Archive for the ‘IGEL’ Category

Release: IGEL Universal Management Suite 4.07.100

Thursday, June 12th, 2014

================
IGEL Universal Management Suite
================
Version 4.07.100
Release date: 11.06.2014
================
Notes:
================

If the windows installer does not start on Windows Server 2003 hosts,
contace IGEL support to get an UNSIGNED setup executable. This will solve
the issue.

The stand alone VNCViewer application has been removed in version 4.05.220.
Use UMS Console with appropriate user permissions to replace it.

The linux installer is tested with
– Ubuntu 12.04 (32bit)
– RedHat Enterprise Linux 6 (32bit)

For further compatibility information check the Universal Management Suite
Data Sheet at www.igel.com.
================
New features
================

– Recycle Bin in management tree: deleted tree items are moved to the
recycler by default and can be restored if needed
* all object types but searches and SWP elements supported
* thin clients remain unchanged (won’t get new settings) as long as they
are in the bin
* assignments are not processed as long as the assigned object
(profile, firmware update, ..) are in the bin
* jobs in bin are not executed
– Secure VNC shadowing
* shadowing through secure connection (SSL)
* only UMS console can start shadowing session
* external VNC viewers (configured in UMS console) are supported
* every shadowing session is logged in UMS
* enable secure VNC in thin client configuration (System->Shadow
NOTE: UDLX v5.03.190 or higher is required to use this feature
– Quick search available in UMS console toolbar
* search is performed on management tree directly
* considered attributes are
+ all management tree nodes: name, ID
+ thin clients: MAC address, last known IP
– Universal Firmware Update enhancements
* Release notes are stored in UMS console and may be opened after
downloading a firmware
* available firmware update list provides matching hardware names (H820, ..)
for every firmware update
* Universal Firmware Update configuration:
‘Synchronize Firmware Information’ button replaced by automated solution
– New support info feature: collect relevant files (setup.ini, group.ini,
system logs, ..) from a thin client via UMS; menu item is
‘Help->Save TC files for support’
– Console common:
* configuration change mark (blue dot on thin client icon) enhanced:
change mark is displayed in profile assignments to give a hint, which
profile change has not been transferred to the thin client yet.
* performance optimization in tree expand action
– Console profiles:
* profile ID is displayed in profile details
* profile import now consideres description field and ‘overwrite sessions’ flag
– Console thin clients
* additional column in thin client information: Cost Center
– Configuration dialog updated to support latest firmware configurations
– VNC shadowing:
* enhanced hotkey mapping: Ctrl+Alt+[key], Shift+Ctrl+Alt+[key] supported

================
Fixed bugs
================

– Database issues
* fixed update problems with Microsoft SQL Server Cluster database
* fixed SQL Syntax error for Oracle database with more than thousand thin clients
(problem with expression count in ‘in’ statement)
– AD / LDAP integration
* fixed problem with LDAP certificates when testing the LDAP connection
(“LDAP: Error code 12 – Unavailable Critical Extension”)
– Console Thin clients
* fixed ‘wake up’ command issue with mutliple network adapters
* fixed tree gaps after scaning new thin clients
* fixed column sorting issue on date columns for thin client directories
– Console Profiles:
* fixed null pointer exception when changing firmware base of all profiles
in a directory
– Console Jobs:
* fixed problems with parent directory directory relation of newly created jobs
– Console files:
* fixed delete ‘File’ issue: if a ‘File’ object is deleted in UMS, the real
file is also deleted from the webdav context
– Console Universal Firmware Update:
* fixed issue with direct assignment of matching firmware updates
– Console directories
* fixed issue when dragging a directory to its own subdirectories
– Licensing
* fixed removing thin client license file from UMS license management

Tip: How to avoid Adobe Flash in Terminal Server/VDI environments with the IGEL LX/OS

Wednesday, May 28th, 2014

Hi Folks,

maybe you also agree that Adobe Flash content is one of the biggest crap that can be used in a Terminal Server/VDI environment. For example youtube or similar site’s mostly waste expensive Server CPU resources only for watching a “funny” video..

flashtaskbar
Yeah… One User with one HD Flash Movie use 41% of  Server CPU resources!

HTML5 is still not a big deal for most site’s, so how can you handle it?

1) Ban it… Block unwanted traffic with a firewall or proxy. This is highly efficient but will upset the user base and maybe you need it (schools/education), so mostly this option is no deal.

2) Buy more Server.. More or less efficient and very expensive (Hardware, licensing, setup and cooling). No deal!

3) Use solutions like Citrix HDX Flash Redirection… More or less efficient, hard to setup and not 100% compatible, it could be a option but it’s not a real solution.

4) Ban it from the servers… I just setup this for a PoC and it seams to be the most efficient way which is also acceptable for most users. So how is the setup?

a) You need IGEL Linux based devices (LX or OS) based on the x86 architecture to do this.

b) Setup a local Firefox browser session and deploy any Version of the Adobe Flash Player for Linux to it (Browser Plugins in the IGEL Setup).

c) Assign a Hotkey to the Firefox Browser Session like ALT+CTRL+i.

d) Setup a IIS/Webserver on any System that is not already running a IIS/Webserver

e) On the Terminal Server/VDI (i recommend to use the golden Image) site open the hosts file which is located in the Windows/System32/drivers/etc folder and edit it. Now add any Website you want to outsource, point it to the “new” Webserver. Example:

192.168.1.150 youtube.com
192.168.1.150 youtube.de
192.168.1.150 anyotheruselessflashsite.com

Do not perform this for any Website which is used for “business” uploads/work! Don’t use a DNS Server to apply the configuration, this might also point the Thin Clients to a “wrong” site… Of course you can also add Webradio Website’s, browser based games or what ever you don’t want to see in a Webbrowser on the server backend. But at all.. It’s not a security solution at all, it’s to save resources only!

f) Create a small HTML Website with a short Text like “This site can not be used on a Server/VDI! Please press ALT+CTRL+i to open the local Browser and use ALT+CTRL+TAB to switch between the Browser/Session.” or similar. Make it simple and easy to understand… Now set this HTML Page as default and 404 error page for the new Webserver (d).

g) Let the user test it… If the User enter www.youtube.com the “new” Website will open and point the user how to work with the local Browser.. For the User it looks “very” embedded into the session, not 100% but it will be good enough to watch movies for most of them.

I know this solution is also not a 100% one and it can be bypassed if the User is using the IP. 😉 ..but it’s not a security solution, the User can watch Movies and you have minimized the wasted CPU resource on your backend. It’s easy to control, high compatible and everyone is happy. From my point it’s currently the best way to handle Flash until it will be fully replaced by HTML5 or any other “better” working solution. The performance depends on the User device, a UD5 will better perform than a UD2 but still: A slow client is better than a slow server for most company environments.

Also some more benefit’s.. You can seperate client traffic from your server traffic quite simple, the customer where i suggest this mentioned that they have 10GB or more “flash” streaming traffic (only youtube) per day in the server infrastructure with a little bit more than 300 user’s. You can use it with any Terminal Server/VDI solution but please note: If using VMWare View, Microsoft RemoteFX, Citrix XenDesktop x.x / XenApp 7.5 or any other solution that support real USB redirection don’t setup USB Redirection for Human Interface Devices (HID) because in this case the Mouse and Keyboard can not be used outside the Session (…and with the local Browser).

You can also add other description’s to the created “manual” website, for example for Android press the home button and open the local Browser or similar.

If you have suggestions to improve this solution feel free to give me a mail or add a comment.

