Demonstration platform).

UMS4 LIVE

UMS4 LIVE

 

Connection:
Start the UMS Console and use the following connection settings:

Universal Management Suite Server: ums.cloud-client.info
Port: 443
User Name: ums
Password: live

Required UMS console: IGEL Universal Suite 4.07.110
Access to the UMS internal Webserver on Port 9080 is blocked, Firmware Updates are not possible from this server!

Cheers

Michael

Release: IGEL Universal Management Suite 4.07.110

Wednesday, July 23rd, 2014

=====================
IGEL Universal Management Suite
=====================
Version 4.07.110
Release date: 11.07.2014
=====================
Notes:
=====================

If the windows installer does not start on Windows Server 2003 hosts,
contace IGEL support to get an UNSIGNED setup executable. This will solve
the issue.

The stand alone VNCViewer application has been removed in version 4.05.220.
Use UMS Console with appropriate user permissions to replace it.

The linux installer is tested with
– Ubuntu 12.04 (32bit)
– RedHat Enterprise Linux 6 (32bit)

For further compatibility information check the Universal Management Suite
Data Sheet at www.igel.com.
*****************************************************************************
UMS 4.07.110 (stable build based on version 4.07.100)
*****************************************************************************
=====================
Fixed bugs
=====================
– Fixed problem creating thin client directories (occurs in combination with
default directory rules only)
– Fixed firmware update assignment issue: assignments did not take effect
if they were assigned to thin client subdirectories
– Fixed file assignment issue: assignments did not take effect
if they were assigned to thin client subdirectories
– Fixed profile assignment issue: assigned object list showed all profiles,
even if there were only some assigned;
NOTE: this was an UI issue only, it did NOT affect the thin client settings
– Fixed null pointer exception if a firmware update is deleted
– Fixed firmware update deployment issue: firmware update registration
(from zip file) fails if UMS console runs on a windows system and the
UMS server runs on linux

Firmware release: IGEL Universal Desktop W7(+) 3.08.100

Wednesday, July 23rd, 2014

IGEL Universal Desktop W7
=========================
Version 3.08.100
14. July 2014
Supported devices:
UD3-W7, UD5-W7, UD9-W7, UD9-W7 Touch, UD10-W7, UD10-W7 Touch
UD3-730 W7, UD3-740 W7, UD5-730 W7, UD5-740 W7, UD9-730 W7, UD9-731 W7
=====================
Notes:
=====================

=====================
Drivers:
=====================
– Realtek RTL8169 Version: 7.43.321.2011
– VIA HD Audio VT1708B: 6.0.01.8700
– Prolific PL-2303 USBtoSerial: 2.0.2.8
– FTDI UsbToSerial: 2.02.04
– OmniKey Cardman 3×21: 1.2.15.0
– Intel HD Graphics: 9.17.10.2875
– Intel PCI Communication Controller: 8.0.0.1262
– Realtek 8168: 7.61.612.2012
– Intel AHCI : 11.2.0.1006
– Gemalto Minidriver for .NET Smart Card: (WES7: 8.3.1.3)
– VIA WLAN VT6656: 1.1.0.2
– Intel Centrino WLAN N-1000: 15.1.0.18
– VIA Chrome 9 VX855: 8.14.14.0141
– D-LINK DWA-131 Nano: 1085.7.0815.2009
– D-LINK DWA-131 REVB Nano: 1015.6.0210.2012
– VIA Chrome9 VX900: 8.14.14.0181
– VIA Chrome9 VX900 for TC236: 8.14.14.0231
– Ralink RT309x/2860: 3.02.01.0
– Ralink WLAN RT357x: 5.1.7.0
– Intel 945 Express: 8.15.10.1930
– eGalax xTouch: 5.11.0.9020
– RTL8168C: 7.018.0322.2010
– Realtek HD Audio: 2.63
=====================
Applications:
=====================
– .NET: 3.5 Sp1
– Microsoft RDP Client : 8
– Internet Explorer: 8
– Windows Media Player: 12
– Sun JAVA RE: 1.7 Update 17
– Ericom WebConnect: 5.6.1.1000
– Ericom PowerTerm: 9.2.0.0
– NXClient: 3.4.0.7
– Quest vWorkspace Client: 7.6
– Ekiga VOIP Client: 3.2.6
– SAP GUI JAVA for Windows: 7.10 R 7
– Tight VNC Server: 2.0.2
– Citrix Receiver: 3.4
– Thin Print: 8.6
– VMware Horizon View Client Version: 5.4.0 build-1219906
– Fabulatech USB for Remote Desktop: 3.1.3
– NCP Enterprise Client: 9.30
– Leostream Connect Client: 2.7.129.0
– Client for RedHat RHEV-D: 3.0-26
– USB Redirection for RedHat RHEV-D: 3.0-26
– Sumatra PDF Reader: 2.1.1
=====================
New features:
=====================
-[System]:
– Added configuration of system audio master volume
On IGEL setup page “Accessories->Sound Mixer->Sound Mixer Configuration”
(registry key: userinterface.sound.mute, default: false)
(registry key: userinterface.sound.use_igel_setup, default: false)
(registry key: userinterface.sound.volume, default: 50)
– Added Icelandic keyboard support
– Added support for D-LINK DWA-131 REVB Nano
– Updated system OpenSSL library to version 1.0.1g
– Added IGEL desktop backgrounds for 16:10 displays
– Added Internet Explorer security sites configuration.
Possibility of adding website url’s to Internet Explorer Security Zones
On IGEL setup page: “Sessions->Browser Sessions>Security->Sites”
(registry key: sessions->web->websettings->internetzone->enableprotectedmode, default: true)
(registry key: sessions->web->websettings->localintranetzone->enableprotectedmode, default: false)
(registry key: sessions->web->websettings->localintranetzone->localintranetsites% )
(registry key: sessions->web->websettings->trustedzone->enableprotectedmode, default: false)
(registry key: sessions->web->websettings->trustedzone->trustedsites% )
(registry key: sessions->web->websettings->restrictedzone->enableprotectedmode, default: true)
(registry key: sessions->web->websettings->restrictedzone->restrictedsites% )

