Citrix PVS The security database on the server does not have a computer account

Navigation

This article applies to all 7.x versions of Citrix Provisioning, including 2206, LTSR 2203, LTSR 1912 CU5, LTSR 7.15.45 (aka 7.15 LTSR CU9), and LTSR 7.6.9 (aka 7.6 LTSR CU8).

  • Change Log
  • Planning and Versions
  • Citrix License Server Version
  • Upgrade
  • vDisk Storage
    • Robocopy Script
  • Installs/Upgrades
    • .Net Framework
    • Provisioning Console
    • Provisioning Server
  • Database Configuration
    • Database Script
    • Configuration Wizard – New Farm
    • Configuration Wizard – Join Farm
  • Troubleshooting – Networking Services Don’t Work After Reboot
  • Firewall
  • Disable BIOS Boot Menu
  • Private Mode vDisk – No Servers Available for vDisk
  • Multi-homed Provisioning Server
  • Antivirus Exclusions
  • TFTP High Availability
  • DHCP Failover
  • Health Check

💡 = Recently Updated

Change Log

  • 2022 July 29 – updated Versions section with PVS 7.15.45 (from LTSR 7.15 Cumulative Update 9)
  • 2022 July 1 – updated Versions section and Install sections with Citrix Provisioning 2206
  • 2022 Mar 27 – updated Versions section and Install sections with Citrix Provisioning 2203
  • 2022 Mar 10 – updated Versions section with Citrix Provisioning 1912 LTSR CU5
  • 2021 Dec 18 – updated Versions section and Install sections with Citrix Provisioning 2112
  • 2021 Nov 3 – updated Versions section with Citrix Provisioning 1912 LTSR CU4
  • 2021 Sep 27 – updated Versions section and Install sections with Citrix Provisioning 2109
  • 2021 Aug 12 – updated Versions section with PVS 7.15.39 (from LTSR 7.15 Cumulative Update 8)
  • 2021 June 17 – updated Versions section and Install sections with Citrix Provisioning 2106
  • 2021 May 14 – updated Versions section with Citrix Provisioning 1912 LTSR CU3
  • 2021 Feb 10 – updated Versions section with PVS 7.15.33 (from LTSR 7.15 Cumulative Update 7)
  • 2020 Dec 14 – updated Versions section and Install sections with Citrix Provisioning 2012
  • 2020 Nov 20 – updated Versions section with Citrix Provisioning 1912 LTSR CU2
  • 2020 Sep 30 – updated Versions section and Install sections with Citrix Provisioning 2009
  • 2020 Jul 1 – updated Versions section with PVS 7.15.27 (from LTSR 7.15 Cumulative Update 6)
  • 2020 Jun 18 – updated Versions section and Install sections with Citrix Provisioning 2006
  • 2020 May 7 – updated Versions section and Install sections with Citrix Provisioning 1912 LTSR CU1
  • 2020 Mar 28 – updated Versions section and Install sections with Citrix Provisioning 2003

Planning and Versions

CTX220651 Best Practices for deploying PVS in multi-geo environments: ensure that Provisioning farms do not span data centers with a network latency that can affect communications between the Provisioning Servers and the SQL database

SQL 2019 is supported with Citrix Provisioning 2003 and newer.

Citrix Provisioning Firewall Rules

The most recent Current Release version of Citrix Provisioning is 2206.

Citrix PVS The security database on the server does not have a computer account

For LTSR CVAD, deploy the Citrix Provisioning version that matches your CVAD version:

Citrix License Server Version

Upgrade the Citrix Licensing server to the latest version.

Citrix PVS The security database on the server does not have a computer account

Upgrade

Windows Server 2022 is supported with Citrix Provisioning 2206 and newer.

SCVMM 2022 is supported with Citrix Provisioning 2206 and newer.