Cheers

Michael

Q&A Feature added to blog@cloud-client.info

Monday, May 26th, 2014

Hello Folks,

as replacement for the forum i’ve added a Q&A Feature to the blog, you need to be a registered user to ask or answer questions. The Q&A Feature can be accessed thru the Menu on the right side (Q&A @ cloud-client.info).

Cheers

Michael

Some changes at cloud-client.info

Saturday, May 24th, 2014

Hello Folks,

we’re close to the 1.500.000 visitors mark and after looking at some facts we are doing some changes.

cloud-client.info maintenance

cloud-client.info maintenance

1) The Forum will be discontinued since today, there will be something as alternative to ask questions in the future but it seams to be that the time for old school forum’s is gone and it doesn’t make sense to use resources on this in the future. Thanks to all registered users and i hope it’s not to bad for you! If you are a native german speaker check out www.igelfreun.de. All personal user information’s will be deleted without any backup to keep the registered user data save.

2) The blog is renamed from “Unofficial IGEL Thin Client Blog” to “blog@cloud-client.info” regarding the fact that other cloud solutions got a bigger impact to this blog in the last time, IGEL Thin and Zero Clients will be still a main focus. So no worry…

3) In the upcoming weeks a “small” cloud-client.info App will be available in the Windows App Store (Windows 8(.1) and RT), work is nearly done (~90%). The App will be for free with no Ads and no in-app sales crap. Stay tuned! The App will not be available for Android or IOS but if someone is intrested to port it just send me an email. 😉

4) UMS Online is still continued… 🙂

 

Cheers

Michael

 

Release: IGEL Universal Desktop W7 Firmware Version 3.07.300

Friday, May 23rd, 2014

IGEL Universal Desktop W7
=========================
Version 3.07.300
21. May 2014
Supported devices:
UD3-W7, UD5-W7, UD9-W7, UD9-W7 Touch, UD10-W7, UD10-W7 Touch
UD3-730 W7, UD3-740 W7, UD5-730 W7, UD5-740 W7, UD9-730 W7, UD9-731 W7

=================
Notes:
=================

=================
Drivers:
=================
– Realtek RTL8169 Version:7.43.321.2011
– VIA HD Audio VT1708B: 6.0.01.8700
– Prolific PL-2303 USBtoSerial: 2.0.2.8
– FTDI UsbToSerial: 2.02.04
– OmniKey Cardman 3×21: 1.2.15.0
– Intel HD Graphics: 9.17.10.2875
– Intel PCI Communication Controller : 8.0.0.1262
– Realtek 8168: 7.61.612.2012
– Intel AHCI : 11.2.0.1006
– Gemalto Minidriver for .NET Smart Card: 8.3.1.3
– VIA WLAN VT6656: 1.1.0.2
– Intel Centrino WLAN N-1000: 15.1.0.18
– VIA Chrome 9 VX855: 8.14.14.0141
– D-LINK DWA-131 Nano: 1085.7.0815.2009
– VIA Chrome9 VX900: 8.14.14.0181
– VIA Chrome9 VX900 for TC236: 8.14.14.0231
– Ralink RT309x/2860: 3.02.01.0
– Ralink WLAN RT357x 5.1.7.0
– Intel 945 Express: 8.15.10.1930
– eGalax xTouch: 5.11.0.9020
– RTL8168C: 7.018.0322.2010
– Realtek HD Audio: 2.63
=================
Applications:
=================
– .NET: 3.5 Sp1
– Microsoft RDP Client : 8
– Internet Explorer: 8
– Windows Media Player: 12
– Sun JAVA RE: 1.7 Update 17
– Ericom WebConnect: 5.6.1.1000
– Ericom PowerTerm: 9.2.0.0
– NXClient: 3.4.0.7
– Quest vWorkspace Client: 7.6
– Ekiga VOIP Client: 3.2.6
– SAP GUI JAVA for Windows: 7.10 R 7
– Tight VNC Server: 2.0.2
– Citrix Receiver: 3.4
– Thin Print: 8.6
– VMware Horizon View Client Version: 5.4.0 build-1219906
– Fabulatech USB for Remote Desktop: 3.1.3
– NCP Enterprise Client: 9.30
– Leostream Connect Client: 2.7.129.0
– Client for RedHat RHEV-D: 3.0-26
– USB Redirection for RedHat RHEV-D: 3.0-26
– Sumatra PDF Reader: 2.1.1
=================
New features:
=================
-[System]:
– Product identification for the UD3 (M330C) updated.
– Support for the new USB 3.0 module in the UD3 (M330C) added.
– Support for updated Omnikey Smartcardreader added.
=================
Bug fixes:
=================
-[System]:
– Wireless regulatory domain configuration is now working with
WLAN module Ralink RT 3572.
– Fixed bug: Rotation not possible with UD3 (M330)
(ISUS: 2014043010000651)

=================
Known Issues:
=================
-[System]:
– Xen Desktop Appliance Mode is not working.
-[FABULATECH]:
– Fabulatech USB for Remote Desktop is currently
not working with Citrix XenDesktop.
-[VmWare]:
– USB Redirection: Devices connected to a USB 3.0 Port will not
be redirected.

Tip: UD3 / UD5 Mini PCI Express Port and mSata Harddisk

Sunday, May 18th, 2014

Hello Folks,

in the last time i got some reports where user try to connect a mSATA SSD thru the Mini PCI Express Port coming with the IGEL UD3 / UD5 Dual Core Mainboard.

This will not work!!! The Mini PCI Express Port and the mSATA Port are looking equal but they are not.

See also Mini PCI Express Specs and Mini SATA Specs.

There are some Boards offering a “cross” compatible connector but the Port coming with the UD3 and UD5 is a pure Mini PCI Express Port and a mSATA Module will not work with it!

Cheers

Michael

cloud-client.info now offers Disqus.com comments

Friday, May 16th, 2014

Hello Folks,

you can now add comments to the blog thru disqus.com.

cloud-client.info maintenance

I hope you like the new feature.

 

Have Fun

Michael

P.S.: Please note that Ads or Spam thru this way will be handled like in the past.. 🙂

Tip: Fix missing “I want to download Adobe Flashplayer..” setting for LX/OS Profiles in UMS 4.06.100

Thursday, May 15th, 2014

Hello Folks,

maybe you also discovered the issue in the IGEL Universal Management Suite Version 4.06.100 if you create a new Profile for a LX/OS based Firmware and you want to deploy the Adobe Flashplayer.

Local at the Client you have a Setting “I want to download Adobe flashplayers and care about the licensing by myself” setting in the Session->Browser->Browser Plugins->Adobe Flash Player configuration but this setting is not available in the UMS if you create or edit a Profile. So you can not create a working configuration thru the regular UMS Profile GUI (see picture below).

umsflashmissing

You can fix this quite simple, just configure all required settings to deploy the Adobe Flashplayer in the regular GUI and now browse to System->Registry->browser_plugin->flashplayer and enable the download_flashplayer setting (see picture below).

umsflashmissingfix

Now you can save the profile and assign it to the IGEL devices, the Flash Player deployment should work now.

