Secure ticket authority Citrix Xenapp 6.5 and web interface

Hi,
We have a Citrix secure gateway in comination with web interface 5.3 and it works fine. We host two sites. One is connected to a Xenapp 5.x environment with a secure ticket authority on a Xenapp 5.x server. The other site is connected to a Xenapp 6.5 server and that is working fine in combination with a xenapp 5.x secure ticket authority but when i connect to a Xenapp 6.5 secure ticket authority it is not working. In the eventvwr i see messages like "SSL handshake from client failed."and "Client IP sent bad ticket, connection dropped." and "Incoming Citrix Gateway Protocol downstream data could not be processed." What is wrong?
LVL 3
pkfwallastAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Daniel BorgerSenior Citrix Engineer- CCEECommented:
any citrix server can be a STA, try changing to a different server in the XenApp6.5 farm. Windows firewall enabled on the STA?

Also, consider moving to storefront as web interface is going away.
joharderCommented:
Double check your WI config for the XA6.5 farm and confirm that the appropriate server(s) are listed as the STA(s).  It sounds like there might just be an error here.
pkfwallastAuthor Commented:
It is still not working. How can i check if a server is a STA and how can i check that it is working?
Your Guide to Achieving IT Business Success

The IT Service Excellence Tool Kit has best practices to keep your clients happy and business booming. Inside, you’ll find everything you need to increase client satisfaction and retention, become more competitive, and increase your overall success.

Dirk KotteSECommented:
all STA's used within a WebInterface Configuration should be listed within the CSG-Config.
The CSG configuration has to know every STA used within someone WI-Config. (the summary of all STA's)
you can check the STA with the CSG-check-tool (available from the CSG console) .

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
pkfwallastAuthor Commented:
I have just used the medevac tool form Citrix and when i perform a xml ticketing test a see the message "Failure unspecified" so the sta is not working but why.
Dirk KotteSECommented:
runs XML/STA IIS integrated or standalone (changed XML-Port "ctxxmlss.exe")?
with IIS integration you have a log file configured within c:\inetpub\Scripts\CtxSta.config
pkfwallastAuthor Commented:
Strange, i don't see the scripts directory in c:\inetpub.
Might this be the issue:
http://blog.samkendall.net/2012/01/06/fixed-citrix-xml-service-issue-after-fresh-xenapp-6-5-install/
Dirk KotteSECommented:
possible ...
do you check "integrate XML with IIS" while installing XenApp?
pkfwallastAuthor Commented:
In the Citrix Web Interface Management Console, in the Secure Access Settings the Secure Ticket Authority URL was not the same as in the Secure GateWay Configuration.

When we added the same Server(URL) we could login with the new Servers' STA ID.
pkfwallastAuthor Commented:
I've requested that this question be closed as follows:

Accepted answer: 0 points for pkfwallast's comment #a40044568

for the following reason:

no one pointed me that those two had to be the same Servers/URL's
Dirk KotteSECommented:
see my Post ...  by: dkottePosted on 2014-02-05 at 14:14:25  ID: 39835402

"all STA's used within a WebInterface Configuration should be listed within the CSG-Config."
Dirk KotteSECommented:
see my Post ...  by: dkottePosted on 2014-02-05 at 14:14:25  ID: 39835402

"all STA's used within a WebInterface Configuration should be listed within the CSG-Config."
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Citrix

From novice to tech pro — start learning today.