ThinOS 9 Upgrade Issue – Certificates

Viewing 15 posts - 1 through 15 (of 19 total)
  • Author
    Posts
  • #53152
    10er
    Participant
    • Total Post: 7
    • Newbie

    Hi,

    We are facing the following issue after upgrading our Wyse 3040s from ThinOS8.6 to ThinOS 9:

    After successfully upgrading to the latest firmware, the client fails to contact our Citrix broker, showing the following error message: “self signed certificate in certificate chain.”

    All required certificates have been applied using the WMS. We managed to fix that error by simply removing the available certificate from the local client. The login works like a charm right after a reboot.

    Is this a known issue? Anything we need to adjust in our WMS? For sure, we don’t want to manually adjust each client as we use an entire fleet.

    The upgrade has been conducted by updating from version 8.5 to 8.6. The final upgrade to 9.0 was applied afterwards.

     

     

    Here’s the client log with the errors mentioned above:

    2020-09-25T07:20:55.955Z:[INFO] [Citrix storefront]: request error => Error: self signed certificate in certificate chain
    2020-09-25T07:20:55.957Z:[INFO] [Citrix storefront]: roaming() error => Error: self signed certificate in certificate chain
    2020-09-25T07:20:55.957Z:[INFO] [Citrix storefront]: login failed error => Error: self signed certificate in certificate chain
    2020-09-25T07:20:55.963Z:[INFO] [vdimgr] tryLogin [https://Citrix Broker URL] err => Error: self signed certificate in certificate chain
    2020-09-25T07:20:55.964Z:[ERROR] [vdimgr] tryTask error => Error: self signed certificate in certificate chain
    2020-09-25T07:20:55.965Z:[ERROR] [vdimgr] tryTask error => Error: self signed certificate in certificate chain

    #53179
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    This looks like a certificate issue.
    What 9.0 version are you using?

    CG

    #53203
    CTSilencer
    Participant
    • Total Post: 1
    • Newbie

    I’m seeing/having the same issue “Error: self signed certificate in certificate chain”.

    ThinOS version 9.0.3030 with Citrix 2006_1130 pkg.  Same terminal works from External.  When brought into the Internal LAN, that’s when the error occurs. Makes no sense as it’s hitting the same Netscaler Gateway VIP from inside and outside.  What is thinOS/workspace checking during prior to connecting?

    #53286
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    we got the same issue.

    thinos 8.6 works fine with our root certificate, upgrade to the latest thinos 9.x produces the certificate error, removing local stored certificate, reboot, obtain the same certificate by wms and it works again.

    that is a bad issue if you want to upgrade all devices, because actually we have to do this workaround on any device

    #53782
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    any new thoughts on this?

    #53787
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    Are the time and date correct on the ThinOS 9 device?

    CG

    #53811
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    Yes time and date are correct. if we delete the root cert and install it again it works. same certificate

    #53869
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    What ThinOS 9.0 version are you using? What is your upgrade path?

    CG

    #53900
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    First we upgrade from 8.6_206 to Version 9.0_011.36 and after that to the version V9.0.3030
    the issue occurs also on 9.0_011.36, uninstall and install again the certificate works, but is not the way we want to do this ^^

    #53915
    ConfGen
    Keymaster
    • Total Post: 10696
    • Jedi Master
    • ★★★★★★★

    Have you checked with Dell support already?

    Have you added the certificate to the 9.x policy also?

    CG

    #54006
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    we will open a case for that issue.

    yes we added the certificate also to the 9.x policy

    #54010
    LRW
    Participant
    • Total Post: 4
    • Newbie

    I have had the same issue, working fine with WTOS 8.6 and not with 9.
    Turned out that I was missing a root cert from our PKI in the chain.

    #54012
    edv-hotline
    Participant
    • Total Post: 8
    • Newbie

    okay, but what i do not understand is, that if we manually uninstall the policy-based installed certificate and install the same certificate again by policy it works ^^

    #54016
    suisse
    Participant
    • Total Post: 100
    • Legend in Own LunchBox
    • ★★★★★

    @confgen:

    I’m receiving mail notification for that thread but haven’t subscribed to it nor participated.

    can you remove me please?

    #54024
    anthony.yates
    Participant
    • Total Post: 4
    • Newbie

    @confgen

    Yep I’m getting notifications for all replies. Also when I login I seem to have Site Admin access. Might want to fix that pretty quickly!

     

Viewing 15 posts - 1 through 15 (of 19 total)
  • You must be logged in to reply to this topic.