Cheers

Michael

 

 

php issue with www.cloud-client.info is fixed

Thursday, May 15th, 2014

Hello Folks,

i got a php issue with the www.cloud-client.info site, this issue is fixed now. Sorry!

cloud-client.info maintenance

cloud-client.info maintenance

Cheers

Michael

Migrated with UDC2: HP ProBook 6530b

Tuesday, May 13th, 2014

Hello Folks,

today i migrated a HP ProBook 6530b Intel i7 based Laptop.

hpprobook6530b

Here are the Test results with the IGEL Universal Desktop OS Version 5.03.100:

Inbuild Touchpad: Working
Inbuild Ethernet 10/100/1000: Working, Intel 82577LM
Inbuild Audio Card: Working, Intel 3400 HD chipset
Inbuild WiFi: Working, Intel Centrino N 6200
Inbuild SD/MMC Card Reader: Working
Inbuild GFX Chipset: Working, Intel Arrandale
Inbuild Keyboard: Working incl. Mouse key
Inbuild Webcam: Working, HP Webcam 2MP
Inbuild USB Ports: Working, Intel 3400 USB2 Enhanced Host Controller
Inbuild SATA Controller incl. external ESATA Port: Working, Intel 3400 Series SATA controller
Inbuild PCI-Express Slot: Working

Cheers
Michael

Tip: Using ICA Sessions with IGEL Linux 5.03.100 and XenApp/XenDesktop 7.x

Thursday, May 8th, 2014

Hi Folks,

in the release notes for the IGEL Firmware 5.03.100 IGEL mentioned that “single” ICA session are not possible with the Citrix Receiver 12/13 for Linux and XenDesktop/XenApp 7.x:

"- ICA sessions created on the IGEL device only work
with Citrix XenApp servers up to version 6.5."

This statement is not really true because in Citrix Terms it means only ICA Sessions based on the Citrix IMA Service (XenDesktop or XenApp 7.5 is using FMA), it is not right for sessions based on a Server IP Address or Hostname where the IMA service is not required/used.

This is also mentioned in the Citrix Edocs in the XenDesktop/XenApp 7.5 Feature description:

  • Custom ICA files — Custom ICA files were used to enable direct connection from user devices (with the ICA file) to a specific machine. In this release, this feature is disabled by default, but can be enabled for normal usage using a local group or can be used in high-availability mode if the Controller becomes unavailable. 

If configured right it can be also used as small HA “solution” for smaller installations with only one XenDesktop/XenApp controller server, please refer also to:  How to enable simple XenDesktop/XenApp 7.5 HA Mode

To enable the feature in general follow this article: Enable direct ICA connections for XD/XA 7.x

In the ICA Session configuration in the UMS Profile/local Thin Client configuration use only the Server IP/Hostname for the connection (see picture below), if you have more than one Server you need to create seperate profiles for each server and assign the profiles to different clients. Of course this is a “manual” work but you are still able to use the ICA sessions if required, a Citrix Storefront or Webinterface Server is not required in this case. If HA mode is enabled like mentioned also a XenDesktop/XenApp 7.x controller can be offline for a short time period (for example maintenance).

 

icssession

Disadvantage:

1) It will only work in LAN environments.
2) No Load Balancing, the clients will always connect to “one” server or you have to configure “several” ICA sessions per Client.
3) No “roaming” sessions if the User use several Thin Clients and these Clients are connecting to different server.
4) Not really usefull for large environments.

It will work with Citrix Receiver 12 and 13 for Linux but also older Receiver Versions (any OS) should work with it.

Cheers

Michael

Release: IGEL Universal Desktop LX / OS 5.03.100

Wednesday, April 30th, 2014

IGEL Universal Desktop OS 2
===========================
Version 5.03.100
Apr 30 2014

====================
Notes:
====================
IMPORTANT:
Dual monitor configuration for “unsupported hardware” works only if “native
driver support” works properly. It is a prerequisite to assure that the
native driver is really working, as the fallback VESA driver does not provide
any dual monitor configuration. Have a look at Application Launcher’s
About tab->Hardware-Graphics Chipset. If VESA is listed there the native
driver does not work and dual monitor configuration is not functional.
Versions
========
– Citrix Receiver 12.1.8.250715
– Citrix Receiver 13.0.2.265571
– Citrix HDX Realtime Media Engine 1.4.0-902
– Citrix Access Gateway Standard Plug-in 4.6.3.0800
– IGEL Legacy RDP Client 1.0
– IGEL RDP Client 2.1
– FabulaTech USB for Remote Desktop 5.0.0
– VMware View client 2.3.0-1551379
– Quest vWorkspace Client 7.6
– Leostream Java Connect 2.4.57.0
– Ericom PowerTerm 9.2.0.6.20091224.1-_rc_-25848
– Ericom Webconnect 5.6.0.4000-rel.20413
– IBM iSeriesAccess 7.1.0-1.0
– Firefox 17.0.11
– Totem Media Player 2.30.2
– Voip Client Ekiga 3.2.7
– Thinlinc Client 3.2.0
– NX Client 3.5.0-7
– Cisco VPN Client 4.8.02.0030-k9
– NCP Secure Client (Enterprise) 3.25-rev15580-i686
– ThinPrint Client 7.0.59
– Xorg X11 Server 1.11.4
– Xorg Xephyr 1.7.6
– PC/SC Lite 1.8.9
– MUSCLE CCID Driver 1.4.13
– Omnikey CCID Driver legacy-3.6.0
– Omnikey RFID Driver legacy-2.7.2
– HID Global Omnikey CCID Driver 4.0.5.1
– REINER SCT cyberJack Driver 3.99.5final.SP03
– SCM Microsystems CCID Driver 5.0.27
– Safenet / Aladdin eToken Driver 8.1.0-4
– ACS CCID Driver 1.0.5
– A.E.T SafeSign PKCS#11 Library 3.0.3665
– Gemalto IDPrime PKCS#11 Library 1.1.0
– Athena IDProtect PKCS#11 Library 623.07
– SecMaker NetID PKCS#11 Library 6.1.1.21
– Philips Speech Driver 12.0.9
– Legacy Philips Speech Driver 5.0.10
– Client 0.8.3 for RedHat Enterprise Virtualization Desktops 3
– INTEL Graphics Driver 2.17.0
– ATI Graphics Driver 6.14.99_git20111219
– VIA Graphics Driver 5.76.52.92-126076
– NVIDIA Graphics Driver 304.60
– 2X Client 10.1-1263
– Imprivata OneSign ProveID Embedded

 

====================
Information:
====================
IMPORTANT: This releases integrates two Citrix Receiver versions 12 and 13.
You can only choose to run either of the versions.
The old 12 Citrix Receiver is still available for compatibility reasons and
activated by default. Version 13 of the Citrix Receiver can be activated at
the local setup of the device or through a UMS profile configuration.
Please check in this readme which restrictions apply and how to switch the
versions.

====================
Known issues:
====================
[ICA/Citrix Receiver 13]
– Currently Kerberos is not supported, so Kerberos passthrough will not work
with ICA sessions and Citrix XenApp/StoreFront.
Workaround: configure “Passthrough authentication”
– Smartcard authentication is supported for ICA sessions created on the IGEL
device (supported with Citrix servers up to version 6.5). Kerberos
passthrough and Citrix XenApp/StoreFront login are not supported.
– Only the “User name and password” StoreFront authentication method is supported.
– During Citrix XenApp/StoreFront logoff the logoff for running desktop sessions
does not work.
– Com-port redirection is not supported.
– Webcam redirection is not supported with H.264 hardware and software encoding,
still legacy theora encoding is supported.

