Citrix Cloud™

Citrix Cloud Connector system requirements

The machines hosting the Citrix Cloud Connector™ must meet the following requirements. At least two Cloud Connectors in each resource location are required for production environments to ensure high availability. As a best practice, Citrix® recommends using the N+1 redundancy model when deploying Cloud Connectors to maintain a highly available connection with Citrix Cloud.

Host Resource requirements

Each Cloud Connector requires a minimum of:

  • 2 vCPU
  • 4 GB memory
  • 20 GB disk space

For Cloud Connectors which will be used for Local Host Cache, Citrix recommends a minimum of 4 vCPU and 6 GB memory for Cloud Connectors.

More vCPU memory enables a Cloud Connector to scale up for larger sites. For recommended configurations, see Scale and size considerations for Cloud Connectors.

Operating systems

The following operating systems are supported:

  • Windows Server 2025
  • Windows Server 2022
  • Windows Server 2019
  • Windows Server 2016

The Cloud Connector is not supported for use with Windows Server Core.

.NET requirements

You must install both of the following on each server.

  • Microsoft .NET Framework 4.7.2 or later. This is already installed by default on Windows Server 2019 and higher. On Windows Server 2016, Download the latest version from the Microsoft website.

  • Microsoft .NET 8.0. Download the latest version from the Microsoft website.

Citrix strongly recommends configuring Windows Update to “Receive updates for other Microsoft products” to ensure these packages are kept up to date.

Server requirements

If you’re using Cloud Connectors with Citrix DaaS™ (formerly Citrix Virtual Apps and Desktops service), refer to Scale and size considerations for Cloud Connectors for machine configuration guidance.

The following requirements apply to all machines where the Cloud Connector is installed:

  • Use dedicated machines for hosting the Cloud Connector. Do not install on the same machine as any other Citrix products, or other applications.
  • The server is not an Active Directory domain controller or any other machine critical to your resource location infrastructure. Regular maintenance on the Cloud Connector performs machine operations that cause an outage to these additional resources.
  • Server clock is set to the correct UTC time.
  • If you are using the graphical installer, you must have a browser installed and the default system browser set.
  • The Cloud Connector installer is downloaded from Citrix Cloud so your browser must allow downloading executable files.

Windows Update guidance

Citrix strongly recommends enabling Windows Update on all machines hosting the Cloud Connector, including the “Install updates for other Microsoft products” policy. The Cloud Connector performs regular checks for pending reboots, which can be triggered by various factors, including Windows Updates, every five minutes. Any detected reboot is promptly executed, irrespective of the preferred day schedule set on the Resource location. This proactive approach ensures that the Cloud Connector isn’t left in a pending update state for an extended period, thereby maintaining system stability.

Citrix Cloud manages restarts to maintain availability, permitting only one Cloud Connector to restart at a time. When setting up Windows Update, ensure that Windows is set to automatically download and install updates during non-business hours. However, the automatic restarts are not allowed for at least four hours to allow the Cloud Connector ample time to manage the restart process. Additionally, you can establish a fallback restart mechanism using Group Policy or a system management tool for situations where a machine must be restarted following an update. For more information, see Manage device restarts after updates.

Note:

  • If the customer does not intend their Cloud Connector to reboot during business hours, we suggest that the customer schedule Windows Updates accordingly outside of business hours.
  • Each Cloud Connector requires approximately 10 minutes to reboot, and this includes the time needed to synchronize with the Citrix Cloud Platform to ensure that only one Cloud Connector reboots at any given point of time. Hence, the recommended minimum delay of four hours for automatic restarts, as mentioned earlier, can be adjusted accordingly to a lesser or greater duration depending on the number of Cloud Connectors in the tenant.

Antivirus configuration

The article Tech Paper: Endpoint Security, Antivirus, and Antimalware Best Practices provides guidelines to help you determine the appropriate balance between security and performance for the Cloud Connectors in your environment. Citrix strongly recommends reviewing these guidelines with your organization’s antivirus and security teams, and performing rigorous lab-based testing before applying them to a production environment.