=====================
Bug fixes:
=====================
-[System]:
– Fixed bug in IGEL firewall configuration “Do not allow Exceptions”
– Fixed some bugs and tooltips in IGEL setup

=====================
Known Issues:
=====================
-[System]:
– Xen Desktop Appliance Mode is not working.
-[FABULATECH]:
– Fabulatech USB for Remote Desktop is currently
not working with Citrix XenDesktop.
-[VMware]:
– USB Redirection: Devices connected to a USB 3.0 Port will not be redirected.
– USB redirection is currently not working if Quest vWorkspace USB
redirection service is enabled.

IGEL offers W7+ devices

Wednesday, July 23rd, 2014

Hello Folks,

IGEL brings up a a new  device/firmware type called Universal Desktop W7+, the Universal Desktop W7+ is similar to the regular W7 but it comes with an 8GB SSD and not like the regular W7 devices with a 4GB SSD.

Main benefit for the W7+ is the fact that you have much more space available to install applications or drivers to the device, for example to install the Lync 2013 VDI Plug-In from Microsoft.

Import: If you are running a mixed environment (W7 and W7+) you have to handle two seperate firmware’s. The Images are not compatible.

W7+ is available for the current UD3, UD5, UD9 and UD10.

Cheers

Michael

Tip: How to solve scrolling issues with XenDesktop 7.x and the Linux Citrix Receiver 13

Wednesday, July 9th, 2014

Hello Folks,

if you got in issue with scrolling in web sites that contain a lot of pictures like Google Pictures than you should try the setting to enable the registry key to enable the h264 deep level compression (System->Registry->ica.wfclient.h264enabled).

Plesase note: You must use Receiver 13 and this settings is currently not available for ARM based Client like the IZ1 or UD2 Multimedia.

Cheers

Michael

Info: Smartphones in Company environments (or Administrators can’t read).

Monday, July 7th, 2014

Hi Folks,

bring your own device (BYOD) is always a big thing for company’s but very often there is a big question: How can users access there device to sync pictures/contacts and other or to perform a firmware update in a company environment. Very often i got question like “How can i access my xxx phone in a VDI session” or “How can i access pictures..” and so on.

Of course you can install drivers and use USB redirection but depending on the network it will work more or less stable and is mostly not really user frindly. The most vendors also do not really take care about this question.. Why?

Now we come to the paperworks.. Do you know that VDI/Terminal Server use/access is forbidden and a license fault for a couple of vendors?

Let’s check it out, Scenario we have a couple of Apple devices and want to use them or make them available for the Users in a VDI / Company environment. Sounds simple right.. But what are we required to do? We need do deploy the Software/Drivers to the End User Device (Desktop PC/Thin Client) and/or to the Virtual Desktops (incl. Terminal Servers). Now check out the Apple License Agreement for IOS 7 and also ITunes.