If you are upgrading from an older version of Citrix Provisioning, do the following:

  1. In-place upgrade the Citrix License Server.
  2. In-place upgrade the Provisioning Console.
    1. Re-register the Citrix.PVS.snapin.dll snap-in: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe" "c:\program files\citrix\provisioning services console\Citrix.PVS.snapin.dll"
    2. If upgrading from 7.15.3000 to 7.15.4000, then manually upgrade the snap-ins. See CTX256773 Powershell SnapIns are not upgraded from PVS 7.15 LTSR CU3 to 7.15 LTSR CU4 after the upgrade is complete
      Citrix PVS The security database on the server does not have a computer account
  3. In-place upgrade the Provisioning Server. If you have two or more Provisioning servers, upgrade one, and then the other. If High Availability is configured correctly, then the Target Devices should move to a different Provisioning server while a Provisioning server is being upgraded.
    1. After the first Provisioning server is upgraded, run the Configuration Wizard. You can generally just click Next through the wizard. At the end, you’ll be prompted to upgrade the database. Then upgrade the remaining Provisioning servers and run the Config Wizard on each of them too.
      Citrix PVS The security database on the server does not have a computer account
  4. Upgrade the Target Device Software inside each vDisk. Don’t do this until the Provisioning servers are upgraded (Target Device Software must be same version or older than the Provisioning Servers).
    1. If your Target Devices are 7.6.1 or newer, you can create a Maintenance version, boot an Updater Target Device, and in-place upgrade the Target Device Software.
    2. If your Target Devices are older, then you must reverse image.

vDisk Storage

Do the following on both Provisioning Servers. The vDisks will be stored locally on both servers. You must synchronize the files on the two servers: either manually (e.g. Robocopy), or automatically (e.g. DFS Replication).

Create D: Drive

  1. In the vSphere Web Client, edit the settings for each of the Provisioning server virtual machines.
  2. On the bottom, use the drop-down list to select New Hard Disk, and click Add.
    Citrix PVS The security database on the server does not have a computer account
  3. Expand the New Hard disk by clicking the arrow next to it.
  4. Change the disk size to 500 GB or higher. It needs to be large enough to store the vDisks. Each full vDisk is 40 GB plus a chain of snapshots. Additional space is needed to merge the chain.
  5. Feel free to select Thin provision, if desired. Click OK when done.
    Citrix PVS The security database on the server does not have a computer account
  6. Login to the session host. Right-click the Start Button, and click Disk Management.
    Citrix PVS The security database on the server does not have a computer account
  7. In the Action menu, click Rescan Disks.
    Citrix PVS The security database on the server does not have a computer account
  8. On the bottom right, right-click the CD-ROM partition, and click Change Drive Letters and Paths.
    Citrix PVS The security database on the server does not have a computer account

  9. Click Change.
    Citrix PVS The security database on the server does not have a computer account
  10. Change the drive letter to E:, and click OK.
    Citrix PVS The security database on the server does not have a computer account
  11. Click Yes when asked to continue.
    Citrix PVS The security database on the server does not have a computer account
  12. Right-click Disk 1 and click Online.
    Citrix PVS The security database on the server does not have a computer account
  13. Right-click Disk 1 and click Initialize Disk.
    Citrix PVS The security database on the server does not have a computer account
  14. Click OK to initialize the disk.
    Citrix PVS The security database on the server does not have a computer account
  15. Right-click the Unallocated space, and click New Simple Volume.
    Citrix PVS The security database on the server does not have a computer account
  16. In the Welcome to the New Simple Volume Wizard page, click Next.
  17. In the Specify Volume Size page, click Next.
  18. In the Assign Drive Letter or Path page, select D: and click Next.
  19. In the Format Partition page, change the Volume label to vDisks and click Next.
    Citrix PVS The security database on the server does not have a computer account
  20. In the Completing the New Simple Volume Wizard page, click Finish.
  21. If you see a pop-up asking you to format the disk, click Cancel since Disk Management is already doing that.

vDisk Folders

On the new D: partition, create one folder per Delivery Group. For example, create one called Win10Common, and create another folder called Win10SAP. Each vDisk is composed of several files, so its best to place each vDisk in a separate folder. Each Delivery Group is usually a different vDisk.

Citrix PVS The security database on the server does not have a computer account

Robocopy Script

Here is a sample robocopy statement to copy vDisk files from one Provisioning server to another. It excludes .lok files and excludes the WriteCache folders.

REM Robocopy from PVS01 to PVS02 REM Deletes files from other server if not present on local server Robocopy D:\vDisks \\pvs02\d$\vDisks *.vhd *.vhdx *.avhd *.avhdx *.pvp /b /mir /xf *.lok /xd WriteCache /xo

Citrix Blog Post vDisk Replicator Utility has a GUI utility script that can replicate vDisks between Provisioning Sites and between Provisioning Farms.

Citrix PVS The security database on the server does not have a computer account

Citrix PVS The security database on the server does not have a computer account

Service Account

Provisioning Services should run as a domain account that is in the local administrators group on both Provisioning servers. This is required for KMS Licensing.

