{"id":33381,"date":"2024-02-29T15:20:03","date_gmt":"2024-02-29T14:20:03","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=33381"},"modified":"2024-10-01T15:23:41","modified_gmt":"2024-10-01T13:23:41","slug":"leap-year-problem-29-february-citrix-and-sophos-on-board","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2024\/02\/29\/leap-year-problem-29-february-citrix-and-sophos-on-board\/","title":{"rendered":"Leap year problem 29 February: Citrix and Sophos on board"},"content":{"rendered":"<p><img decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" title=\"Stop - Pixabay\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/06\/Stop01.jpg\" alt=\"Stop - Pixabay\" align=\"left\" \/>[<a href=\"https:\/\/www.borncity.com\/blog\/2024\/02\/29\/schaltjahrproblem-29-februar-citrix-und-sophos-im-boot\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]It's a leap year, which happens roughly every four years. And there is something even more memorable: Sophos is struggling with the leap year 2024 because there are problems with SSL\/TLS decryption in the SOPHOS Central Endpoint Agent. And at Citrix, the CtxHdxWebSocketService somehow no longer works on 29 February 2024 &#8211; this was already the case four years ago. And with SOPHOS Central there are problems with TLS decryption today.<\/p>\n<p><!--more--><\/p>\n<h2>Citrix CtxHdxWebSocketService fails<\/h2>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg06.met.vgwort.de\/na\/5c251d33203a45e28daf753dbeed69ec\" alt=\"\" width=\"1\" height=\"1\" \/>German blog reader Christian R. contacted me by email this morning and raised a Citrix issue (thanks for that). According to him, Citrix has a special function that transfers the communication of teams in a Citrix session to the local client. The whole thing runs via the Citrix CtxHdxWebSocketService, so far so normal, but today, 29 February 2024, this service is on strike. On reddit.com there is the entry <a href=\"https:\/\/www.reddit.com\/r\/Citrix\/comments\/1b2u72p\/ctxhdxwebsocketservice_service_not_starting_leap\/\" target=\"_blank\" rel=\"noopener\">CtxHdxWebSocketService service not starting &#8211; Leap year problem<\/a> with the description of the error:<\/p>\n<blockquote><p>It happens again.. \"Citrix HDX HTML5 Video Redirection Service\" crashes on Service start.<\/p>\n<p>Eventlog says:<\/p>\n<p>Name der fehlerhaften Anwendung: WebSocketService.exe, Version: 15.45.0.12, Zeitstempel: 0x64c00c5e<\/p>\n<p>Name des fehlerhaften Moduls: <em>ucrtbase.dll<\/em>, Version: 10.0.17763.1490, Zeitstempel: 0x51d4b57a<\/p>\n<p>Ausnahmecode: 0xc0000409<\/p>\n<p>Fehleroffset: 0x000a5b3b<\/p>\n<p>ID des fehlerhaften Prozesses: 0x7974<\/p>\n<p>Startzeit der fehlerhaften Anwendung: 0x01da6ada2ab52ac7<\/p>\n<p>Pfad der fehlerhaften Anwendung: C:\\Program Files (x86)\\Citrix\\HDX\\bin\\WebSocketService.exe<\/p>\n<p>Pfad des fehlerhaften Moduls: C:\\Windows\\System32\\ucrtbase.dll<\/p>\n<p>Berichtskennung: 37ad8d28-17d2-45a0-9e4f-ecc3925ba10a<\/p>\n<p>Vollst\u00e4ndiger Name des fehlerhaften Pakets:<\/p>\n<p>Anwendungs-ID, die relativ zum fehlerhaften Paket ist:<\/p><\/blockquote>\n<p>Christian pointed out that this had already surprised some administrators four years ago, as you can read on reddit.com at <a href=\"https:\/\/www.reddit.com\/r\/Citrix\/comments\/fb9j4e\/ctxhdxwebsocketservice_service_not_starting_after\/\" target=\"_blank\" rel=\"noopener\">CtxHdxWebSocketService service not starting after service stop<\/a>. There is also a <a href=\"https:\/\/discussions.citrix.com\/topic\/407299-citrix-hdx-html5-video-redirection-service-stopped-on-all-vdas-today\/\" target=\"_blank\" rel=\"noopener\">Citrix HDX HTML5 Video Redirection Service &#8211; stopped on all VDA's today<\/a> post in the Citrix community, which discusses the issue in February 2020. At that time it was related to a certificate problem. If you set the date to 1 March, it worked.