Product Documentation

Installing the Signed Certificate on Citrix Gateway

When you receive the signed certificate from the Certificate Authority (CA), pair it with the private key on the appliance and then install the certificate on Citrix Gateway.

To pair the signed certificate with a private key

  1. Copy the certificate to Citrix Gateway to the folder nsconfig/ssl by using a Secure Shell (SSH) program such as WinSCP.
  2. In the configuration utility, on the Configuration tab, in the navigation pane, expand SSL and then click Certificates.
  3. In the details pane, click Install.
  4. In Certificate-Key Pair Name, type the name of the certificate.
  5. In Certificate File Name, select the drop-down box in Browse and then click Appliance.
  6. Navigate to the certificate, click Select and then click Open.
  7. In Private Key File Name, select the drop-down box in Browse and then click Appliance. The name of the private key is the same name as the Certificate Signing Request (CSR). The private key is located on Citrix Gateway in the directory \nsconfig\ssl.
  8. Choose the private key and then click Open.
  9. If the certificate is PEM-format, in Password, type the password for the private key.
  10. If you want to configure notification for when the certificate expires, select Notifies When Expires.
  11. In Notification Period, type the number of days, click Create and then click Close.

To bind the certificate and private key to a virtual server

After you create and link a certificate and private key pair, bind it to a virtual server.

  1. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
  2. In the details pane, click a virtual server and then click Open.
  3. On the Certificates tab, under Available, select a certificate, click Add and then click OK.

To unbind test certificates from the virtual server

After you install the signed certificate, unbind any test certificates that are bound to the virtual server. You can unbind test certificates using the configuration utility.

  1. In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway and then click Virtual Servers.
  2. In the details pane, click a virtual server and then click Open.
  3. On the Certificates tab, under Configured, select the test certificate and then click Remove.