[RDP]
– Fabulatech USB Redirection is not supported with IGEL Legacy RDP Client 1.0.
Please use IGEL RDP Client 2 – RDP legacy mode can be deactivated at
IGEL Setup -> Sessions -> RDP -> RDP Global -> Options page

[Quest vWorkspace]
– Multimedia Redirection:
Sound redirection is not working with WMV/WMA streams
– USB Redirection does not work reliable

[NVIDIA graphics support]
– In dual screen configurations DPMS monitor saving mode creates
display content corruptions on secondary VGA display after resume
====================
New features:
====================
[ICA/Citrix Receiver 13]
– Added Citrix Receiver 13.0.2
– Added support for StoreFront

Hints (It is IMPORTANT to read this, if you plan to use Citrix Receiver 13
instead of 12 and/or want to connect to a Citrix server version 7.x):
– This firmware contains two Citrix Receivers, but only one of them can be
active at a time. Default is Citrix Receiver 12. The version can be
switched by the new parameter “Use Citrix Receiver version 13” in the
IGEL setup at “Sessions->Citrix->Citrix Receiver Selection” (registry:
ica.useversion13). For Citrix Receiver 13 configuration setting the new
parameter “Citrix server version” is mandatory (see below).
– The new parameter “Citrix server version” on IGEL setup page
“Sessions->Citrix->Citrix XenApp/StoreFront->Server” (registry key:
ica.pnlogin.serverversion) defines the capabilities of the Receiver
accroding to the used Citrix server versions (default is “XenApp 6.x or
older”):
IMPORTANT FOR SERVER URL CONFIGURATION in the IGEL registry (With local
IGEL Setup or UMS 4.07.100 the server url is automatically stored at the
correct keys, if you use the provided setup page at
“Sessions->Citrix->Citrix XenApp/StoreFront->Server”):
Depending on the Citrix server version you have configured, different
sets of server url configurations apply:
* XenApp/XenDesktop 7.x Store:
For access to a Citrix Storefront:
registry keys ica.pnlogin.browseraddress_store<NR>.*
(optional: ica.pnlogin.browseraddress_store<NR>.farm)
* XenApp/XenDesktop 7.x Legacy Mode
For access to the legacy mode of a Citrix Storefront:
registry keys ica.pnlogin.browseraddress_store_legacy<NR>.*
(optional: ica.pnlogin.browseraddress_store_legacy<NR>.farm)
* XenApp 6.x or older:
For access to a XenApp Server:
registry keys ica.pnlogin.browseraddress<NR>.*
(optional: ica.pnlogin.browseraddress<NR>.farm)

– For Citrix StoreFront access with Citrix Receiver 13 only https web interfaces
are supported. If the SSL certificate of your Citrix server is not signed
by a trusted certificate authority (like Verigsign, Thawte etc.), you have to
install the root certificate of your own certificate authority on each Thin
Client.
Please use http://edocs.igel.com/index.htm#10200413.htm to access the document
on how to install SSL certificate.
– With Citrix Receiver 13 it is not possible to connect to a Citrix server
with other methods than the web interface (this affects the parameter
“Use Citrix XenApp Services Site” registry key: ica.pnlogin.useserversettings).
Due to that it is not possible to select another password change method than
“Citrix XenApp Services Site”.
– ICA sessions created on the IGEL device only work with Citrix XenApp servers up
to version 6.5.
– The parameter “Deferred update mode” has no effect anymore.
– The window options on IGEL setup page
“Sessions->Citrix->Citrix XenApp/StoreFront->Options” are not supported anymore.

Hints for the configuration on server side (for Citrix servers version 7.x):
– After installation and basic configuration of Machine Catalogs and Delivery
Groups, you end up with a store that uses http only. But the Citrix Receiver
13 for Linux supports stores with https only (the Windows version of Citrix
Receiver has this limitation, too; but it is possible to change some
registry keys on the client side to enable http support; unfortunately
this is not possible with the Linux version of Citrix Receiver).
– To switch the store to https, change the base URL on page “Server Group”
in the Citrix StoreFront Management Console.
– Then adjust the “Transport Type” in the “Manage Delivery Controllers”
dialog of the “Store” page in Citrix StoreFront Management Console.
– Then add a https binding for the website in the IIS Management Console
(you have to choose an SSL certificate in the corresponding dialog).
– Password change is disabled by default on a Citrix server 7.x. To enable it,
open the Citrix StoreFront Management Console and go to page
“Authentication”. Click on the authentication method “User name and
password” and then on “Manage Password Options” on the right pane.
– The error messages of Citrix servers 7.x and Citrix Receiver 13 are terribly
misleading. When you are using Citrix servers 7.x and you experience
problems with the connection itself or login, please double check
that everything is ok on the server side. It is a good thing to check the
overview page for a target machine in Citrix Studio. To get there, choose
“View Machines” in the context menu of a Delivery Group.
Then check for each machine:
– that the “Registration State” of the machine is “Registered”
– that the “Maintenance Mode” of the machine is “Off”
– that the “Power State” of the machine is “On”
– that you are using the correct user if there is a user
mentioned in the column “User”.
Also, if something does not work (although it really should), try to reboot
the Citrix server. In our tests this helped sometimes when we experienced
strange problems.

– With Citrix Receiver 13 there is support for new graphics codec parameters:
– H264 deep compression codec registry keys:
* ica.wfclient.h264enabled (disabled by default)
* ica.wfclient.texttrackingenabled
* ica.wfclient.smallframesenabled
The H264 codec is only usable if the multimedia codec pack is installed.
– JPEG codec registry keys:
* ica.wfclient.directdecode
* ica.wfclient.batchdecode (enabled by default)

Detailed description of the parameters are available at:
http://support.citrix.com/proddocs/topic/receiver-linux-13-0/receiver-linux-13-0.html and

Click to access Linux-OEM-Guide-13.0-12-13-13.pdf

[ICA/Citrix Receiver 12]
– Improved ICA sessions with Kerberos Passthrough: it is now possible to choose
the Kerberos implementation(s) which are used with Citrix via parameter
ica.module.virtualdriver.sspi.kerberosselection.

[RDP]
– Changed default authentication mode to support NLA authentication aside local logon
for automatic access to Windows Server 2008, 2008 R2, 2012 and 2012 R2.
You can disable local logon and network authentication at IGEL setup page
“Sessions->RDP->RDP Global->Local Logon”
(registry: rdp.login.use_rdplogin and rdp.login.enable-network-authentication)
– IGEL RDP 2 only:
– Improved RDP remote apps
– correct positioning of drop down windows
– improved window maximizing and minimizing
– fixed display errors
– Added support for audio recording capability
– Improved RD Web Access:
Added support for the following options at IGEL setup page “Sessions->RDP->RDP Global”:
– Mapping (everything)
– Performance (RemoteFX only)
– Options (Inverted cursor color only)
– Native USB Redirection
– Multimedia Redirection .
– Added RDP session resolution with random settings.
– Added a “RDP connection bar” in a fullscreen RDP sessions, to minimize and quit the session.
The feature can be enabled at IGEL setup page “Sessions->RDP->RDP Global->Window->Enable toolbar”
(registry key: rdp.winconnect.enable-toolbar)

[ICA/RDP]
– Added new method to define multiple USB serial devices:
“Sessions->Citrix->ICA Global->Mapping->COM Ports->COM Port Devices”
(registry: ica.wfclient.comport<NR>)
“Sessions->RDP->RDP Global->Mapping->COM Ports->COM Port Devices”
(registry: rdp.winconnect.comport<NR>)
“Devices->Printer->CUPS->Printers->Printers”
(registry: print.cups.printer<NR>.serial_device)
For RDP and ICA COM Port Mapping, serial printers, USB serial devices
can be defined through USB vendor and device ID. This is done in the format
/dev/usbserial/ttyUSB_Vxxxx_Pyyyy, where xxxx and yyyy are the USB vendor
and product IDs in lower case hexadecimal digits (4 digits each).
In the IGEL Setup running on the thin client currently available devices
will be shown when pressing the “Detect Devices…” button.
– Updated Philips Speech Drivers to version 12.0.9