<\/p>\n<p><span style=\"color: #000000;\">Also <\/span>Thomas G. mailed me \"I would like to report a problem with Citrix Virtual Apps and Desktops\". His explanation: \"The \"Citrix HDX HTML5 Video Redirection Service\" crashes when you try to start the service. Apparently this is related to a certificate that is issued daily (and is only valid for one day). This is apparently missing today.\" He referred to the reddit.com thread <a href=\"https:\/\/www.reddit.com\/r\/Citrix\/comments\/fb9j4e\/ctxhdxwebsocketservice_service_not_starting_after\/\" target=\"_blank\" rel=\"noopener\">CtxHdxWebSocketService service not starting after service stop<\/a>, where the problem is also addressed.<\/p>\n<p>Thomas cannot name the exact effects, but he assumes that Teams HDX will not allow video transmission. It is also unclear which versions of \"Citrix Virtual Apps and Desktops\" are affected. He is using \"Citrix Virtual Apps and Desktops 7 2308\".<\/p>\n<h2>Problems with TLS decryption at SOPHOS Central<\/h2>\n<p>German blog Leser Markus H. Reader Markus H. informed me by email and in a private message on Facebook (thanks for that) about a problem with SOPHOS. In his message he wrote:<\/p>\n<blockquote><p>Maybe interesting for the blog, if others also have SOPHOS Central in use and have problems with active TLS decryption today. It seems that the leap year doesn't taste good.<\/p><\/blockquote>\n<p>On Sophos endpoints that were restarted on 29 February 2024, browsers may display a warning as shown in the screenshot below:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2024\/02\/image-34.png\" alt=\"Sophos Error\" \/><\/p>\n<p>Markus then pointed me to the Sophos Endpoint advisory <a href=\"https:\/\/web.archive.org\/web\/20240423122117\/https:\/\/support.sophos.com\/support\/s\/article\/KB-000045954?language=en_US\" target=\"_blank\" rel=\"noopener\">Sophos Endpoint \"Your connection isn't private\" after reboot<\/a> from the manufacturer, which addresses the problem. Affected are:<\/p>\n<ul>\n<li>Sophos Central Windows Endpoint<\/li>\n<li>Sophos Home<\/li>\n<li>Sophos Central Windows Servers<\/li>\n<\/ul>\n<p>if SSL\/TLS decryption of HTTPS websites is enabled in the threat protection policy and if the endpoint is restarted and the system date is 29 February 2024. The solution is to disable SSL\/TLS decryption as of today, 29 February, and enable it again on 1 March. However, they are probably in the process of distributing a Sophos Endpoint SSL\/TLS decryption policy override since 8:00 am.<\/p>\n<p>PS: In New Zealand, a software error forced numerous self-service petrol pumps on 29 February 2024 for hours \"out of order\", but they are back now, as I read <a href=\"https:\/\/www.nzherald.co.nz\/hawkes-bay-today\/news\/february-29-allied-fuel-pumps-around-nz-ground-to-a-halt-as-systems-forget-leap-year\/XEQBK5JLBZG6LO3VGUQ6Q2WGC4\/\" target=\"_blank\" rel=\"noopener\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]It's a leap year, which happens roughly every four years. And there is something even more memorable: Sophos is struggling with the leap year 2024 because there are problems with SSL\/TLS decryption in the SOPHOS Central Endpoint Agent. And at &hellip; <a href=\"https:\/\/borncity.com\/win\/2024\/02\/29\/leap-year-problem-29-february-citrix-and-sophos-on-board\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[463,1547],"tags":[47,1544],"class_list":["post-33381","post","type-post","status-publish","format-standard","hentry","category-issue","category-software","tag-issue","tag-software"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=33381"}],"version-history":[{"count":2,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33381\/revisions"}],"predecessor-version":[{"id":35179,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/33381\/revisions\/35179"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=33381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=33381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=33381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}