Citrix PVS The security database on the server does not have a computer account

Provisioning Console Install/Upgrade

The installation and administration of Citrix Provisioning 2206 and older (including LTSR versions 2203, 1912 CU5, 7.15.45 and 7.6.9) are essentially identical.

Windows Server 2022 is supported with Citrix Provisioning 2206 and newer.

SCVMM 2022 is supported with Citrix Provisioning 2206 and newer.

If you want to automate the installation and configuration of Citrix Provisioning, see Dennis Span Citrix Provisioning Server unattended installation.

Citrix PVS The security database on the server does not have a computer account

To manually install Provisioning Console, or in-place upgrade the Provisioning Console:

  1. Go to the downloaded Citrix Provisioning, and in the Console folder, run PVS_Console_x64.exe.
    Citrix PVS The security database on the server does not have a computer account
  2. Click Install.
    Citrix PVS The security database on the server does not have a computer account
    1. If you are upgrading, and if you get an error about a newer version of Citrix Diagnostics Facility is already installed…
      Citrix PVS The security database on the server does not have a computer account
    2. …then you might have to uninstall the existing Citrix Diagnostics Facility installation and try the upgrade again.
      Citrix PVS The security database on the server does not have a computer account
  3. If you see the .NET Framework Setup page:
    1. Check the box next to I have read and accept the license terms, and click Install.
      Citrix PVS The security database on the server does not have a computer account
    2. In the Installation Is Complete page, click Finish.
      Citrix PVS The security database on the server does not have a computer account
    3. Click Restart Now.
      Citrix PVS The security database on the server does not have a computer account
    4. Restart the PVS_Console_x64.exe installer.
      Citrix PVS The security database on the server does not have a computer account
    5. Click Install.
  4. In the Welcome to the InstallShield Wizard for Citrix Provisioning Console x64 page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  5. In the License Agreement page, select I accept the terms, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  6. In the Customer Information page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  7. In the Destination Folder page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  8. In the Ready to Install the Program page, click Install.
    Citrix PVS The security database on the server does not have a computer account
  9. In the InstallShield Wizard Completed page, click Finish.
    Citrix PVS The security database on the server does not have a computer account
  10. Click Yes if you are prompted to restart.
    Citrix PVS The security database on the server does not have a computer account

After upgrading the Console, re-register the PowerShell snap-in. This is required for the Citrix App Layering Agent.

"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\InstallUtil.exe" "c:\program files\citrix\provisioning services console\Citrix.PVS.snapin.dll"

Citrix PVS The security database on the server does not have a computer account

Provisioning Server – Install/Upgrade

The installation and administration of Citrix Provisioning 2206, 1912 LTSR CU5, 7.15.45, 7.6.9 and other 7.x versions are essentially identical.

Windows Server 2022 is supported with Citrix Provisioning 2206 and newer.

SCVMM 2022 is supported with Citrix Provisioning 2206 and newer.

You can in-place upgrade Provisioning Server. The Provisioning Servers must be upgraded before the vDisks’ Target Device Software are upgraded. While upgrading one Provisioning Server, all Target Devices are moved to the other Provisioning Server assuming that vDisk High Availability is properly configured.

To install/upgrade Provisioning server:

  1. If vSphere, make sure the Provisioning server virtual machine Network Adapter Type is VMXNET 3.
    Citrix PVS The security database on the server does not have a computer account
  2. Go to the downloaded Provisioning ISO, and in the Server folder, run PVS_Server_x64.exe.
    Citrix PVS The security database on the server does not have a computer account
  3. Click Install when asked to install prerequisites.
    Citrix PVS The security database on the server does not have a computer account
  4. Note: there’s a long delay before the installation wizard appears.
  5. In the Welcome to the Installation Wizard for Citrix Provisioning Server x64 page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  6. In the License Agreement page, select I accept the terms, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  7. In Citrix Provisioning 1811 and newer, you’ll see a Default Firewall Ports page. You can optionally select Automatically open all Citrix Provisioning ports in Windows Firewall. If you later use the Citrix Provisioning Console to change the ports, then the Windows Firewall rules need to be adjusted manually since the Citrix Provisioning Console won’t do it for you.
    Citrix PVS The security database on the server does not have a computer account
  8. In the Customer Information page, select Anyone who users this computer, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  9. In the Destination Folder page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  10. In the Ready to Install the Program page, click Install.
    Citrix PVS The security database on the server does not have a computer account
  11. In the Installation Wizard Completed page, click Finish.
    Citrix PVS The security database on the server does not have a computer account

Database Script

By default, the Citrix Provisioning Configuration Wizard will try to create the database using the credentials of the person that is running the Wizard. This isn’t always feasible. An alternative is to create a script that a DBA can run on the SQL server.

