Citrix Presentation server can not contact the license server

Reading Time: 3 minutes

If you come across the above error,  you may also come across one or more of the errors below within your Citrix server event logs.

This computer running Citrix Presentation Server will now stop accepting connections. This server is no longer in or could not enter a licensing grace period.


Or

Citrix Presentation Server has entered the grace period. You have x hour(s) remaining before this server stops accepting connections from client devices

Or

The licenses required by this edition of MetaFrame Presentation Server are not present on the license server

Or

Citrix XenApp cannot contact the license server localhost

Or

This computer running Citrix XenApp will now stop accepting connections. This server is no longer in or could not enter a licensing grace period

Or

Error received while obtaining a license for a Citrix Presentation Server client connection. A grace license has been granted.

Or

Citrix presentation server license acquisition err (-xx): Unable to acquire a license from server. Please contact your system administrator or open event viewer for more details.
The alerts are generated when your citrix servers lose connection with the citrix license server. The citrix servers will continue to run until the grace period expires, unless they are able to communicate with the license server again.

Once your citrix servers have successfully communicated with the license server, you should receive the below or something similar within your event log.

This server is successfully communicating with the license server. Citrix Presentation Server has left the grace period

There are a few basic tasks you can carry out:

1) Ensure the citrix licensing services are running. If you need to locate you citrix license server, see link in step 3. If the license server is running go to step 2.

2) Restart the IMA service on your Citrix servers

3) If the above does not resolve issue, restart the license services on your Citrix licensing server. If you don’t know which server holds the citrix licensing role, see https://cloudbuild.co.uk/?p=1713

4) If any of the above do not resolve your issue, check your citrix licenses have not expired. On your Citrix license server, access Start, Programs, Citrix and Citrix license console. If they have expired you need to renew. Otherwise go to step 5.

5) From your citrix server, open a command prompt window and telnet to your citrix license server on port 27000. Please note, the port may be different, follow the link in step three to find out what port you are using. If you are unable to telnet to the port, you need to open the port on your firewall. The citrix servers need to communicate with the license server. Example telnet servername 27000

6) Can you ping the license server from a citrix server and the citrix server from the license server.

7) An incorrect Presentation Server edition level may have been set. Click a citrix server name within your citrix farm, from the right hand pane click set presentation server edition. Ensure the correct version is selected. Do the same for all your Citrix servers.

8.) Within a command prompt type netstat -a    –  Is the connection from your citrix server to license server established? If not you could have netoworking issues between servers.

9) Restart, the license server

10) If issue still exists, restart Citrix servers.

 Just a list of basic tasks which usually get to the bottom of grace period alerts.

Explanation from Citrix:

The problem occurs when there are intermittent problems, or delays (over 10 seconds per message) affecting the communication of messages between the XenApp server and the License Server. Once a timeout of a message sent from the XenApp server to the License Server occurs, subsequent communication to the License Server does not occur correctly because the persistent connection from XenApp to the License Server becomes unstable. As a result of the instability of this connection, subsequent user connections to the XenApp server might fail with the previously noted errors.

Important note: This problem only occurs in cases where the License Server is online and partially accessible over the network from the affected XenApp server. If the License Server is completely offline, this problem does not occur because the XenApp server continues to accept user connections until the standard licensing grace period expires or the License Server becomes accessible, whichever comes first.

A common source of this problem is intermittent network connectivity because of a physical problem such as damaged or defective network hardware (patch cables, patch panels, or switch ports).

User could not be logged off. Access is denied

Reading Time: < 1 minute

When you attempt to log off a user session via terminal services manager or via task manager, you receive the below error:

Error:User ‘username’ (sessionId=) could not be logged off. Access is Denied.

The above error occurs when you do not have correct permissions. Ensure you have the correct permissions or are part of the correct security group.

Logoff and back on after correct permissions have been granted. You should be able to logoff sessions without the above error.

Controlling permissions to applications available via redirected desktop or start menu

Reading Time: 2 minutes

I have seen lots of environments where administrators have setup several start menu or desktop redirected folders for different departments with an organisation.

For example:
Sage Payroll should only be available for the Payroll department, so therefore a redirected start menu folder is setup for the payroll department. Another redirected start menu folder may be setup for the I.T department and so on. At the end you may have several redirected start menu and desktop folders which can look messy and become difficult to manage.

Microsoft do have a tool available which will make your life much easier and allow you to use one start menu or desktop folder for all users. You can make shortcuts available to users depending on what security groups they are part of. So you have one redirected start menu folder for all users but only make apps available which they need to use, and this is all controlled by Security Groups.

The tool is Share and Storage Management which is part of Windows Server 2008 and replaces File Server Management tool in Windows Server 2003.

To add the feature to a Windows 2008 server:

1. Start the Server Manager
2. Click Roles
3. Click Add Roles
4. Select File Services and click the Next button
5. Select File Server Resource Manager
6. Decide which volumes you would like to monitor and configure the rest as required
7. When done, the File Server Resource Manager and the Share and Storage Management tools are installed

To configure the feature

1. Access Share and Storage Management tools via programs, administrative tools
2. Right click on the share, for example startmenu if you have one
3. Click Properties
4. Click the advanced button
5. Click ‘Enable Access-Based enumeration’ and click OK
6. Click the permissions tab and setup share permissions and NTFS permission as required. If its for a redirected start or desktop folder, you may want to allow users
read only access.
7. Click OK when done
8. Now access your redirected start menu folder where ever it is setup, right click on a shortcut, for example Sage Payroll and add the Sage Security Group to the security tab. The result is, the Sage Payroll application shortcut
will only be visible to users within the Sage Security Group.