{"id":27034,"date":"2022-10-18T05:33:22","date_gmt":"2022-10-18T03:33:22","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=27034"},"modified":"2022-10-18T11:50:36","modified_gmt":"2022-10-18T09:50:36","slug":"citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/","title":{"rendered":"Citrix connections broken after Windows update KB5018410 (October 2022) (TLS problem)"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Windows\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Windows-klein.jpg\" alt=\"Windows\" width=\"200\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]Small addendum from last week. Since the October patchday (October 11, 2022), administrators of Citrix installations have noticed that connections no longer work for Citrix clients once Windows update KB5018410 has been installed. This update for Windows 10 version 20H2-21H2 is likely where the TLS 1.0\/1.1 issue struck. <strong>Addendum:<\/strong> It seems that an out-of-band update from Microsoft has fixed this issue.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/4fdeb725d94e4f0d99b230a7458fbd21\" alt=\"\" width=\"1\" height=\"1\" \/>I became aware of the issue the other day via the following <a href=\"https:\/\/twitter.com\/cstalhood\/status\/1580875551753240576\" target=\"_blank\" rel=\"noopener\">tweet<\/a> from Carl Stalhood. The message is simple: If you install the Windows update KB5018410, you should not be surprised about broken connections from Citrix clients.<\/p>\n<p><a href=\"https:\/\/twitter.com\/cstalhood\/status\/1580875551753240576\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Citrix connection fail with update KB5018410\" src=\"https:\/\/i.imgur.com\/AA1Srmi.png\" alt=\"Citrix connection fail with update KB5018410\" \/><\/a><\/p>\n<p>In the Citrix forum there is a discussion <a href=\"https:\/\/discussions.citrix.com\/topic\/417451-citrix-workspace-no-connect-after-microsoft-october-2022-update\/\" target=\"_blank\" rel=\"noopener\">CITRIX WORKSPACE NO CONNECT AFTER MICROSOFT OCTOBER 2022 UPDATE<\/a> about this. The thread starter writes:<\/p>\n<blockquote><p>Hi,<\/p>\n<p>After my Workstations was installed the Microsotf Security Update October 2022 KB5018410, the Citrix Workspace Client can\u00b4t connect with Netscaler server, the error for new connections is \"can't add account with provided url\". The clients that have Citrix open, can\u00b4t open any application. If uninstall it the Microsoft KB, Citrix work fine. We try with differents Citrix version and the problem persist. Any idea?<\/p>\n<p>The Windows OS version is Windows\u00a0 21H2<\/p><\/blockquote>\n<p>There, the Citrix clients can no longer connect to the server as soon as the update KB5018410 for Windows 10 version 20H2-21H2 has been installed. A user then confirms that it was probably due to the TLS problem outlined below.<\/p>\n<blockquote><p>@Martin Berthiaume, I found the solution for our environment in Citric ADC (aka Netcaler). The Load balancing virtual server object for our Storefront missed settings for TLSv11 and TLSv12 in SSL parameters. I also tested with the delfault Ciphers, but had to remove them again because then the Session from HP Linux thin clients stopped working. In my searching for answers I also fixed an outdated certificate in IIS on the StoreFront servers. But it wasnt until I checked the LSv11 and TLSv12 the receiver started to work again. It seems like KB5018410 unchecks these the older ones Internet Options just leaving TLSv12 .<\/p><\/blockquote>\n<p>In the forum thread, a user describes how he enabled TLS 1.2 in his environment to get the connections working again. Maybe free <a href=\"https:\/\/www.nartac.com\/Products\/IISCrypto\/?fbclid=IwAR3UkKeTVI-iMvn0RzlVPnbcco46XQAws8lUqj2hkMXfgsD9tA7trvg8vg4\" target=\"_blank\" rel=\"noopener\">Nartac tool<\/a><em>\u00a0<\/em>for testing TLS configuration is also quite helpful.