[VMware Horizon View]
– Updated VMware Horizon View to version 2.3.0-1551379
– Added Realtime Audio Video (RTAV) support. Can be activated in IGEL setup at
“Sessions->Horizon View Client Global->Real Time Audio Video”
– Added switch for “Ctrl+Alt+Insert” redirection to VM. Depending on server
configuration either “Ctrl+Alt+Insert”, “Ctrl+Alt+Delete” or no action can be triggered.
The registry key is located at “vmware.view.sendctrlaltinstovm” (default is false).
– For passthrough authentication added possibility to use the shortened domain name
instead of the fully qualified domain name, like “EXAMPLE” instead of “EXAMPLE.COM”.
Enable shortened domain name for a particular session with registry key
sessions.vdm_client<NR>.options.passthrough_shortdomain

[VPN]
– Added NCP Secure Enterprise client version 3.25-rev15580-i686

[WiFi]
– Updated all WiFi drivers backported from 3.13.2 Linux kernel,
new support for dual Band 2.4GHz/5Ghz wireless USB adapters
based on Ralink RT3572 chipset.
For other new supported devices, please check 3rd party hardware database.
– Added support for self service WiFi connections (Cafe Wireless):
The user can manage and select WiFi connections via the WiFi tray icon’s context menu.
This feature is disabled by default. It can be enabled at IGEL setup page
“Network->LAN Interfaces->Wireless->Enable wireless manager” (registry:
network.applet.wireless.enable_connection_editor)
– Added new parameters for better control of WiFi roaming capabilities with access
points that share the same SSID:
* network.interfaces.wirelesslan.device0.lock_initial: Default: false
If true the device will stick to the access point it is connected to
even if candidates with better signal quality are present.
Setting this parameter to true is a last resort for problems that are caused by
too much roaming.
* network.interfaces.wirelesslan.device0.bgscan.module: Default: “none”
These settings should be changed by experts only.
Selection of the bgscan (“background scan”) module used by wpa_supplicant
in the cases of WPA Enterprise and WPA2 Enterprise.
If the parameter “lock_initial” is set to true, it is recommended that this be “none”.
Possible values:
– “none”:
No background scanning is done.
– “simple”:
The WiFi module tries to scan for a potentially better fitting AP in the background.
The simple module has the following parameters (default values are those
hardcoded in NetworkManager 0.9.4.0):
* network.interfaces.wirelesslan.device0.bgscan.simple.signal_strength: (default: -45)
This defines a threshold that determines which of the following two parameters
shall be effective.
A signal level (dBm) is expected.
* network.interfaces.wirelesslan.device0.bgscan.simple.short_interval: (default: 30)
Interval between background scans in seconds if the actual signal level
of the currently connected access point is worse than
network.interfaces.wirelesslan.device0.bgscan.simple.signal_strength.
* network.interfaces.wirelesslan.device0.bgscan.simple.long_interval: (default: 300)
Interval between background scans in seconds if the actual signal level
of the currently connected access point is better than
network.interfaces.wirelesslan.device0.bgscan.simple.signal_strength.
– Added new parameters that control WiFi roaming between WiFi networks with different SSIDs:
* network.interfaces.wirelesslan.device0.mssid_check_interval: (default: 10)
The interval in seconds between checking if automatic roaming might be neccessary.
This includes detecting that a connection has been lost and a new one should be
established..
* network.interfaces.wirelesslan.device0.mssid_quality_threshold: (default: 20)
If the current connection’s quality percentage is below this value
scanning will be performed to find a potentially better network.
* network.interfaces.wirelesslan.device0.mssid_quality_difference_threshold: (default: 40)
A candidate for automatic roaming is only considered if its quality percentage
is this much better than the current connection’s quality.
* network.interfaces.wirelesslan.device0.mssid_previously_used_threshold: (default: 55)
During boot: If the previously used SSID’s quality percentage is above this threshold
it is preferred.
* network.interfaces.wirelesslan.device0.mssid_user_selection: Default: false
If true, the user can initiate roaming to a network via the WiFi tray icon’s context menu.
(The context menu must be enabled.).
If automatic roaming shall not interfere with the user’s choice, the following
values are appropriate:
network.interfaces.wirelesslan.device0.mssid_quality_threshold=0
network.interfaces.wirelesslan.device0.mssid_quality_difference_threshold=101
network.interfaces.wirelesslan.device0.mssid_previously_used_threshold=0

[Network]
– Added network-related system tray icons, one per device and VPN controlled with
the following settings:
Wired:
* IGEL setup “Network/Lan Interfaces->Interface[1,2]->Enable tray icon”
(registry: network.applet.lan[1,2].enable_trayicon):
Defines whether the tray icon is shown or not (default: enabled)
* IGEL setup “Network/Lan Interfaces->Interface[1,2]->Enable context menu”
(registry: network.applet.lan[1,2].enable_context_menu):
Switches the the context menu on or off (default: enabled)
* IGEL setup “Network/Lan Interfaces->Interface[1,2]->Enable network info dialog”
(registry: network.applet.lan[1,2].enable_network_info_dialog):
Switches access to the info dialog on or off (i.e. IP address) (default: enabled)
Wifi:
* IGEL setup “Network/LAN Interfaces/Wireless->Enable tray icon”
(registry: network.applet.wireless.enable_trayicon):
Defines whether the tray icon is shown or not (default: enabled)
* IGEL setup “Network/LAN Interfaces/Wireless->Enable context menu”
(registry: network.applet.wireless.enable_context_menu):
Switches the the context menu on or off (default: enabled)
* IGEL setup “Network/LAN Interfaces/Wireless->Enable network info dialog”
(registry: network.applet.wireless.enable_network_info_dialog):
Switches access to the info dialog on or off (i.e. IP address) (default: enabled)
* IGEL setup “Network/LAN Interfaces/Wireless->Enable wireless manager”
(registry: network.applet.wireless.enable_connection_editor):
Switch access to the self service wireless manager on or off (default: disabled)
VPN:
* IGEL setup “Network->VPN->Enable tray icon”
(registry: network.applet.vpn.enable_trayicon):
Defines whether the tray icon is shown or not (default: enabled)
* IGEL setup “Network->VPN->Enable context menu”
(registry; network.applet.vpn.enable_context_menu):
Switches the the context menu on or off (default: enabled)
* IGEL setup “Network->VPN->Enable network info dialog”
(regsitry: network.applet.vpn.enable_network_info_dialog):
Switches access to the info dialog on or off (i.e. IP address) (default: enabled)
[PowerTerm]
– Improved PowerTerm Interconnect IBM 5250 Emulation:
Added new parameters KBDTYPE and CHARSET at IGEL Setup page
“Sessions->PowerTerm Terminal Emulation->[Session Name]->General”.

[Java]
– Updated Java Runtime Environment to 1.7.0 U55.
– Added exception sites list to allow Java applications to be run after
the appropriate security prompts (according to Oracle’s JRE security
policy).
Exception sites (=URL) can be added at IGEL’s registry parameter
“java.deployment.exception_site%”. There you have to add a new instance for
each site.
Example: Use a self-signed Java webstart application.
– Added possibility to set the JRE security level by changing the registry
key “java.deployment.security_level”.

