Brian Madden Logo
Your independent source for application and desktop virtualization.
Marketplace

advertisement
Brian Madden's Blog

Oops! SP2 for Windows XP Breaks Citrix NFuse / Web Interface Clients

Written on Feb 12 2004 10,583 views, 45 comments


by Brian Madden

As you probably know by now, one of the key enhancements of Service Pack 2 for Windows XP is the added security. Unfortunately, this added security causes a default installation of Internet Explorer to classify web files with the "ICA" extension as unsafe. This means that when using Service Pack 2, users are not able click on a linked ICA file from a Citrix NFuse or MetaFrame Web Interface web site.

Prior to Service Pack 2, Windows XP users could browse to Citrix NFuse / Web Interface servers and click on links to launch remote MetaFrame applications. Clicking a link causes the web server to pass an ICA file down to the Windows XP client device where the locally installed ICA Client software receives it and seamlessly launches the application.

Once Service Pack 2 is installed, clicking an ICA file link pops up a dialog box warning that some files may harm your computer. The user is asked whether they want to Open, Save, or Cancel. Worse still is that choosing the "Open" option doesn't seem to work. The only workaround involves saving the file to your computer and then running it manually from there.

The security warning box is presented to the user regardless of the configured security zone of the server.

In all fairness, this security complexity is not limited to Citrix ICA files. (The web is filling with stories of people who can no longer run VBS files with SP2.) Also, workarounds are possible. However, it could provide quite a bit of cleanup work for Citrix administrators, especially when users connect from outside workstations that will automatically receive SP2 via Windows Update.

We don't yet know if this behavior is by design or simply an oversight of the classification of ICA files. (Certainly Microsoft shouldn't consider ICA files as dangerous as VBS files?)



Comments

Guest wrote Microsoft is aware of this
on 12-12-2004 1:17 PM
This message was originally posted by Brian Madden on March 5, 2004
As a follow up, I received a phone call yesterday from a Microsoft employee who said that this issue is known within Microsoft, and that it's officially made it into the bug tracking database for SP2.
Guest wrote No Title
on 12-12-2004 1:21 PM
This message was originally posted by Andrew on March 24, 2004
But as of RC1, have made no (good) alterations - the security warning box doesnt appear now!
Guest wrote Windows XP SP2 - Do your Homework
on 12-12-2004 1:21 PM
This message was originally posted by an anonymous visitor on April 13, 2004
Windows XP SP2 Technical Preview
Download the Network Install
Published: March 19, 2004
Windows XP Service Pack 2 (SP2) provides an enhanced security infrastructure that defends against viruses, worms and hackers, along with increased manageability and control for IT professionals and an improved experience for users.


To aid IT professionals in planning and testing for the deployment of Windows XP SP2, Microsoft is making available this preview, based on Release Candidate 1 of the SP2. Additionally, we have established 11 newsgroups for sharing information.

WARNING! This technical preview is unsupported and is intended for testing purposes only. Do not use in production environments.

There is no phone or incident support available for this download, but any questions may be posted in the newsgroups available at http://communities.microsoft.com/newsgroups/default.asp?icp=xpsp2&slcid=us

Guest wrote CITRIX
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 16, 2004
So is there any way to "work around" this issue with Citrix? I liked SP2 but cannot live without Citrix so I un-installed it. I would love to find a way to have both.
Guest wrote Work around
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 19, 2004
Save to desktop and open there?
Guest wrote CITRIX (Work Arouond)
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 20, 2004
Thanks. I thought of that but the file is deemed unsafe whether launched from Citrix or from a saved location.
Guest wrote CITRIX & XP SP 2
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 21, 2004
Install Mozilla firefox, login to NFUSE, and work normally :)
Guest wrote CITRIX
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 22, 2004
Y0U ARE THE MAN! It W0RKED I SEND MY ThaNKS IN A BiG WAY!