Certificate validation requirements

The Cloud Connector depends on X.509 certificates to validate the integrity of software packages it installs and Citrix Cloud endpoints that it contacts. These certificates are issued by widely respected enterprise certificate authorities (CAs).

To perform this validation, Cloud Connectors have the following requirements:

  • The root certificates must be present in the host certificate store.
  • The intermediate certificates must be present in the host certificate store.
  • The Cloud Connector must be able to verify the certificate’s Certificate Revocation List (CRL).

For complete instructions for downloading and installing the certificates, see CTX223828.

Root Certificate Requirements

The following root certificates must be installed on Cloud Connector hosts:

  • https://cacerts.digicert.com/DigiCertGlobalRootG3.crt
  • https://cacerts.digicert.com/DigiCertGlobalRootG2.crt
  • https://cacerts.digicert.com/DigiCertGlobalRootCA.crt
  • https://cacerts.digicert.com/DigiCertTrustedRootG4.crt
  • https://cacerts.digicert.com/BaltimoreCyberTrustRoot.crt
  • https://www.d-trust.net/cgi-bin/D-TRUST_Root_Class_3_CA_2_2009.crt
  • https://www.microsoft.com/pkiops/certs/Microsoft%20RSA%20Root%20Certificate%20Authority%202017.crt
  • https://www.microsoft.com/pkiops/certs/Microsoft%20EV%20ECC%20Root%20Certificate%20Authority%202017.crt
  • https://www.microsoft.com/pkiops/certs/Microsoft%20ECC%20Root%20Certificate%20Authority%202017.crt

Root certificates are usually packaged as part of the Operating System or distributed by the Windows Root Certificate Program, unless:

  • The Turn off Automatic Root Certificate Update group policy is in place to block the root certificate update; and
  • Connectivity from the Connector host server to the internet is restricted, preventing the update from being downloaded

If any certificate is missing, the Cloud Connector installer will attempt to download it from http://cacerts.digicert.com.

Where this is not possible, the root certificates will need to be manually installed on all Cloud Connector hosts.

Intermediate Certificate Requirements

The following intermediate certificates must be installed on Cloud Connector hosts:

  • https://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt

Intermediate certificates are usually downloaded on demand when the server is presented with a certificate issued by an intermediate authority that is missing from the Windows Certificate store.

If connectivity from the connector host server to the internet is restricted, this download may not happen. In these cases the intermediate certificates will need to be manually installed on all Cloud Connector hosts.

Certificate Revocation List (CRL) Requirements

It is important to verify that certificates used to validate components have not been compromised. This is implemented with Certificate Revocation Lists (CRLs). When a client uses a certificate to validate the integrity of a file or endpoints, the client checks whether it trusts the CA that issued the certificates and whether the certificate has been revoked. If the certificate is on a CRL, the certificate is revoked and cannot be trusted.

The CRL servers use HTTP on port 80 instead of HTTPS on port 443. Cloud Connector components, themselves, do not communicate over external port 80. The need for external port 80 is a byproduct of the certificate verification process that the operating system performs.

The following CRL endpoints must be available for the Cloud Connector to contact on HTTP port 80:

  • http://cacerts.digicert.com/
  • http://dl.cacerts.digicert.com/
  • http://crl3.digicert.com
  • http://crl4.digicert.com
  • http://ocsp.digicert.com
  • http://www.d-trust.net
  • http://root-c3-ca2-2009.ocsp.d-trust.net
  • http://crl.microsoft.com
  • http://oneocsp.microsoft.com
  • http://ocsp.msocsp.com

For more information about how to test for CRL and OCSP connectivity, see https://www.digicert.com/kb/util/utility-test-ocsp-and-crl-access-from-a-server.htm.

Customer Managed Certificates

In addition to the Citrix-managed certificates required for communicating with Citrix Cloud services, customers can deploy additional certificates on Cloud Connectors to secure communication with other on-premises components. These certificates will be customer-managed and need to be monitored and renewed by the customer.

