Citrix Provisioning

What’s new

What’s new in 2603

This release of Citrix Provisioning includes the enhancements described in the following sections. It includes several fixes for issues seen in past releases, and issues that we have identified.

New server certificate requirements

A server certificate for the provisioning server is now required in all configurations. Additionally, each server certificate must meet additional requirements. To help with this, the Configuration Wizard now includes a feature to generate a self-signed certificate that meets these requirements.

For more information, see:

Support for the New Microsoft SecureBoot CA Certificates

As documented by Microsoft at Windows Secure Boot certificate expiration and CA updates - Microsoft Support, the current certificates used for validating binaries when using Secure Boot are expiring in 2026 and have been replaced by new CA certificates which will be used in the future to validate that binaries are properly signed. This release of Citrix Provisioning includes support for secure boot when these new certificates are being used. See Windows Secure Boot certificate expiration and CA updates for details on how you can prepare for supporting secure boot once this has happened.

It is vital that you start the process of upgrading the hypervisor and existing VMs as well as upgrading to a version of Citrix Provisioning that supports the new certificates now to avoid outages starting in June 2026.

For more information, see Windows Secure Boot certificate expiration and CA updates.

New ports for internal communication

In addition to using UDP ports 6890-6909 for internal communications between provisioning servers, TCP ports 6890-6909 are now also used as Citrix Provisioning transitions to an improved internal communications protocol which will facilitate future enhancements. These ports must be allowed through the firewall. The provisioning server installer will adjust the firewall rules for these new ports if you select to automatically open the firewall ports. For more information, see UDP and TCP ports.

What’s new