Bug ID 610125: Launching applications using Citrix HTML5 receceiver does not work in SSL offload mode

Last Modified: Mar 21, 2019

Bug Tracker

Affected Product:  See more info
BIG-IP APM(all modules)

Known Affected Versions:
11.6.0, 11.6.0 HF1, 11.6.0 HF2, 11.6.0 HF3, 11.6.0 HF4, 11.6.0 HF5, 11.6.0 HF6, 11.6.0 HF7, 11.6.0 HF8, 11.6.1, 11.6.1 HF1, 11.6.1 HF2, 11.6.2, 11.6.2 HF1, 11.6.3, 11.6.3.1, 11.6.3.2, 11.6.3.3, 11.6.3.4, 11.6.4, 12.0.0, 12.0.0 HF1, 12.0.0 HF2, 12.0.0 HF3, 12.0.0 HF4, 12.1.0, 12.1.0 HF1, 12.1.0 HF2, 12.1.1, 12.1.1 HF1, 12.1.1 HF2, 12.1.2, 12.1.2 HF1, 12.1.2 HF2, 12.1.3, 12.1.3.1, 12.1.3.2, 12.1.3.3, 12.1.3.4, 12.1.3.5, 12.1.3.6, 12.1.3.7, 12.1.4, 13.1.0, 13.1.0.1, 13.1.0.2, 13.1.0.3, 13.1.0.4, 13.1.0.5, 13.1.0.6, 13.1.0.7, 13.1.0.8, 13.1.1, 13.1.1.1, 13.1.1.2, 13.1.1.3, 13.1.1.4

Opened: Aug 10, 2016
Severity: 3-Major
Related AskF5 Article:
K91727822

Symptoms

While launching the applications or desktops from Storefront UI using Citrix HTML5 receiver produces the following error "Citrix Receiver cannot reach the server".

Impact

Receiver for HTML5 cannot be used.

Conditions

APM is configured in Storefront integration mode with SSL offload (Only client side SSL is enabled). Enabled SSL/TLS for each VDA in Citrix environment.

Workaround

Use server side SSL as well on the virtual server to connect with SSL/TLS-enabled VDA. Otherwise, disable SSL/TLS on the VDA. Because the system does not use server side SSL on the virtual server, and VDA is enabled for SSL/TLS ICA connections, proxying plain ICA connections from APM to VDA is not supported.

Fix Information

None

Behavior Change