From IOS7 License Agreement:

“…and you may not distribute or make the iOS Software available over a network where it could be used by multiple devices at the same time”

From ITunes License Agreement:

“You may not make the Apple Software available over a network where it could be used by multiple computers at the same time.”

What do it mean? Quite simple: Software deployment = Forbidden, Use on Terminal Server = Forbidden, Use on VDI = Forbidden

For Windows Phone 8.1 Microsoft denies the use of the Software for “commercial Software Hosting services” without any deeper explanation. For Android devices it depends on the vendor, but mostly here you will find similar parts in the EULA.

This is also one reason why we have discontinued the work on our integration packs for IOS/Android.

So how can you exchange files? Quite simple: Use cloud services like OneDrive, GoogleDrive or similar. Using a Smart Phone as “USB Memory” is mostly obsolete today and there are a bunch of cloud services available to perform the job.

So from my point of view in “company” or “commercial” environments mostly all smart phone vendors only allow the use thru cloud based services incl. Exchange based EMail and that’s it. If you have an other view please share it… 😉

Cheers

Michael

Release: IGEL Linux SoC for IZ1 and UD2 Multimedia Version 1.08.100

Friday, July 4th, 2014

IGEL Linux SoC
==============
Version 1.08.100
Jul 01 2014
Supported devices: IZ1-RFX, IZ1-HDX, UD2-LX MultiMedia
Versions
========
– Citrix Receiver 12.5.1.234536
– Citrix Receiver 13.0.3.274243
– IGEL Legacy RDP Client 1.0
– IGEL RDP Client 2.1
– VMware View client 2.0.0-1049726
– Leostream Java Connect 2.4.57.0
– Firefox 20.0
– Xorg X11 Server 1.10.4
– Xorg Xephyr 1.10.4
– PC/SC Lite 1.8.9
– MUSCLE CCID Driver 1.4.13
– REINER SCT cyberJack Driver 3.99.5final.SP03
– ACS CCID Driver 1.0.5
– Imprivata OneSign ProveID Embedded
================
Information:
================
IMPORTANT: If you install this firmware you cannot downgrade to versions
earlier than 1.07.100.

IMPORTANT: This releases integrates two Citrix Receiver versions 12 and 13.
You can only choose to run either of the versions.
The old 12 Citrix Receiver is still available for compatibility reasons and
activated by default. Version 13 of the Citrix Receiver can be activated at
the local setup of the device or through a UMS profile configuration.
Please check in this readme which restrictions apply and how to switch the
versions.
================
Known issues:
================
[ICA/Citrix Receiver 12 and 13]
– Currently Kerberos is not supported, so Kerberos passthrough will not work
with ICA sessions and Citrix XenApp/StoreFront.
Workaround: configure “Passthrough authentication”

[ICA/Citrix Receiver 13]
– Smartcard authentication is supported for ICA sessions created on the IGEL
device (supported with Citrix servers up to version 6.5). Kerberos
passthrough and Citrix XenApp/StoreFront login are not supported.
– Only the “User name and password” StoreFront authentication method is supported.
– During Citrix XenApp/StoreFront logoff the logoff for running desktop sessions
does not work.
– Com-port redirection is not supported.
– Webcam redirection is not supported with H.264 hardware and software encoding,
still legacy theora encoding is supported.

================
New features:
================
[ICA/Citrix Receiver 13]
– Added Citrix Receiver 13.0.3.274243
– Added support for StoreFront
– Added support for SHA-2 certificates