[base system]
– Updated FabulaTech USB for Remote Desktop to version 5.0
– Updated StepOver serversonet to version 0.7.16
– Updated Adobe Flash Player download url to version 11.2.202.356
– New TC Setup version 4.6.13
– Improved Active Directory/Kerberos Logon to specify the default lifetime and renewal
lifetime of Kerberos tickets through registry parameters:
– “auth.krb5.libdefaults.ticket_lifetime” (default: 10 hours)
– “auth.krb5.libdefaults.renew_lifetime” (default: 7 days)
– Changed the hotkey to hide all windows and show the desktop to be active by default.
The default hotkey is “Ctrl + Windows-Key + ‘d'”. You can disable the hotkey at IGEL setup:
“User Interface->Hotkeys->Commands->Hide all windows and show desktop”
– Updated Chinese, Dutch, French and German userinterface translations.
– Added an webcam test application. The application can be started from
“Application Launcher->System tab->Webcam Information”.
For scripting access use the command “webcam-info”:
* option “-l”:
retrieve a list containing all possible frame resolutions and frame rates.
– Fixed tray-manager regarding missing system tray icons in some cases.

[Smartcard]
– Added new smart card PKCS#11 library Athena IDProtect version 623.07.
– Added new SecMaker Net iD PKCS#11 library 6.1.1.21,
the SecMaker Net iD Browser Plugin has been removed.
– Added new version 1.1.0 of Gemalto IDPrime PKCS#11 Library with support for
all new IDPrime cards.
– Added new HID Global Omnikey smart card reader driver version 4.0.5.1
IMPORTANT:Some applications (e.g. A.E.T. SafeSign) require the following parameter
to be set in the registry: scard.pcscd.omnikey_tpdu_t1mode
Support for the following new driver models is added:
VendorID ProductID Name in Driver
0x076B 0x0596 OMNIKEY CardMan (076B:0596) 2020
0x076B 0x3020 OMNIKEY CardMan (076B:3020) 3020
0x076B 0x3022 OMNIKEY CardMan (076B:3022) 3021
0x076B 0x3620 OMNIKEY CardMan (076B:3620) 3620
0x076B 0x7021 OMNIKEY CardMan (076B:7021) 3121
0x076B 0x3623 OMNIKEY CardMan (076B:3623) 3621
0x076B 0x3822 OMNIKEY CardMan (076B:3822) 3821
0x076B 0x3823 OMNIKEY CardMan (076B:3823) 3821
0x076B 0x5820 OMNIKEY CardMan (076B:5820) 4121 CL
0x076B 0x512D OMNIKEY CardMan (076B:512D) 5025 PROX CL
0x076B 0x502A OMNIKEY CardMan (076B:502A) 5025 PROX CL
0x076B 0xC001 OMNIKEY CardMan (076B:C001) 5121
0x076B 0xC100 OMNIKEY CardMan (076B:C100) 5121
0x076B 0xC101 OMNIKEY CardMan (076B:C101) 5121
0x076B 0xC104 OMNIKEY CardMan (076B:C104) 5125 CL
0x076B 0xC105 OMNIKEY CardMan (076B:C105) 5125
0x076B 0x5127 OMNIKEY CardMan (076B:5127) 5127 CK
0x076B 0x5220 OMNIKEY CardMan (076B:5220) 5220 Pay CL
0x076B 0x5221 OMNIKEY CardMan (076B:5221) 5221 Pay
0x076B 0x5311 OMNIKEY CardMan (076B:5311) 5321
0x076B 0x532B OMNIKEY CardMan (076B:532B) 5321 Pay
0x076B 0xA521 OMNIKEY CardMan (076B:A521) 5321
0x076B 0x5326 OMNIKEY CardMan (076B:5326) 5326 DFR
0x076B 0x5421 OMNIKEY CardMan (076B:5421) 5421
0x076B 0x1784 OMNIKEY CardMan (076B:1784) 6020
0x076B 0x6623 OMNIKEY CardMan (076B:6623) 6121
0x076B 0x6310 OMNIKEY CardMan (076B:6310) 6311 CL
0x076B 0x1BD0 OMNIKEY CardMan (076B:1BD0) 7120
0x076B 0x1BD1 OMNIKEY CardMan (076B:1BD1) 7121
0x076B 0x8630 OMNIKEY CardMan (076B:8630) 8630
0x076B 0x9621 OMNIKEY CardMan (076B:9621) 9621
0x076B 0xA023 CCID SC Reader (076B:A023)
0x076B 0xA024 CCID SC Reader (076B:A024)
0x076B 0xA111 CCID SC Reader (076B:A111) Keyboard
0x076B 0xA112 CCID SC Reader (076B:A112) Keyboard
0x076B 0xA721 CCID SC Reader (076B:A721)
0x076B 0xB000 CCID SC Reader (076B:B000) HID identiCLASS
0x076B 0xB001 CCID SC Reader (076B:B001) iCLASS Smart@Link
0x076B 0xC000 CCID SC Reader (076B:C000)
0x076B 0xC200 CCID SC Reader (076B:C200)
0x076B 0xC300 CCID SC Reader (076B:C300)
0x046A 0x007B Cherry SmartTerminal XX44 (046A:007B)
0x046A 0x0090 Cherry SC Reader (046A:0090)
0x046A 0x0091 Cherry SC Reader (046A:0091)
0x046A 0x0092 Cherry SC Reader (046A:0092)
0x0BF8 0x101B CCID SC Reader (0BF8:101B) Fujitsu D321
====================
Fixed bugs:
====================
[ICA/Citrix Receiver 12]
– Fixed Citrix XenApp matching of application names in ICA autostart list
– Fixed Citrix XenApp refresh command.
– Fixed display of user name in screen lock/unlock dialog,
if Citrix XenApp password is synchronized with screen lock password.

[ICA/Citrix Receiver 13]
– Added support for “BypassSetLED” parameter:
registry key ica.wfclient.bypasssetled, Fixed issue with enabled key:
when a published application is configured to run a macro on one of the LED keys
(Caps Lock, Num Lock, or Scroll Lock), pressing the key can cause the macro to
run multiple times.

[XenDesktop Appliance]
– Fixed a minor bug with german keyboard layout and numblock DEL key.

[RDP]
– Fixed RDP native USB redirection device rules:
Product and vendor IDs need to be entered in hexadecimal now (decimal is not
supported anymore).
Streamlined with all other USB redirection rules.
– Fixed RemoteFX codec if “Legacy mode” is enabled:
– crash of RDP sessions to Windows 8 RDVH
– wrong rendering in RDP sessions with Server 2012
– Fixed logon with Gemalto .net cards and Windows Server 2008

[VMware Horizon View]
– Fixed smart card redirection in Horizon View with RDP protocol

[Quest vWorkspace]
– Fixed fullscreen sessions started from web interface.
Additional screen dimensions defined in the websession config are ignored.
– Fixed bug for SSL secured gateway/nat/proxy settings

[PowerTerm]
– Fixed setting “Autosave Size and Position” to not send thin client settings
to UMS at termination of session any more. Instead keep size and position
stored locally on thin client.

[Imprivata]
– Fixed imprivata appliance mode to work with dual screen settings in Citrix,
if the setting “ICA->ICA Global->Window->Multi Monitor Fullscreen Mode” is enabled.

[WiFi]
– Fixed support for PCI WLAN adapter based on Ralink RT3091.

