Citrix Secure HDX / DTLS 1.0 & RC5 Removal

Citrix has just removed two security standards from the 1990s from the Citrix Workspace app for Mac 2603.10 Tech Preview.

Sessions that have worked reliably for years are failing right now.

Citrix Workspace for Mac 2603.10: Deprecation of DTLS 1.0

Symptom

When the session starts, the desktop appears briefly—then the host terminates the connection before you can do anything.

Client logs show:

  • ICAEngLoadPd failed: Secure Ica 1.0 is deprecated
  • CAPABILITY_SECUREICA2: Host does not support Secure ICA 2.0
  • PACKET_TERMINATE → Session.Launch.ConnectionFailed

And the VDA confirms it. ICA Service event log:

→ Event ID 3: “You do not have the correct encryption level to access this session.”

The current public release still works.

Only the Tech Preview doesn't work.

The reason is more interesting than the symptom

  • DTLS 1.0 has been officially removed from the client
  • Secure ICA 1.0 (RC5) is gone as well

The removal of DTLS is documented.

Screenshot below — 2603.10 is explicitly named; DTLS 1.2 is now the default.

There is no documentation anywhere on how to remove RC5.

You can only see it in the ICA engine log:

→ “ICAEngLoadPd failed: Secure Ica 1.0 is deprecated”

The client can no longer load RC5. If the VDA does not yet support Secure HDX, the capability negotiation fails—and the host terminates the session due to an explicit encryption mismatch.

What this means for CVAD environments

  • Mac users running the Preview build are affected today
  • The Windows Workspace app will likely follow the same path
  • Secure ICA has been deprecated on the server side since CVAD 2402
  • The migration window is getting smaller

A note on the Tech Preview status

Specific symptoms may vary between preview builds.

What won’t change is the direction—RC5 and DTLS 1.0 are being phased out on the client side; the server-side deprecation has been in effect since CVAD 2402; and the platform modernization train has already left the station.

The strategic direction is clear: Secure HDX

Application-level end-to-end encryption using AES-256-GCM.

The gateway still routes the traffic—but can no longer inspect it.

From our Secure HDX migrations, one pattern keeps emerging

When you combine Secure HDX with HDX Insight or SmartControl, the gateway requires a new TLS-secured side channel to the VDA—separate from the standard 1494/2598 path.

Firewall rules and certificate chains that were “good enough” for years suddenly become critical along that path.

Check those before you flip the switch.

Quick Self-Check

Run this on the VDA during an active session:

ctxsession.exe -v

If the ICA Encryption line still shows RC5 instead of SecureHDX AES-256 GCM —

The move to Secure HDX is long overdue. We’re seeing this across multiple @Citrix environments at ceterion. Same direction, different obstacles.


Update 1

Sources, for anyone who wants to verify:

  1. DTLS 1.0 removal — the first screenshot is from the official Citrix Workspace app for Mac 2603.10 Preview documentation. It’s a dynamically updated page, so the content changes with each new preview — hence the screenshot rather than a link. Citrix states that the Mac client no longer supports DTLS 1.0 and now defaults to DTLS 1.2.

  2. RC5 / Secure ICA 1.0 removal — this isn't mentioned in any public documentation. The evidence comes from a full correlation of client and server logs:

→ engload.m: “ICAEngLoadPd failed: Secure ICA 1.0 is deprecated”
→ wdinit.c: “CAPABILITY_SECUREICA2: Host does not support Secure ICA 2.0”
→ session terminates with PACKET_TERMINATE / Session.Launch.ConnectionFailed
→ VDA ICA Service event log (second screenshot), Event ID 3: encryption-level mismatch — confirming on the server side that this is exactly what breaks the crypto handshake

The same connection works with the Public Release in the same environment—as confirmed by a direct comparison. Server-side context: Secure ICA has been deprecated since CVAD 2402.

That asymmetry is the whole point—one change is announced, while the other can only be detected by its effect.

I'd be happy to compare notes if you're seeing the same thing in your environment.


Update 2

2603.10 has been released as a general availability (GA) version (June 4)—it is no longer a Tech Preview. It is now available as a manual download; the phased automatic update rollout has not yet reached devices (and may be restricted by your GACS/MDM policies), so the exact timing of its arrival will vary by environment.

Two entries in the official 2603.10 list of fixed issues are worth highlighting, because they match exactly what we observed in the field:

→ “Sessions might disconnect unexpectedly over TCP due to a decryption failure” (CVADHELP-31790)
→ “Sessions might disconnect unexpectedly after a network interruption” (CCVADHELP-4930)

The removal of DTLS 1.0 is now documented in the stable release notes (not just on the rolling preview page): docs.citrix.com/en-us/citrix-workspace-app-for-mac/whats-new

The RC5 / Secure ICA 1.0 issue still isn't mentioned anywhere in the documentation—it remains a log-only finding. The asymmetry persists.

Bottom line: it’s GA. Once it’s added to your fleet, anyone still using RC5 server-side will feel the impact—so it’s worth planning the switch to Secure HDX before then.