Hints (It is IMPORTANT to read this, if you plan to use Citrix Receiver 13
instead of 12 and/or want to connect to a Citrix server version 7.x):
– This firmware contains two Citrix Receivers, but only one of them can be
active at a time. Default is Citrix Receiver 12. The version can be
switched by the new parameter “Use Citrix Receiver version 13” in the
IGEL setup at “Sessions->Citrix->Citrix Receiver Selection” (registry:
ica.useversion13). For Citrix Receiver 13 configuration setting the new
parameter “Citrix server version” is mandatory (see below).
– The new parameter “Citrix server version” on IGEL setup page
“Sessions->Citrix->Citrix XenApp/StoreFront->Server” (registry key:
ica.pnlogin.serverversion) defines the capabilities of the Receiver
accroding to the used Citrix server versions (default is “XenApp 6.x or
older”):
IMPORTANT FOR SERVER URL CONFIGURATION in the IGEL registry (With local
IGEL Setup or UMS 4.07.100 the server url is automatically stored at the
correct keys, if you use the provided setup page at
“Sessions->Citrix->Citrix XenApp/StoreFront->Server”):
Depending on the Citrix server version you have configured, different
sets of server url configurations apply:
* XenApp/XenDesktop 7.x Store:
For access to a Citrix Storefront:
registry keys ica.pnlogin.browseraddress_store<NR>.*
(optional: ica.pnlogin.browseraddress_store<NR>.farm)
* XenApp/XenDesktop 7.x Legacy Mode
For access to the legacy mode of a Citrix Storefront:
registry keys ica.pnlogin.browseraddress_store_legacy<NR>.*
(optional: ica.pnlogin.browseraddress_store_legacy<NR>.farm)
* XenApp 6.x or older:
For access to a XenApp Server:
registry keys ica.pnlogin.browseraddress<NR>.*
(optional: ica.pnlogin.browseraddress<NR>.farm)

– For Citrix StoreFront access with Citrix Receiver 13 only https web interfaces
are supported. If the SSL certificate of your Citrix server is not signed
by a trusted certificate authority (like Verigsign, Thawte etc.), you have to
install the root certificate of your own certificate authority on each Thin
Client.
Please use http://edocs.igel.com/index.htm#10200413.htm to access the document
on how to install SSL certificate.
– With Citrix Receiver 13 it is not possible to connect to a Citrix server
with other methods than the web interface (this affects the parameter
“Use Citrix XenApp Services Site” registry key: ica.pnlogin.useserversettings).
Due to that it is not possible to select another password change method than
“Citrix XenApp Services Site”.
– ICA sessions created on the IGEL device only work with Citrix XenApp servers up
to version 6.5.
– The parameter “Deferred update mode” has no effect anymore.
– The window options on IGEL setup page
“Sessions->Citrix->Citrix XenApp/StoreFront->Options” are not supported anymore.

Hints for the configuration on server side (for Citrix servers version 7.x):
– After installation and basic configuration of Machine Catalogs and Delivery
Groups, you end up with a store that uses http only. But the Citrix Receiver
13 for Linux supports stores with https only (the Windows version of Citrix
Receiver has this limitation, too; but it is possible to change some
registry keys on the client side to enable http support; unfortunately
this is not possible with the Linux version of Citrix Receiver).
– To switch the store to https, change the base URL on page “Server Group”
in the Citrix StoreFront Management Console.
– Then adjust the “Transport Type” in the “Manage Delivery Controllers”
dialog of the “Store” page in Citrix StoreFront Management Console.
– Then add a https binding for the website in the IIS Management Console
(you have to choose an SSL certificate in the corresponding dialog).
– Password change is disabled by default on a Citrix server 7.x. To enable it,
open the Citrix StoreFront Management Console and go to page
“Authentication”. Click on the authentication method “User name and
password” and then on “Manage Password Options” on the right pane.
– The error messages of Citrix servers 7.x and Citrix Receiver 13 are terribly
misleading. When you are using Citrix servers 7.x and you experience
problems with the connection itself or login, please double check
that everything is ok on the server side. It is a good thing to check the
overview page for a target machine in Citrix Studio. To get there, choose
“View Machines” in the context menu of a Delivery Group.
Then check for each machine:
– that the “Registration State” of the machine is “Registered”
– that the “Maintenance Mode” of the machine is “Off”
– that the “Power State” of the machine is “On”
– that you are using the correct user if there is a user
mentioned in the column “User”.
Also, if something does not work (although it really should), try to reboot
the Citrix server. In our tests this helped sometimes when we experienced
strange problems.

– With Citrix Receiver 13 the following codec parameters are available:
JPEG codec registry keys:
* ica.wfclient.directdecode
* ica.wfclient.batchdecode (enabled by default)

The H264 deep compression codec is not available in this release.