[Network]
– Fixed wrong netmask in the network information dialog of the network tray icon.

[Smartcard]
– Fixed bug in smart card service pcsc-lite: When entering the smart card PIN
with certain PIN pad readers inside an ICA session, the PIN input window was
not displayed correctly.
– Fixed SCM Microsystems/Identive smart card readers: handle older reader models
with driver version 5.0.21, only new ones with 5.0.27.
This fixes problems with old readers in driver version 5.0.27.
– Implemented SCARD_ATTR_CURRENT_PROTOCOL_TYPE in pcsc-lite;
this helps smart card log on with SafeSign minidriver

[ThinPrint]
– improved the “default” mark of a printer configured in IGEL Setup
“Devices->Printer->Thinprint->Printer”.

[base system]
– Fixed OpenSSL Heartbleed bug: CVE-2014-0160,
security patches for CVE-2014-0092,CVE-2014-1959,CVE-2013-4242.
– Fixed system suspend/resume caps-lock/scroll-lock modifiers reset.
– Fixed Kerberos authentication:
when typing a wrong password at log on or screen saver unlock, badPwdCount in
Active Directory was incremented by 2 instead of 1 and thus the account was
locked too soon.
– Fixed smart card logon to a Windows 2003 Server based Active Directory.
In this case the parameter “auth.krb5.realms.pkinit.pkinit_win2k” has to be set.
– Fixed non native resolutions with VIA VX800/VX855 graphic chipsets:
the desktop is expanded over the whole screen again.
– Fixed custom partition: For downloading via FTP over SSL use explicit FTPS
instead of implicit FTPS.
– Fixed disappearing of network connection dialog, if no pointer device is connected.
– Fixed VIA graphics chipsets for dual monitor configuration with autodetected
resolutions and manual connector assignment
– Fixed SW cursor support with VIA graphics chips
– Fixed special character % in desktop folder names
– Improved handling of Lock keys in VNC Server. All modifiers will be cleared by default
when shadowing is started. Lock keys are handled on client side only by default.
(registry: network.vncserver.clear_all and network.vncserver.skip_lockkeys)

[Java]
– Fixed smartcard access used in java webstart UMS.

Updated: cloud-client.info IGEL Hardware overview Whitepaper

Wednesday, April 30th, 2014

Hello Folks,

the cloud-client.info IGEL Hardware overview Whitepaper has been updated and contains now also the latest devices and some other small modifications.

The Whitepaper is available here: Download

Cheers

Michael

Tip: Hidden Citrix Receiver failback switch in the IGEL Linux

Wednesday, April 30th, 2014

Hello Folks,

iam not sure how long this feature already exists but i should mention it here….

IGEL has included in all current LX/OS Firmware Versions (V4.13.x or V5.01.x to < 5.03.100) a hidden “failback” Switch which can help to bypass issues with the latest included Citrix Receiver Version.

In the current IGEL Firmware 5.02.100 you are able to switch between Citrix Receiver 12.1.8.250715 (default, mentioned in the release notes) and Citrix Receiver 12.1.6.231670 (mentioned nowhere… 🙁 ). I do not unterstand why this is included as a hidden feature because it’s a clear benefit to have this option available.

Switching between these Versions is quite simple, you only need to execute the command /services/ica/bin/switch_ica_fallback. This can be done from a command line/terminal session for tests / troubleshooting or you can execute it during boottime for production. If you want to switch back to the “default” version just execute the command again… Funny right?

If you want to perform the last option open a profile or the local IGEL Setup and browse to System – Firmware Customization – Custom Commands – Desktop Commands and enter the command in the Custom Command Desktop Final field. After this change is done the setting will be active after the next reboot.

Update: This solution is not available in the Firmware 5.03.100, use here the switch in the gui or the registry setting System->Registry->ICA and enable useversion13.

Cheers

Michael

P.S.: It might be that this switch will be removed in later firmware releases..

Release: IGEL Universal Desktop LX Version 4.13.180

Tuesday, April 29th, 2014

IGEL Universal Desktop LX
=========================
Version 4.13.180
Apr 17 2014
Versions
========
– Citrix Receiver 12.1.8.250715
– Citrix HDX Realtime Media Engine 1.4.0-902
– Citrix Access Gateway Standard Plug-in 4.6.3.0800
– IGEL RDP Client 1.0
– FabulaTech USB for Remote Desktop 3.1.2
– VMware View client 2.3.0-1551379
– Quest vWorkspace Client 7.6
– Leostream Java Connect 2.4.57.0
– Ericom PowerTerm 9.2.0.6.20091224.1-_rc_-25848
– Ericom Webconnect 5.6.0.4000-rel.20413
– IBM iSeriesAccess 7.1.0-1.0
– Firefox 17.0.11
– Totem Media Player 2.30.2
– Voip Client Ekiga 3.2.7
– Thinlinc Client 3.2.0
– NX Client 3.5.0-7
– Cisco VPN Client 4.8.02.0030-k9
– NCP Secure Client (Enterprise) 323_038.i686
– ThinPrint Client 7.0.59
– Xorg X11 Server 1.11.4
– Xorg Xephyr 1.7.6
– PC/SC Lite 1.8.9
– MUSCLE CCID Driver 1.4.13
– Omnikey CCID Driver 3.6.0
– Omnikey RFID Driver 2.7.2
– REINER SCT cyberJack Driver 3.99.5final.SP03
– SCM Microsystems CCID Driver 5.0.27
– Safenet / Aladdin eToken Driver 8.1.0-4
– ACS CCID Driver 1.0.5
– A.E.T SafeSign PKCS#11 Library 3.0.3665
– Gemalto .NET PKCS#11 Library 2.1.0
– SecMaker NetID PKCS#11 Library 6.0.1.44
– Philips Speech Driver 12.0.8
– Legacy Philips Speech Driver 5.0.10
– Client 0.8.3 for RedHat Enterprise Virtualization Desktops 3
– INTEL Graphics Driver 2.17.0
– ATI Graphics Driver 6.14.99_git20111219
– VIA Graphics Driver 5.75.32.87a-59172
– VIA Legacy Graphics Driver 4.1.83
– SAP GUI java710rev6
– 2X Client 10.1-1263
– Imprivata OneSign ProveID Embedded
================
Known issues:
================
[Quest vWorkspace]
– Multimedia Redirection:
Sound redirection is not working with WMV/WMA streams
– USB Redirection does not work reliable
================
IGEL Universal Desktop LX 4.13.180 (stable build based on 4.13.170)
================
Fixed bugs:

[base system]
Fixed tray-manager regarding missing tray icons in some cases.
================
IGEL Universal Desktop LX 4.13.170 (stable build based on 4.13.140)
================
New features:
================

[VMware Horizon View]
– For passthrough authentication added possibility to use the shortened domain
name instead of the fully-qualified domain name, like
“EXAMPLE” instead of “EXAMPLE.COM”.

To enable shortened domain name for a particular session,
go in the IGEL Registry and set the key
sessions.vdm_client%.options.passthrough_shortdomain
to true.