  1. Go to C:\Program Files\Citrix\Provisioning Services, and run DBScript.exe.
    Citrix PVS The security database on the server does not have a computer account
  2. Change the selection to New database for 2012 or higher.
  3. Enter a path to save the script file.
  4. Fill in the other fields.
  5. Select an Active Directory group containing your Citrix administrators, and click OK.
    Citrix PVS The security database on the server does not have a computer account
  6. In SQL Server Management Studio, open the SQL script.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  7. Execute the script to create the database.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  8. The person that runs the Citrix Provisioning Configuration Wizard will need db_owner permission to the new Citrix Provisioning database.
    Citrix PVS The security database on the server does not have a computer account
  9. Create a Windows service account that will run the services on the Citrix Provisioning server. This account must have a SQL login on the SQL server containing the Citrix Provisioning database. The Citrix Provisioning Configuration Wizard will grant this account the correct permissions in the database.
    Citrix PVS The security database on the server does not have a computer account

Configuration Wizard – New Farm

  1. If you used DBScript.exe to pre-create the database, skip to Configuration Wizard – Join Farm.
  2. For SQL AlwaysOn Availability Group, see CTX201203 SQL Server AlwaysOn Configuration for PVS 7.6. In summary: Use the wizard to create the database instance. In SQL, create the Availability Group. Then reconfigure Citrix Provisioning Server to point to the SQL AlwaysOn listener.
  3. The Citrix Provisioning Configuration Wizard launches automatically. If the database wasn’t pre-created, then the person running the wizard must have dbcreator and securityadmin roles on the SQL Server. If true, click Next. If not true, then cancel the wizard and launch it as somebody that does have those roles.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  4. The DHCP Services page appears. DHCP is typically hosted on a different server so select The service that runs on another computer. It is also possible to install DHCP on the Provisioning Servers. Click Next.
    Citrix PVS The security database on the server does not have a computer account
  5. In the PXE Services page, if you intend to use Boot Device Manager (BDM or ISO) instead of PXE, then change the selection to The service that runs on another computer, which disables the PXE service.
  6. If your Target Devices and Provisioning Servers are on the same broadcast network, then change the selection to Citrix Provisioning PXE service on this computer.
  7. Click Next.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  8. In the Farm Configuration page, choose Create Farm, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  9. In the Database Server page, enter the name of the SQL server. Provisioning 2203 has an option for specifying credentials to the SQL server.
    Citrix PVS The security database on the server does not have a computer account
  10. In the New Farm page, enter the following:
    • Enter a descriptive Database name. Put the word Citrix in the database name so the DBA knows what it is for.
    • Enter a descriptive Farm name.
    • Enter a descriptive Site name.
    • Enter a descriptive Collection name. All of these names can be changed later.
    • Select the Active Directory group that will have administrator permissions to Citrix Provisioning, and click Next. If you don’t see your group here, select any group you belong to, and you can fix it later in the console.
      Citrix PVS The security database on the server does not have a computer account
  11. In the New Store page, browse to one of the vDisk folders, and give the store a name. Then click Next.
    Citrix PVS The security database on the server does not have a computer account
  12. In the License Server page, enter the name of your Citrix license server, check the box next to Validate license server communication, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  13. In the User account page, notice it defaults to Network service account. This won’t work with KMS licensing so change it to Specified user account. Enter credentials for an account that is a local administrator on all Provisioning servers, and click Next. Note: Provisioning 7.16 and newer support Group Managed Service Accounts.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  14. In the Active Directory Computer Account Password page, check the box, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  15. In the Network Communications page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  16. In the TFTP Option and Bootstrap Location page, check the box, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  17. In the Stream Servers Boot List page, click Advanced.
    Citrix PVS The security database on the server does not have a computer account
  18. Check the box next to Verbose mode, click OK, and then click Next.
    Citrix PVS The security database on the server does not have a computer account
  19. If Provisioning 7.12 or newer, in the Soap SSL Configuration page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  20. If Provisioning 7.11 or newer, in the Problem Report Configuration page, enter your MyCitrix credentials, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  21. In the Finish page, click Finish.
    Citrix PVS The security database on the server does not have a computer account
  22. If you are upgrading, then you might be asked to upgrade the database. Click Yes.
    Citrix PVS The security database on the server does not have a computer account
  23. Click OK if you see the firewall message.
    Citrix PVS The security database on the server does not have a computer account
  24. In the Finish page, click Done.
    Citrix PVS The security database on the server does not have a computer account

