Hi Lukas,
sorry for the late response.
The problem according the minimal step-by-step instructions is, that the Citrix 
Linux VDA agent is not public available.
For the Ubuntu steps, please see the list below:

1. Create VM and deploy Ubuntu with cloud init and 24.04.2 iso image
2. Implement certificates (from own pki)
3. Join AD domain with adcli and configure with sssd and krb5
Dependencies:
  - 'acl'
  - 'krb5-user'
  - 'libpam-mklocaluser'
  - 'libpam-mount'
  - 'libpam-modules'
  - 'libpam-modules-bin'
  - 'libpam-python'
  - 'libpam-runtime'
  - 'libpam-ssh'
  - 'libpam-krb5'
  - 'libpam-systemd'
  - 'libpam-winbind'
  - 'libpam0g'
  - 'krb5-pkinit'
  - 'pamtester'
  - 'realmd'
  - 'samba'
  - 'sssd'
  - 'sssd-dbus'
  - 'sssd-tools'
  - 'unzip'
4. Install Ubuntu desktop packages
Packages:
  - ubuntu-desktop-minimal
  - vim
  - ubuntustudio-wallpapers-focal
  - okular
  - gnome-software
  - open-vm-tools
  - yaru-theme-gtk
5. Installation of Citrix VDA client 24.11.0.70-1.ubuntu24.04
Dependencies:
  - openjdk-11-jdk
  - postgresql
  - libpostgresql-jdbc-java
  - libxm4
  - libsasl2-2
  - libsasl2-modules-gssapi-mit
  - libldap2
  - krb5-user
  - libgtk2.0-0
  - apt-transport-https
  - dotnet-sdk-8.0
  - gnome-session

After that process the login via the Citrix federated-authentication-
service works on Ubuntu 22.04 but on Ubuntu 24.04 the error listed above
occurs.

Because of the functional setup with the same Citrix VDA version on Ubuntu 
22.04 my supposition is, that the problem lies in the Ubuntu 24.04 packages.
Hope these information help you understanding the problem.

Thank you!

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2098484

Title:
  Pkinit fails with invalid argument

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/krb5/+bug/2098484/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to