Detailed description of the parameters is available at:
http://support.citrix.com/proddocs/topic/receiver-linux-13-0/receiver-linux-13-0.html

[ICA/Citrix Receiver 12]
– Updated Citrix Receiver to version 12.5.1.234536

[ICA]
– For ICA sessions with workarea window mode: In multi monitor setups
the workarea window can be restricted to a single monitor now.
Configure “Start Monitor” at setup page:
“Sessions->Citrix->ICA Sessions->session name->Window”.
If the “Start Monitor” is configured to “No Configuration”, the session window
is expanded over all monitors without covering the taskbar.
– Improved Citrix XenApp/StoreFront session configuration
– Added new filter for desktop placement of Citrix XenApp applications
at Setup page “Sessions->Citrix->Citrix XenApp/StoreFront->Appearance”.
– Improved “Overwrite local Start Menu and desktop setting with server
setting” by separting parameter for start menu and desktop.
– Added autostart of sessions. The list of autostarted applications can be
defined at: “Sessions->Citrix->Citrix XenApp/StoreFront->Logon”.
Hint:
The autostart mechanism does not care about automatically reconnected
applications. To avoid this, the number of allowed running sessions
can be limited at server side.
– Added additional settings for protocol encryption
– At registry key “ica.module.encryption” you can disable encryption for
all ICA sessions
– At setup page “Sessions->Citrix->ICA Sessions->session name->Options” set
“Encryption Level” to “None” to disable encryption for individual ICA sessions.
(registry key: session.ica<NR>.appsrv.encryptionlevelsession)

[RDP]
– Updated to IGEL RDP Client 2.1 based on FreeRDP Client 1.1:
– Added support for RDP 8 based RemoteFX Adaptive Graphics virtual channel:
– Calista Codec (RemoteFX7)
– Progressive Codec
– Clear Codec
– Planar Codec
– Added H264 Video optimized remoting virtual channel
– Added support for audio recording capability
– Improved RemoteApp support
– Added support for Remote Desktop Web Access accessible at setup page
“Sessions->RDP->Remote Desktop Web Access”
– For compatibility reasons it is still possible to enable IGEL Legacy RDP
Client 1.0 at setup page “Sessions->RDP->RDP Global->Options->RDP legacy mode”.
IMPORTANT: The following features are not available:
– RDP 8 based RemoteFX support
– Remote Desktop Web Access
– Changed default authentication mode to support NLA authentication aside local logon
for automatic access to Windows Server 2008, 2008 R2, 2012 and 2012 R2.
You can disable local logon and network authentication at IGEL setup page
“Sessions->RDP->RDP Global->Local Logon”
(registry: rdp.login.use_rdplogin and rdp.login.enable-network-authentication)
– The RDP session window resolution can now be configured with custom resolutions at
IGEL setup page “Sessions->RDP->RDP Sessions->session name->Window”
(registry key: sessions.winconnect<NR>.option.resolution)
– Added a “RDP connection bar” in a fullscreen RDP session, to minimize and quit the session.
The feature can be enabled at IGEL setup page “Sessions->RDP->RDP Global->Window->Enable toolbar”
(registry key: rdp.winconnect.enable-toolbar)

[Imprivata]
– Updated bootstrap loader to version 1.0.230504

[VNC]
– Added VNC secure mode, based on a SSL-encrypted VNC connection. The SSL
connection uses a special certificate located in the directory /wfs/ca-certs.
This feature requires the Universal Management Suite (UMS) to be involved,
to handle the shadowing permissions and double check whether the connection
is allowed or not. In addition the UMS is used to assure a secure credential
exchange between the TC and the UMS console.
IMPORTANT: The UMS must have the version 4.07.100 or higher!
The feature can be enabled in IGEL setup at “System->Shadow->Secure Mode”
(registry key: network.vncserver.secure_mode, default: off)
– Added hide disconnect button configuration in the Remote Shadowing Indicator at setup page
“System->Shadow->Allow User to disconnect Remote Shadowing”
(registry key: “network.vncserver.showdisconnectbtn”, default: on).

[UMS]
– Added information about network speed and duplex mode of Thin Client in the
system information pane along with other Thin Client specific properties.

[Network]
– Added support for 802.1X MD5 authentication
– Added parameter for DHCP user class option (see RFC 3004):
Setup page Network -> DHCP Client -> Standard Options -> “User Class”
Registry key: network.dhcp.user_class
The default value is empty and means that the option is not used.
Non-printable bytes can be specified as \ooo, where each o is an octal digit,
or \xhh, where each h is a hexadecimal digit.
‘\’ and ‘”‘ must be escaped by prepending ‘\’.
– Added parameters for DHCP client identifier options (see RFC 2132):
Registry keys:
* network.interfaces.ethernet.device0.dhcp_client_id
* network.interfaces.ethernet.device1.dhcp_client_id
* network.interfaces.wirelesslan.device0.dhcp_client_id
The default value is empty and means that the option is not used.
Non-printable bytes can be specified as \ooo, where each o is an octal digit,
or \xhh, where each h is a hexadecimal digit.
‘\’ and ‘”‘ must be escaped by prepending ‘\’. Example values:
\x00host.example.org (a FQDN with type byte 0 prepended),
\x01\x00\x11\x22\x33\x44\x55 (the MAC address 00:11:22:33:44:55 with type byte 1 prepended)