================
Fixed bugs:

[base system]
Security patches: CVE-2014-0160,CVE-2014-0092,CVE-2013-4242

================
IGEL Universal Desktop LX 4.13.140 (stable build based on 4.13.110)
================
New features:
================

[VMware Horizon View]
– Updated VMware Horizon View to version 2.3.0-1551379
– Added Realtime Audio Video (RTAV) support. Can be activated in setup at
“Sessions->Horizon View Client Global->Real Time Audio Video”
– Added switch for “Ctrl+Alt+Insert” redirection to VM. Depending on server
configuration either “Ctrl+Alt+Insert”, “Ctrl+Alt+Delete” or no action
can be triggered. The registry key is located at
“vmware.view.sendctrlaltinstovm” (default is false)

[Java Runtime Environment]
– Updated Java Runtime Environment to 1.7.0 U51.
– Added exception sites list to allow Java applications to be run after
the appropriate security prompts (according to Oracle’s JRE security
policy).
Exception sites (=URL) can be added at IGEL’s registry parameter
“java.deployment.exception_site%”. There you have to add a new instance for
each site.
Example: Use a self-signed Java webstart application.
– Added possibility to set the JRE security level by changing the registry
key “java.deployment.security_level”.
================
Fixed bugs:
================
[Smartcard]
– Fixed SCM Microsystems/Identive smart card readers: handle older readers
with driver version 5.0.21 and only new ones with 5.0.27.

[VMware Horizon View]
– Fix smart card redirection in Horizon View with RDP protocol

[ICA]
– Fixed Citrix XenApp/Programm Neighborhood refresh command
– Fixed matching of application names in ICA autostart list
– User name is shown again in screen lock unlock dialog, when
Citrix XenApp password is synchronized with screen lock password

[Wifi]
– Fixed support for PCI Wifi adapter based on Ralink RT3091.
================
IGEL Universal Desktop LX 4.13.110 (stable build) based on 4.13.100
================
Fixed bugs:
================
[ICA]
– Fixed missing desktop/menu icons with Citrix XenApp/Program Neighborhood.

[X11 system]
– UMD: Restored possiblity to update / downgrade if a satellite is not compatible with IGEL Linux v5

Info (Updated): USB 3.0 Memory – Same device with different results or what vendors doesn’t tell you.

Monday, April 28th, 2014

Hi Folks,

did you already got an USB 3.0 Memory or maybe two or more of them for you company? Your Users complain different write/read performance results? Why?
Reason is quite simple, it seams to be a big fun for some vendors to sale “different” devices providing different results with the same device name/part number. My negative sample for today is the Memory Vendor PNY and the Product USB-Stick 128 GB PNY Wave Attache™ USB 3.0 – Part Number FD128GBWAVE30-EF.

I got two of these devices for tests with the IGEL UD5 USB 3.0 Ports and the user was complaining different results with similar USB memory devices, so of course the different result must came from the Thin Client… 🙁 …but this is not the case. 🙂

I was able to reproduce these different results with PC’s, Tablet computer or any other device coming with a USB 3.0 port and the issue was not the thin client; it is the memory device.

The difference was “huge”, the first USB Memory provides a write speed of 60-80 mb/s which is good for a USB Memory but the second one provides only 25mb/s as max. write speed? What? It’s not much faster than a USB 2.0 device…

128 GB PNY Wave Attache, same but different

128 GB PNY Wave Attache, same but different

So i went to a electronic store close by that offers these USB Memory devices and both versions are offered here at the same time, funny but you can see the difference for this product quite simple if you know where to look (expand the upper picture).

Iam sorry to say: For me it’s a little bit “cheating” to work in this way… Provide the fast version for tests and sale “mixed” versions of the same product at the same time and i don’t believe that the production costs are equal. The slow PNY memory seams to be a “better refurbished” USB 2.0 memory and the results are not even close to the results mentioned in public available tests which can be found at Google or what PNY mentions on the package as max. speed.

So i only can recommend to test this in advance! If you buy a bigger amount force the reseller to provide you a “specification” guarantee and as end customer try to replace the device if possible, last one could be hard because the speed for the device is mentioned only “very” flexible by PNY and of course it’s a “low budget” device but a extreme result difference like this should also not happen for a “low budget” device with a brand on it from my point of view.

By this way, PNY is not the only vendor working in this way but regarding the fact that this device is “sold” and “announced” in a massive way at the moment you should have an eye on this.

I also wait for a statement from PNY and how this can be fixed, i will update this article if i got a statement from PNY and the marketing slogan “Make Life Simple” from PNY sounds like a bad joke for me at the moment but maybe there are people who like to play a device “lottery”.

 Update:

I found a 3rd Version and after this test results the best indicator to detect the fast Version is the engraved CE symbol, see picture below. The Version without the CE Mark provides a 3x faster write speed than the one with the engraved CE Mark during my tests. I’ve tested now 7 of these sticks (4 with engraved CE Mark and 3 without the engraved CE Mark), thanks also for the feedback provided by other users confirming these results! Also the slow one has a red LED, the fast one during my test always comes with an orange LED which shows Disk activity.

PNYUSB3SF

 

Cheers

Michael

P.S.: I will keep my two same but different PNY memory devices to have it as negative sample how “Same but not similar device” can look like.

P.S.2: I do not know how much versions are sold by PNY and this is only my personal result, so iam not responsible if there are also other versions with other visible indicators available. Test! Test! Test!

P.S.3: I got already similar results with display vendors (very common) and other devices like smart card readers but in these cases there was always a different revision number available (printed on the packaging and/or device) which clearly mentioned a difference.. This is not the case for the PNY memory device and i really try to find one.

Tip: Fixing Microsoft Remote Desktop Services issue with IGEL Linux 5.02.100 and Windows Server 2008 R2 SP1

Friday, April 11th, 2014

Hello Folks,

if you have discovered issues with the Microsoft Remote Desktop Services (RDS) client coming with the latest IGEL Linux V5.02.100 Firmware you should try the following setting:

If using the IGEL Universal Management Suite (UMS) make sure the profile is optimzed for a Firmware 5.x.x.

In the setup browse to Sessions-RDP-RDP Global-Options and enable the RDP Legacy Mode, if you are using an older UMS Version and the setting is not shown in the GUI browse to System-Registry-RDP and enable RDP Legacy Mode here.

Assign the profile and restart the RDS Session, issues shown on the server (like not working RDS Services) should be gone now.

Cheers

Michael

Info: Is the IGEL UMS affected by the OpenSSL Heartbleed (CVE-2014-0160) issue?

Thursday, April 10th, 2014

Hello Folks,

i just made some tests but it doesn’t look like the IGEL Universal Management Suite is affected by the Heartbleed issue.

You can test against our public UMS Server if you like but here is the result:

UMS Console Port Default 8443 on our Server 443

UMS Console Port Default 8443 on our Server 443

 

I’ve tested the console port 8443 and the client connection port 30001, in both cases the results are ok and did not show up any Heartbleed related issue.

 

Cheers

Michael

P.S.: Please note that I run only a test for the last Version 4.06.100 of the IGEL Universal Management Suite and that my test is not an official statement from IGEL Technology!

Tip: Disable the Last Logon User shown in the Windows ES W7 Logon screen

Tuesday, April 8th, 2014

Hello Folks,

sometimes you don’t need the Auto Logon feature coming with the Windows based IGEL Thin Clients, for example if the device is joined in a domain and you don’t want to see the local Administrator and User account in the Windows Logon Page to make the handling simple for the user.

You can download a new Partial Update for Windows based IGEL Thin Clients here: Download

This Partial Update will disable the Last User Logon Informations in the Windows Logon Screen, the result will look like the screenshot below.

withdisabledlastusername

You can also use this as sample how to deal with a Partial Update for a Windows based IGEL Thin Client. The archive contains the package, a manual as PDF, the required UMS Profile and the project file to edit the Partial Update together with our DATI tool.

Cheers

Michael