The following table provides a summary of the communication flows which can be secured with customer-managed certificates.

Component Traffic Flow from Connector Further Documentation
StoreFront Inbound HTTPS Configuration
NetScaler® Gateway Inbound HTTPS Configuration
Hypervisor Outbound Securing connections to the VMware Environment

Citrix DaaS

Utilizing the Cloud Connector for connectivity to DaaS resources necessitates the installation of additional certificates and granting access to extended PKI infrastructure. Each Cloud Connector machine is required to fulfill the following requirements:

  • HTTP port 80 is open to the following addresses:
    • crl.*.amazontrust.com
    • ocsp.*.amazontrust.com
    • *.ss2.us
  • Communication with the following addresses is enabled
    • https://*.amazontrust.com
    • https://*.ss2.us
  • The following root certificates are installed:
    • https://www.amazontrust.com/repository/AmazonRootCA1.cer
    • https://www.amazontrust.com/repository/AmazonRootCA2.cer
    • https://www.amazontrust.com/repository/AmazonRootCA3.cer
    • https://www.amazontrust.com/repository/AmazonRootCA4.cer
    • https://www.amazontrust.com/repository/SFSRootCAG2.cer
  • The following intermediate certificates are installed:
    • https://www.amazontrust.com/repository/G2-RootCA4.orig.cer
    • https://www.amazontrust.com/repository/R3-ServerCA3A.cer
    • https://www.amazontrust.com/repository/SFC2CA-SFSRootCAG2.cer
    • https://www.amazontrust.com/repository/SFC2CA-SFSRootCAG2.v2.cer
    • https://www.amazontrust.com/repository/G2-RootCA1.orig.cer
    • https://www.amazontrust.com/repository/R1-ServerCA1A.cer
    • https://www.amazontrust.com/repository/G2-RootCA3.cer
    • https://www.amazontrust.com/repository/R3-ServerCA3A.orig.cer
    • https://www.amazontrust.com/repository/G2-RootCA2.orig.cer
    • https://www.amazontrust.com/repository/G2-RootCA4.cer
    • https://www.amazontrust.com/repository/R2-ServerCA2A.cer
    • https://www.amazontrust.com/repository/R4-ServerCA4A.cer
    • https://www.amazontrust.com/repository/R1-ServerCA1A.orig.cer
    • https://www.amazontrust.com/repository/G2-RootCA1.cer
    • https://www.amazontrust.com/repository/G2-RootCA2.cer
    • https://www.amazontrust.com/repository/G2-RootCA3.orig.cer
    • https://www.amazontrust.com/repository/R4-ServerCA4A.orig.cer
    • https://www.amazontrust.com/repository/G2-ServerCA0A.cer
    • https://www.amazontrust.com/repository/G2-ServerCA0A.orig.cer
    • https://www.amazontrust.com/repository/SFSRootCA-SFSRootCAG2.cer

If any certificate is missing, the Cloud Connector will download it from https://www.amazontrust.com

For complete instructions for downloading and installing the certificates, see CTX223828.

Active Directory requirements

  • The server must be joined to an Active Directory domain that contains the resources and users that you use to create offerings for your users. For multi-domain environments, see Deployment scenarios for Cloud Connectors in Active Directory.
  • Each Active Directory forest you plan to use with Citrix Cloud must always be reachable by two Cloud Connectors.
  • The Cloud Connector must be able to reach domain controllers in both the forest root domain and in the domains that you intend to use with Citrix Cloud. For more information, see the following Microsoft support articles:
  • Use universal security groups instead of global security groups. This configuration ensures that user group membership can be obtained from any domain controller in the forest.

Supported Active Directory functional levels

The Cloud Connector supports the currently supported Microsoft versions and functional levels.

Note:

Windows Server 2025 functional level is only supported with Database 32k pages disabled.

Network requirements

Federal Information Processing Standard (FIPS) support

The Cloud Connector supports the FIPS-validated cryptographic algorithms that are used on FIPS-enabled machines.

Citrix Cloud Connector system requirements