[base system]
– Updated Chinese, Dutch, French and German userinterface translations.
– Added an webcam test application. The application can be started from
“Application Launcher->System tab->Webcam Information”.
For scripting access use the command “webcam-info”:
* option “-l”:
retrieve a list containing all possible frame resolutions and frame rates.
– Added bulgarian keyboard layout support
– Added a new user setup session. Configurable at IGEL setup page
“Accessories->Setup Session”
– Improved Application Launcher: applications are sorted by name.
– Updated TC Setup to version 4.7.4
– Updated PC/SC Lite to version 1.8.9
– Updated open source ccid driver to version 1.4.13
– Updated timezone informations to ubuntu version tzdata_2014a-0ubuntu0.12.04
– Updated common CA certificates to ubuntu version ca-certificates_20140325:
The list of integrated certificates is available at:
http://myigel.biz/index.php?dir=IGEL_UNIVERSAL_DESKTOP_FIRMWARE/LX_SoC/

================
Fixed bugs:
================
[ICA/Citrix Receiver 13]
– Fixed LED indicator for (Caps Lock, Num Lock or Scroll Lock) when a published
application is configured to run a macro on one of the LED keys. Pressing the key
can cause multiple runs of the macro. Configureable at registry
“ica.wfclient.bypasssetled”.

[ICA]
– Fixed missing desktop/menu icons with Citrix XenApp/StoreFront.
– Fixed Citrix XenApp/StoreFront refresh command.
– Fixed matching of application names for Citrix XenApp/StoreFront autostart.
– Fixed screen lock dialog to show the logged in user name, if
Citrix XenApp password is synchronized with screen lock password.
– Citrix XenApp/StoreFront with multi monitor configuration:
Fixed fullscreen window placement if “Multi Monitor Fullscreen Mode” is set to
“Restrict fullscreen session onto one monitor” at setup page
“Sessions->Citrix->ICA Global->Window”.
Configure option “Citrix XenApp/StoreFront Start Monitor” (registry:
“ica.pnlogin.xineramamonitor”) at the same page.

[RDP Rdesktop]
– Fixed random server disconnection when audio is enabled.
– Fixed RDP login speed.
– Fixed execution of remote apps with short names.
– Fixed smart card support in RDP sessions.

[Desktop]
– Fixed autoresolution and monitor detection issues.
– Fixed VGA monitor timings.
– Fixed taskbar background with left and right taskbar position.

[base system]
– Fixed bootloader to prevent sudden system crashes,
optimized bootloader.
– Enabled Browser Sessions on IGEL IZ1-RFX.
– Fixed audio capture control in audio mixer.
– Fixed security vulnerability CVE-2014-0196

[Browser]
– Firefox crashed the system while playing videos.
Limited memory usage with these registry keys:
browserglobal.app.media_cache_size, default: 64000 (=64MB)
browserglobal.app.browser_cache_offline_capacity, default: 64000 (=64MB)

[Imprivata]
– Fixed Login dialog in multi monitor environments

Info: cloud-client.info App is now available in the Windows Store

Friday, June 27th, 2014

Hello Folks,

since today the cloud-client.info App is available in the Windows App Store, you can download it for free here: CCI App

cciapp

 

No Ads, No in app sales of course.

Have fun!

Michael

 

Video: cloud-client.info UMS Appliance 2.7 Demo Video

Thursday, June 26th, 2014

Hello Folks,

to give you a short impression of the cloud-client.info UMS Appliance i’ve uploaded a Video to youtube, have fun!

[youtube:https://www.youtube.com/watch?v=EhEYwn6wu9s]

Cheers

Michael

Info: UMS Live is now updated to IGEL Universal Management Suite 4.07.100

Friday, June 20th, 2014

Hello Folks,

i just updated the UMS Live Server to 4.07.100 (our public UMS Demonstration platform), also the last version of the cloud-client.info UMS Template is now included.

