Citrix ADC Release (Feature Phase) 14.1 Build 34.42
Release Date: Oct 28, 2024
IMPORTANT
- Build 14.1-25.53 and later builds address the security vulnerabilities described in CTX677944 and CTX677998.
- Build 14.1-25.56 and later builds address the security vulnerabilities described in CTX678072. This build replaces 14.1-25.53.
- Build 14.1-12.35 and later builds address the security vulnerabilities described in CTX584986.
- Build 14.1-8.50 and later builds address the security vulnerabilities described in CTX579459.
- Build 14.1-4.42 and later builds address the security vulnerabilities described in CTX561482 and prior bulletins.
Release Notes Citrix ADC
For detailed documentation for the release refer to Citrix ADC 14.1
Note to SDX Customers
Citrix ADC image file name format has changed starting from 12.0 release as explained this example:
New name format: build-14.1-4.42_nc_64.tgz
Equivalent old format build-14.1-4.42_nc.tgz
Upgrading of Citrix ADC instance to 13.0 using SVM GUI in older SVM versions will not work. Please use the workaround below :
- SVM 11.1 version prior to 55.x or any version of 11.0 or 10.5: Rename 13.0 Citrix ADC image file name to old format as per the example above.
Supported Citrix ADC Platforms
Please refer to CTX113357 for updates on the Citrix ADC Hardware/Software Compatibility Matrix.
Please Note
From 12.1 release, the following weak ciphers are removed from the DEFAULT_BACKEND cipher group. DEFAULT_BACKEND cipher group is bound by default to the SSL, SSL_TCP, SIP_SSL, SSL_Diameter and SSL_FIX services on NetScaler.
- SSL3-DES-CBC-SHA
- SSL3-EXP-DES-CBC-SHA
- SSL3-EXP-RC2-CBC-MD5
- SSL3-EDH-DSS-DES-CBC-SHA
- TLS1-EXP1024-DHE-DSS-DES-CBC-SHA
- SSL3-EXP-EDH-DSS-DES-CBC-SHA
- SSL3-EDH-RSA-DES-CBC-SHA
- SSL3-EXP-EDH-RSA-DES-CBC-SHA
- TLS1-EXP1024-RC2-CBC-MD5
- SSL3-ADH-DES-CBC-SHA
- SSL3-EXP-ADH-DES-CBC-SHA
Build
Release 14.1 Build 34.42 (nCore)
- SHA-256 - f44d4094f25523ca292efef0443b915058e84ccc1dbc89be8acdaec092c46150
Digital Signature File
- SHA-256 - ae4990416de6ea9ce7496754916169e4b383856f3ae35b7ef685d833dc4f5d20
Digital Signing Public Key
- SHA-256 - f236d31cec90f4159e835eeaa72fa56d1cf20f0accac110acb857335cd41d075
Command to Verify Digital Signature
openssl dgst -sha512 -verify build-14.1-34.42_signing.pub -signature build-14.1-34.42_nc_64.tgz.sha512.signed build-14.1-34.42_nc_64.tgz
Verified OK
Audit Servers
Audit Server Utilities for Windows
- SHA-256 - 7ed9b33bb9a4918a7108ea6a3175527b0ac010ddffeb99fb0c11f15151047c6c
Audit Server Utilities for Linux
- SHA-256 - b41d210bcd0a343de5c9364d81cf3afcb6684f380bd40451d7ff21c0e2e047c8
Audit Server Utilities for BSD
- SHA-256 - 2bc44fa6aa7c0c57a639f7d3b331453401cf04b216a71b4a882365a4e3552740
Weblog Clients
Weblog Clients for Windows
- SHA-256 - c551f99006302498a22641897ba0c7ee55989ffb89354866f27d89f797225e6d
Weblog Clients for Linux
- SHA-256 - 8784f24a6dbf5361a0248c0fb2877f4d335bc346add903e7938a00bb0cc08b3d
Weblog Clients for BSD
- SHA-256 - cb753d558f96160c9af0496db079b215129687e750bd7583f434f14e00e42522
Additional Components
FIPS Firmware Version 2.2-130013
Note: FIPS firmware version 2.2 applies only to MPX 9700/10500/12500/15500 FIPS appliances.
Checksums- SHA-256 - 0926C8A1BDBE8D678DBEF1600D45AE18A308D4524782BB6D0A234D194BB5BC38
FIPS Firmware Version 2.2 Signature File
- SHA-256 - 0C1CFA0DE318ADB55BD32B4B4AA7059C7F120674C90A84B767DACAC718F53CF2