From Running the Configuration Wizard silently at Citrix Docs: Now that you have a configured server, you can run "C:\Program Files\Citrix\Provisioning Services\ConfigWizard.exe" /s to produce an .ans file at "C:\ProgramData\Citrix\Provisioning Services\ConfigWizard.ans". This .ans file can be modified and copied to additional Provisioning servers. "C:\Program Files\Citrix\Provisioning Services\ConfigWizard.exe" /a reads the .ans file and applies the configuration silently.

Configuration Wizard – Join Farm

  1. The Configuration Wizard launches automatically.
  2. There are two methods of handling SQL permissions:
    1. The person running the wizard must have db_owner on the database and securityadmin role on the SQL Server. This allows the wizard to add the service account to SQL logins and grant it access to the database.
    2. Or the person running the wizard can be limited to just db_owner permission to the database. The service account must be added manually to SQL logins by a DBA.
      Citrix PVS The security database on the server does not have a computer account
  3. The DHCP Services page appears. DHCP is typically hosted on a different server so select The service that runs on another computer. It is also possible to install DHCP on the Provisioning Servers. Click Next.
    Citrix PVS The security database on the server does not have a computer account
  4. In the PXE Services page, if you intend to use Boot Device Manager (BDM or ISO) instead of PXE, then change the selection to The service that runs on another computer, which disables the PXE service.
  5. If your Target Devices and Provisioning Servers are on the same broadcast network, then change the selection to Citrix Provisioning PXE service on this computer.
  6. Click Next.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  7. In the Farm Configuration page, click Join existing farm.
    Citrix PVS The security database on the server does not have a computer account
  8. In the Database Server page, enter the name of the SQL server. Provisioning 2203 has an option for specifying credentials to the SQL server.
    Citrix PVS The security database on the server does not have a computer account
  9. In the Existing Farm page, select the database, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  10. In the Site page, select an existing site, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  11. If you used the script to create the database, then there probably are no stores defined. Do so now.
    Citrix PVS The security database on the server does not have a computer account
  12. Otherwise, in the New Store page, select the existing store, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  13. In the License Server page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  14. In the User account page, notice it defaults to Network service account. This won’t work with KMS licensing so change it to Specified user account. Enter credentials for an account that is a local administrator on all Provisioning servers, and click Next. Note: Provisioning 7.16 and newer support Group Managed Service Accounts.
    Citrix PVS The security database on the server does not have a computer account

    Citrix PVS The security database on the server does not have a computer account
  15. In the Active Directory Computer Account Password page, check the box, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  16. In the Network Communications page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  17. In the TFTP Option and Bootstrap Location page, check the box, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  18. In the Stream Servers Boot List page, click Advanced.
    Citrix PVS The security database on the server does not have a computer account
  19. Check the box next to Verbose mode, click OK, and then click Next.
    Citrix PVS The security database on the server does not have a computer account
  20. If Provisioning 7.12 or newer, in the Soap SSL Configuration page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  21. If Provisioning 7.11 or newer, in the Problem Report Configuration page, enter your MyCitrix credentials, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  22. In the Finish page, click Finish.
    Citrix PVS The security database on the server does not have a computer account
  23. Click OK if you see the firewall message.
    Citrix PVS The security database on the server does not have a computer account
  24. In the Finish page, click Done.
    Citrix PVS The security database on the server does not have a computer account

Troubleshooting – Networking Services Don’t Work After Reboot

If your PXE service or TFTP service does not work after a reboot of the Provisioning server, do the following:

  1. One option is to set the Citrix PVS PXE Service, Citrix PVS TFTP Service, and Citrix PVS Two-stage boot Service to Automatic (Delayed Start).
  2. The TFTP and Two-stage Boot services can be delayed by setting registry keys.
    • Keys = HKLM\System\CurrentControlSet\services\BNTFTP (and PVSTSB)\Parameters
    • Value = InitTimeoutSec (DWORD). 1 – 4 seconds. Default is 1.
    • Value = MaxBindRetry (DWORD). 5 – 20 retries. Default is 5.

