VMware Horizon Community
jmatz135
Hot Shot
Hot Shot

After Software Updates Via SCCM Some Persistent Desktops Go Agent Unreachable

We have a few hundred persistent full VMs in our Horizon View environment.  These are updated via SCCM as they are full persistent VMs.  Occasionally a few of them will get their updates, restart and then go agent unreachable.  The only way to get them back is to remove them from the desktop pool and re-add them to the pool then shut them down and let Horizon View configure them and then start them up.  Does anyone have any idea why this would happen?  Horizon View 7.8

Reply
0 Kudos
3 Replies
Alex_Romeo
Leadership
Leadership

Hi,

Try to check which updates have been applied on the computers you lose reachability. It happens that some security updates make computers unreachable.

Prevent a worm by updating Remote Desktop Services (CVE-2019-0708) – Microsoft Security Response Cen...

https://www.reddit.com/r/vmware/comments/9zetv2/agent_unreachable_on_newly_added_vms_solved/?utm_sou...

Alessandro Romeo

Blog: https://www.aleadmin.it/
Reply
0 Kudos
jmatz135
Hot Shot
Hot Shot

It's happened to a small number of random computers a few months in a row now.  It isn't a particular update that is causing the issue. 

Reply
0 Kudos
jmatz135
Hot Shot
Hot Shot

So it looks like the Horizon View Agent is trying to request a Changekey with the server.  Logs on the server show:
[DesktopTracker] CHANGEKEY message from agent/{some long guid} is discarded as it cannot be validated

[JMSMessageSecurity] Message could not be validated: Signature invalid for identity agent/{long guid}

[JMSMessageSecurity] Identity validation failed: UNKNOWN

This seems to be the same issue as is described in this article:

VMware Knowledge Base

Presumably we could run a key reset to get the machine working again as well.

The question is why does running software updates on the machine and rebooting it cause this to happen occasionally. 

Reply
0 Kudos