UMS4 LIVE

UMS4 LIVE

 

Connection:
Start the UMS Console and use the following connection settings:

Universal Management Suite Server: ums.cloud-client.info
Port: 443
User Name: ums
Password: live

Required UMS console: IGEL Universal Suite 4.07.100
Access to the UMS internal Webserver on Port 9080 is blocked, Firmware Updates are not possible from this server!

Cheers

Michael

Release: Cloud-Client.info UMS Appliance for Microsoft Hyper-V and Oracle Virtual Box Version 2.7

Friday, June 13th, 2014

Hello Folks,

a new Version of the Cloud-Client.info UMS Appliance for Microsoft Hyper-V and Oracle Virtual Box is available for download, Version 2.7 can be downloaded here for free: Download

cloud-client.info UMS Appliance 2.7

 

2.7

– Updated Ubuntu Subsystem
– Updated IGEL Universal Management Suite to 4.07.100
– Updated cloud-client.info UMS Template to 1.0.80

 

Cheers

Michael

 

 

 

Release: Cloud-Client.info UMS Template Version 1.0.80

Friday, June 13th, 2014

Hello Folks,

there is a new Version of the cloud-client.info UMS Template available here: Download

Here is a short overview about the changes coming with Version 1.0.80

1.0.80
——
– Support for IGEL Universal Desktop LX V5 Firmware 5.03.190
– Support for IGEL Universal Desktop LX V4 Firmware 4.13.180
– Removed support for ARM Device Firmwares regarding the lack of differences for the configuration
– Removed support for IGEL Zero Firmwares regarding the lack of differences for the configuration
– Merged Windows ES and W7 Profiles to provide a better overview
– Added Profiles for IGEL Linux V5 to switch between Citrix Receiver Version 12 and 13 (Review Firmware release notes!)
– Added Profile for IGEL Linux V5 to enable Cafe Wireless (Wireless Manager available for the User)
– Added Profile for IGEL Linux V4/V5 to configure the Audio volume
– Added Profile for IGEL Linux V5 to configure the H264 Codec for Citrix Receiver 13
– Added Profile for IGEL Linux V5 to configure the Kerberos implementation for Citrix Receiver 12
– Added Profile for IGEL Linux V5 to disable the NLA Authentication for RDP Sessions (Local Login Window)
– Added Profile for IGEL Linux V5 to disable the Network Tray Icons (LAN and WiFi)
– Added Profile for IGEL Linux V5 to disable/hide the Webcam Information/Tool for the User
– Added Profile for IGEL Linux V4/V5 to configure the “middle” Mouse button behavior in a Citrix Session
– Updated Template via Import Files for LX/OS and W7/ES
– Removed old Firmwares
– Profiles Total 477

Cheers

Michael

 

Release: IGEL Universal Desktop LX/OS 5.03.190

Thursday, June 12th, 2014

IGEL Linux
==========
Version 5.03.190
June 11 2014
Supported devices: UD2-LX, UD3-LX, UD5-LX, UD9-LX, UD10-LX
IZ2-RFX, IZ2-HDX, IZ2-HORIZON, IZ3-RFX, IZ3-HDX, IZ3-HORIZON
Versions
========
– Citrix Receiver 12.1.8.250715
– Citrix Receiver 13.0.2.265571
– Citrix HDX Realtime Media Engine 1.4.0-902
– Citrix Access Gateway Standard Plug-in 4.6.3.0800
– IGEL Legacy RDP Client 1.0
– IGEL RDP Client 2.1
– FabulaTech USB for Remote Desktop 5.0.0
– VMware View client 2.3.0-1551379
– Quest vWorkspace Client 7.6
– Leostream Java Connect 2.4.57.0
– Ericom PowerTerm 9.2.0.6.20091224.1-_rc_-25848
– Ericom Webconnect 5.6.0.4000-rel.20413
– IBM iSeriesAccess 7.1.0-1.0
– Firefox 17.0.11
– Oracle JRE 1.7.0_55
– Totem Media Player 2.30.2
– Voip Client Ekiga 3.2.7
– Thinlinc Client 3.2.0
– NX Client 3.5.0-7
– Cisco VPN Client 4.8.02.0030-k9
– NCP Secure Client (Enterprise) 3.25-rev15580-i686
– ThinPrint Client 7.0.59
– Xorg X11 Server 1.11.4
– Xorg Xephyr 1.7.6
– PC/SC Lite 1.8.9
– MUSCLE CCID Driver 1.4.13
– Omnikey CCID Driver legacy-3.6.0
– Omnikey RFID Driver legacy-2.7.2
– HID Global Omnikey CCID Driver 4.0.5.1
– REINER SCT cyberJack Driver 3.99.5final.SP03
– SCM Microsystems CCID Driver 5.0.27
– Safenet / Aladdin eToken Driver 8.1.0-4
– ACS CCID Driver 1.0.5
– A.E.T SafeSign PKCS#11 Library 3.0.3665
– Gemalto IDPrime PKCS#11 Library 1.1.0
– Athena IDProtect PKCS#11 Library 623.07
– SecMaker NetID PKCS#11 Library 6.1.1.21
– Philips Speech Driver 12.0.9
– Legacy Philips Speech Driver 5.0.10
– Client 0.8.3 for RedHat Enterprise Virtualization Desktops 3
– INTEL Graphics Driver 2.17.0
– ATI Graphics Driver 6.14.99_git20111219
– VIA Graphics Driver 5.76.52.92-126076
– 2X Client 10.1-1263
– Imprivata OneSign ProveID Embedded
==================
Information:
==================
IMPORTANT: This releases integrates two Citrix Receiver versions 12 and 13.
You can only choose to run either of the versions.
The old 12 Citrix Receiver is still available for compatibility reasons and
activated by default. Version 13 of the Citrix Receiver can be activated at
the local setup of the device or through a UMS profile configuration.
Please check in this readme which restrictions apply and how to switch the
versions.