Disable Firewall

Disable the Windows Firewall to allow communication to all Citrix Provisioning Server ports. Or, see Citrix Provisioning Firewall Rules and manually open all required ports. If you change the ports in the Citrix Provisioning Console, then you’ll need to adjust the Windows Firewall rules accordingly.

  1. In Server Manager, click Tools, and click Windows Firewall with Advanced Security.
    Citrix PVS The security database on the server does not have a computer account
  2. Click Windows Firewall Properties.
    Citrix PVS The security database on the server does not have a computer account
  3. On the Domain Profile tab, change the Firewall state to Off.
    Citrix PVS The security database on the server does not have a computer account

The versioning process in Citrix Provisioning will present a boot menu when booting any version except Production.

Citrix PVS The security database on the server does not have a computer account

  1. To avoid this, create the DWORD registry value HKLM\Software\Citrix\ProvisioningServices\StreamProcess\SkipBootMenu on both Provisioning Servers and set it to 1. Note: the location of this key changed in Provisioning Services 7.0 and newer.
    Citrix PVS The security database on the server does not have a computer account
  2. Then restart the Citrix PVS Stream Service.
    Citrix PVS The security database on the server does not have a computer account

Private Mode vDisk – No Servers Available for vDisk

Citrix CTX200233 – Error: “No servers available for disk”: When you set a vDisk to Private Image mode (or new Maintenance version), if the Target Device is not connected to the server that contains the vDisk then you might see a message saying “No Servers Available for vDisk”.

  1. To avoid this, create the DWORD registry value HKLM\Software\Citrix\ProvisioningServices\StreamProcess\SkipRIMSForPrivate on both Provisioning Servers and set it to 1. Note: the location of this key changed in Provisioning Services 7.0.
    Citrix PVS The security database on the server does not have a computer account
  2. Then restart the Citrix PVS Stream Service.
    Citrix PVS The security database on the server does not have a computer account

Multi-Homed Provisioning Server

From slide 20 of http://www.slideshare.net/davidmcg/implementing-and-troubleshooting-pvs:, Multi-homed Provisioning server is not recommended but if you insist, and if running Provisioning 6.1 or older, configure the following. Provisioning 7.7 configuration wizard should have asked you for the management NIC.

  • HKLM\Software\Citrix\ProvisioningServices\IPC
    • New Reg_Sz (string) named IPv4Address with the IP of the NIC for IPC
  • HKLM\Software\Citrix\ProvisioningServices\Manager
    • New Reg_Sz (string) named GeneralInetAddr with the IP of the NIC and port
    • e.g. 10.1.1.2:6909

Citrix 133877 Timeout Error 4002 in Provisioning Server Console after Clicking “Show Connected Devices“: when there are multiple streaming NICs assigned to the Provisioning Server, when Show Connected Devices was clicked in the Provisioning console, the following symptoms might be experienced: Server timeout error 4002, unusual delay of 3 to 4 minutes to list the connected devices, or Provisioning console stops responding. Complete the following to resolve the issue:

  1. On the Provisioning Server machine, under HKLM\software\citrix\provisioningServices\Manager key, create registry DWORD RelayedRequestReplyTimeoutMilliseconds, and set it to 50 ms (Decimal).
  2. Create a DWORD RelayedRequestTryTimes, and set it to 1.
  3. Open the Provisioning Server console and test by selecting the Show Connected Devices command.

Antivirus Exclusions

Citrix’s Recommended Antivirus Exclusions

Endpoint Security, Antivirus, and Antimalware Best Practices at Citrix Docs TechZone contains a list of recommended exclusions for Citrix Provisioning.

Citrix Blog Post Citrix Recommended Antivirus Exclusions: the goal here is to provide you with a consolidated list of recommended antivirus exclusions for your Citrix virtualization environment focused on the key processes, folders, and files that we have seen cause issues in the field:

  • Set real-time scanning to scan local drives only and not network drives
  • Disable scan on boot
  • Remove any unnecessary antivirus related entries from the Run key
  • Exclude the pagefile(s) from being scanned
  • Exclude Windows event logs from being scanned
  • Exclude IIS log files from being scanned

See the Blog Post for exclusions for each Citrix component/product including: StoreFront, VDA, Controller, and Provisioning. The Blog Post also has links to additional KB articles on antivirus.