N0W if I Can 0NLY figure out this pen!
Guest wrote Citrix (followup)
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on April 25, 2004
It seems that any browser but IE will handle Citrix. So just use Netscape or any other browser but IE.
Guest wrote It looks like the ICA clients version 8 fix this problem
on 12-12-2004 1:22 PM
This message was originally posted by Brian Madden on April 27, 2004
These are the new clients that come with MetaFrame Presentation Server 3, and they're freely downloadable now.
Guest wrote The Metaframe Presentation Server doesn't solve it!
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on May 7, 2004
The Solution to save the ICA file to your desktop doesn't work, either, if that functionality has been disabled on the desktop or if you cannot right click and save on a workstation.

The workaround is to wait until it's fixed.

Guest wrote an answer from Citrix ...
on 12-12-2004 1:22 PM
This message was originally posted by m@ in london on May 7, 2004
look at the following Microsoft document:
http://download.microsoft.com/download/8/7/9/879a7b46-5ddb-4a82-b64d-64e791b3c9ae/WinXPSP2_Documentation.doc
check from page 103, it gives some details about the new Windows XP SP2 feature: Internet Explorer MIME Handling Enforcement

you can turn it off by setting the following registry value to 0 ( off)
HKEY_LOCAL_MACHINE(or Current User)\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING
Guest wrote Citrix ICA session from a Windows XP.SP2(RC1) client system
on 12-12-2004 1:22 PM
This message was originally posted by Patrick Laroche on May 14, 2004
Out of my own
STEP_1: Set registry value for iexplorer.exe to '0' (off) in 'HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_MIME_HANDLING'
STEP_2: Go to Control Panel' > 'Internet Options' > 'Security' > 'Trusted Sites' and add the fully qualified internet name of your NFuse gateway, for example 'https://citrix.mydomain.com'.
STEP_3: Re-install the Citrix ICA web client.
This patch works both with MSIE and Mozilla.
Guest wrote You can also use the java client and it works
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on May 25, 2004
You can also change your portal settings from native client to java and it works just fine.
Guest wrote If there is a box "Can't find ica file"
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on May 25, 2004
If you get the error box "can't fand ica file" try to uncheck the box "don't save encrypted pages to disk" under "extras" from ie.
Guest wrote Web ICA Client Works
on 12-12-2004 1:22 PM
This message was originally posted by an anonymous visitor on June 9, 2004
I have tried the new version of 8.0 and it works great. No problems, no tweaking, easy install. Server side I am running Metaframe XPe Feature Release 3, Nfuse 2.0. All my users are starting to use the new client.
Guest wrote Confirm Web ICA client version 8.0 works.
on 12-12-2004 1:29 PM
This message was originally posted by an anonymous visitor on June 23, 2004
I have been experiencing this problem since installing SP2 RC1. On reading this page I have just downloaded version 8.0 of the client. My connection to an outside site has worked first time.
Guest wrote Remove Citrix and go to Tarantella's TSE
on 12-12-2004 1:31 PM
This message was originally posted by an anonymous visitor on August 13, 2004
Windows product that like TSE that enhances Windows WTS build and does not try to replace it like Citrix is a much better fit. This will stop the issues of compatibility when additional patches comes out...
Guest wrote Remove Citrix?
on 12-12-2004 1:49 PM
This message was originally posted by Coupland on September 8, 2004
Well, I think Citrix is a little overpriced but to say Citrix tries to replace WTS is pure silliness. WTS IS Citrix technology purchased by Microsoft. If anything Microsoft hoped to replace Citrix and later decided against it based on the sheer revenue generated by the software vender. Want to run Citrix? Well you'll need Windows server and Terminal server licenses. lol
Guest wrote Registry changes help
on 12-12-2004 1:50 PM
This message was originally posted by Lax on September 17, 2004
With registry changes and installation of new web client it works fine with MS IE.
Guest wrote Help!
on 12-12-2004 1:50 PM
This message was originally posted by an anonymous visitor on October 6, 2004
I installed both Mozilla foxfire & citrix 8.0
but my citrix is still not working
Guest wrote registry changes worked
on 12-12-2004 1:52 PM
This message was originally posted by manu on October 14, 2004
step 1 recommended by patrick worked - thanks!! of course i did not understand what i did so i have no clue what impact it will have on my machine