==================
Known issues:
==================
[ICA/Citrix Receiver 13]
– Currently Kerberos is not supported, so Kerberos passthrough will not work
with ICA sessions and Citrix XenApp/StoreFront.
Workaround: configure “Passthrough authentication”
– Smartcard authentication is supported for ICA sessions created on the IGEL
device (supported with Citrix servers up to version 6.5). Kerberos
passthrough and Citrix XenApp/StoreFront login are not supported.
– Only the “User name and password” StoreFront authentication method is supported.
– During Citrix XenApp/StoreFront logoff the logoff for running desktop sessions
does not work.
– Com-port redirection is not supported.
– Webcam redirection is not supported with H.264 hardware and software encoding,
still legacy theora encoding is supported.

[RDP]
– Fabulatech USB Redirection is not supported with IGEL Legacy RDP Client 1.0.
Please use IGEL RDP Client 2 – RDP legacy mode can be deactivated at
IGEL Setup -> Sessions -> RDP -> RDP Global -> Options page

[Quest vWorkspace]
– Multimedia Redirection:
Sound redirection is not working with WMV/WMA streams
– USB Redirection does not work reliable
==================
IGEL Linux 5.03.190 (stable build based on 5.03.120)
==================
New features:
==================
[VNC]
– Added VNC secure mode, based on a SSL-encrypted VNC connection. The SSL
connection uses a special certificate located in the directory /wfs/ca-certs.
This feature requires the Universal Management Suite (UMS) to be involved,
to handle the shadowing permissions and double check whether the connection
is allowed or not. In addition the UMS is used to assure a secure credential
exchange between the TC and the UMS console.
IMPORTANT: The UMS must have the version 4.07.100 or higher!
The feature can be enabled in IGEL setup at “System->Shadow->Secure Mode”
(registry key: network.vncserver.secure_mode, default: off)

[Java]
– Update Java Runtime Environment to version 1.7.0

[Flash]
– Updated Flash Player download URL to version 11.2.202.359

[UMS]
– Added information about network speed and duplex mode of Thin Client in the
system information pane along with other Thin Client specific properties.

==================
Fixed bugs:
==================
[ICA]
– Fixed HDX Flash Redirection to work with enabled server-side content
fetching (SSCF)

[RDP]
– Fixed local logon window for IGEL RDP Client 2 to customize the Server-URL
within the logon window.
==================
IGEL Linux 5.03.120 (stable build based on 5.03.110)
==================
Fixed bugs:
==================
[RDP]
– Fixed program crash on a UD2 if RemoteFX is enabled.
– Fixed window position if VESA mode is enabled.
==================
IGEL Linux 5.03.110 (stable build based on 5.03.100)
==================
Fixed bugs:
==================
[Windowmanager]
– Fixed hotkeys for switching additional keyboard layouts.

[base system]
– Restricted RPC access: RPC informations are only reported to localhost now.

[Network]
– Fixed a problem with 802.1X authentication in connection with SCEP.
– Improved dynamic DNS registration with method DNS.

[WiFi]
– Fixed a bug that broke WiFi roaming between multiple SSIDs under certain circumstances.