<\/p>\n<h2>Update KB5018410 and the TLS problem<\/h2>\n<p>I had pointed out the problem of TLS 1.0\/1.1 being disabled by Microsoft for Windows 10 version 20H2-21H2 with the October 11, 2022 security update in the run-up to the October 2022 patchday in the post <a href=\"https:\/\/borncity.com\/win\/2022\/10\/11\/windows-10-achtung-vor-einem-mglichen-tls-desaster-zum-oktober-2022-patchday\/\">Windows 10: Beware of a possible TLS disaster on October 2022 patchday<\/a>. This was not voodoo, as Microsoft already documented exactly this in the September 2022 preview update (see <a href=\"https:\/\/borncity.com\/win\/2022\/09\/21\/windows-10-20h2-21h2-preview-update-kb5017380-20-9-2022\/\">Windows 10 20H2-21H2 Preview Update KB5017380 (Sept. 20, 2022)<\/a>). And on Patchday, October 11, 2022, the TLS 1.0\/1.1 shutdown was then distributed more broadly (see <a href=\"https:\/\/borncity.com\/win\/2022\/10\/12\/patchday-windows-10-updates-11-oktober-2022\/\">Patchday: Windows 10-Updates (October 11, 2022)<\/a>).<\/p>\n<blockquote><p>Also just got a message on Facebook that someone at a customer has experienced Outlook connection problems, probably due to the October update and TLS. The tips from my article <a href=\"https:\/\/borncity.com\/win\/2022\/10\/10\/bug-outlook-stellt-keine-verbindung-mehr-zum-e-mail-server-her-oktober-2022\/\">Bug: Outlook no longer connects to the mail server (October 2022)<\/a> may help there.<\/p><\/blockquote>\n<h2>Out-of-band for Windows as a fix<\/h2>\n<p><strong>Addendum:<\/strong> It has been mentioned within the comments below and within my German blog &#8211; Microsoft has confirmed a bug in Windows, that's causing SSL and TLS connection issues. I covered this update within the blog post <a href=\"https:\/\/borncity.com\/win\/2022\/10\/18\/sonderupdates-fr-windows-fixen-ssl-tls-verbindungsproblem-auch-bei-citrix-17-oktober-2022\/\" rel=\"bookmark noopener noreferrer\" data-wpel-link=\"internal\">Out-of-band updates for Windows fixes SSL-\/TLS connection issues (also with Citrix) \u2013 October 17, 2022<\/a> eine \u00dcbersicht der verf\u00fcgbaren Updates aufgelistet.<\/p>\n<p>Out-of-band #update for #Windows fixes SSL \/ TLS connection issues &#8211; also for Citrix clients<\/p>\n<p><strong>Similar articles:<\/strong><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2022\/09\/21\/windows-10-20h2-21h2-preview-update-kb5017380-20-9-2022\/\">Windows 10 20H2-21H2 Preview Update KB5017380 (Sept. 20, 2022)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2022\/10\/12\/patchday-windows-10-updates-11-oktober-2022\/\">Patchday: Windows 10-Updates (October 11, 2022)<\/a><br \/>\n<a href=\"https:\/\/borncity.com\/win\/2022\/10\/11\/windows-10-achtung-vor-einem-mglichen-tls-desaster-zum-oktober-2022-patchday\/\">Windows 10: Beware of a possible TLS disaster on October 2022 patchday<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]Small addendum from last week. Since the October patchday (October 11, 2022), administrators of Citrix installations have noticed that connections no longer work for Citrix clients once Windows update KB5018410 has been installed. This update for Windows 10 version 20H2-21H2 &hellip; <a href=\"https:\/\/borncity.com\/win\/2022\/10\/18\/citrix-verbindungen-nach-windows-update-kb5018410-oktober-2022-gestrt-tls-problem\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,1547,22,2],"tags":[466,76],"class_list":["post-27034","post","type-post","status-publish","format-standard","hentry","category-issue","category-software","category-update","category-windows","tag-problem","tag-windows-10"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/27034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=27034"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/27034\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=27034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=27034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=27034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}