Microsoft’s virus scanning recommendations

(e.g. exclude group policy files) – http://support.microsoft.com/kb/822158.

TFTP High Availability

BIOS machines have multiple methods of booting into PVS:

  • PXE (network boot) on same subnet as Citrix Provisioning Servers.
  • PXE (network boot) on different subnet as Citrix Provisioning Servers. DHCP Scope Options 66 and 67 required.
  • Boot ISO created by Citrix Provisioning Boot Device Manager.
  • Boot partition created by the Citrix Provisioning Virtual Desktops Setup Wizard.

EFI/UEFI machines have two methods of booting into PVS:

  • PXE (network boot) on same subnet as Citrix Provisioning Servers. DHCP Scope Option 11 required.
  • PXE (network boot) on different subnet as Citrix Provisioning Servers. DHCP Scope Options 66, 67, and 11 required.

If PXE booting on same subnet as Provisioning Servers, then make sure the PXE service is running on the Citrix Provisioning Servers. When your target device boots, it will broadcast a PXE Request message to the entire subnet. One of the Provisioning Servers PXE services will reply with the IP address of the TFTP service on the local Provisioning Server.

  • If EFI/UEFI, the bootstrap file cannot be modified to contain the Provisioning Server addresses so you must instead configure DHCP Scope Option 11 with those addresses. See CTX208519 Configuring PVS for High Availability with UEFI Booting and PXE service.

If your Target Devices are not on the same VLAN/subnet as the Provisioning Servers, then for EFI/UEFI devices, you will need to configure DHCP Scope Options 66, 67, and 11. BIOS machines can instead use Boot ISO or Boot Partition, but these options are not available for EFI/UEFI.

  • DHCP Scope Option 66 (TFTP Server address) only supports a single address. For High Availability, either DNS Round Robin your TFTP servers, or configure Citrix ADC to load balance TFTP. TFTP service runs on the Citrix Provisioning Servers.
  • Citrix CTX131954 Implementation Guide – High Availability for TFTP
  • NetScaler 10.1 and newer and Citrix ADC have native support for TFTP protocol. Older versions of NetScaler are more difficult to configure.
    Citrix PVS The security database on the server does not have a computer account
  • For EFI/UEFI, for DHCP Scope Option 67, see Unified Extensible Firmware Interface (UEFI) pre-boot environments at Citrix Docs for the correct file name.

DHCP Failover

The DHCP infrastructure must be highly available. And session hosts should be configured with DHCP Reservations. With multiple DHCP servers, any reservation should be created on all DHCP servers hosting the same DHCP scope. The easiest way to accomplish this is with the DHCP Failover feature in Windows Server 2012 and newer.

  1. Build two DHCP servers on Windows Server 2012 or newer.
  2. Create a scope for the Provisioning Target Devices.
  3. Right-click the existing scope, and click Configure Failover.
    Citrix PVS The security database on the server does not have a computer account
  4. In the Introduction to DHCP Failover page, click Next.
    Citrix PVS The security database on the server does not have a computer account
  5. In the Specify the partner server to use for failover page, enter the name of the other DHCP server, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  6. In the Create a new failover relationship page, enter a Shared Secret, and click Next.
    Citrix PVS The security database on the server does not have a computer account
  7. Click Finish.
    Citrix PVS The security database on the server does not have a computer account
  8. Click Close.
    Citrix PVS The security database on the server does not have a computer account

Health Check

CTP Sacha Thomet’s PowerShell script to view the health/status of the Provisioning environment. Emails an HTML Report. For Provisioning 7.7 and newer, see https://blog.sachathomet.ch/2015/12/29/happy-new-script-pvs-7-7-healthcheck/.

Citrix PVS The security database on the server does not have a computer account

  • Provisioning – Console Configuration
  • Back to Citrix Provisioning

How do you fix the security database on the server does not have a computer account?

Security database on the server does not have a computer account for this workstation trust relationship.
First unjoin the computer from the domain and make sure you set a local administrator password on machine or set an user account password which is a member of local administrators group..
Reboot the machine..

How do you fix the security database on the server does not have a computer account for this workstation trust?

Win 10 The Security Database on the Server does not have a Computer Account for this Workstation Trust Relationship after update 20H2.
Run an nslookup on each of the problem machines. ... .
Reset the computer accounts for the problem machines in ADUC..
Verified replication is taking place on both DCs..