Product Documentation

Installing and Managing SSL Certificates

May 04, 2017

The process of installing SSL certificates involves uploading the certificate and key files to the SDX appliance, and then installing the SSL certificate on the NetScaler instances.

Uploading the Certificate File to the SDX Appliance

For any SSL transaction, the server needs a valid certificate and the corresponding private and public key pair. The certificate file must be present on the SDX appliance when you install the SSL certificate on the NetScaler instances. You can also download the SSL Certificate files to a local computer as a backup.

In the SSL Certificates pane, you can view the following details.

Name
The name of the certificate file.
Last Modified
The date when the certificate file was last modified.
Size
The size of the certificate file in bytes.

To upload SSL certificate files to the SDX appliance

  1. In the navigation pane, expand Management Service, and then click SSL Certificate Files.
  2. In the SSL Certificates pane, click Upload.
  3. In the Upload SSL Certificate dialog box, click Browse and select the certificate file you want to upload.
  4. Click Upload. The certificate file appears in the SSL Certificates pane.

To create a backup by downloading an SSL certificate file

  1. In the SSL Certificates pane, select the file that you want to download, and then click Download.
  2. In the message box, from the Save list, select Save as.
  3. In the Save As message box, browse to the location where you want to save the file, and then click Save.

Uploading SSL Key Files to the SDX Appliance

For any SSL transaction, the server needs a valid certificate and the corresponding private and public key pair. The key file must be present on the SDX appliance when you install the SSL certificate on the NetScaler instances. You can also download the SSL key files to a local computer as a backup.

In the SSL Keys pane, you can view the following details.

Name
The name of the key file.
Last Modified
The date when the key file was last modified.
Size
the size of the key file in bytes.

To upload SSL key files to the SDX appliance

  1. In the navigation pane, expand Management Service, and then click SSL Certificate Files.
  2. In the SSL Certificate pane, on the SSL Keys tab, click Upload.
  3. In the Upload SSL Key File dialog box, click Browse and select the key file you want to upload.
  4. Click Upload to upload the key file to the SDX appliance. The key file appears in the SSL Keys pane.

To create a backup by downloading an SSL key file

  1. In the SSL Certificate pane, on the SSL Keys tab, select the file that you want to download, and then click Download.
  2. In the message box, from the Save list, select Save as.
  3. In the Save As message box, browse to the location where you want to save the file, and then click Save.

Installing an SSL Certificate on a NetScaler Instance

The Management Service lets you install SSL certificates on one or more NetScaler instances. Before you begin installing the SSL certificate, make sure that you have uploaded the SSL certificate and key files to the SDX appliance.

To install SSL certificates on a NetScaler instance

  1. In the navigation pane, click NetScaler.
  2. In the details pane, under NetScaler Configuration, click Install SSL Certificates.
  3. In the Install SSL Certificates dialog box, specify values for the following parameters.
    Certificate File*
    Specify the file name of the valid certificate. The certificate file must be present on the SDX appliance.
    Key File*
    Specify the file name of the private-key used to create the certificate. The key file must be present on the SDX appliance.
    Certificate Name*
    Specify the name of the certificate-key pair to be added to the NetScaler. Maximum length: 31
    Certificate Format*
    Specify the format of the SSL certificate supported on the NetScaler. A NetScaler appliance supports the PEM and DER formats for SSL certificates.
    Password
    Specify the pass-phrase that was used to encrypt the private-key. This option can be used to load encrypted private-keys. Max length: 32.
    Note: Password protected private key is supported only for the PEM format.
    Save Configuration*
    Specify whether the configuration needs to be saved on the NetScaler. Default value is false.
    Instance IP Address*
    Specify the IP addresses of the NetScaler instances on which you want to install the SSL certificate.
  4. Click OK, and then click Close.

Updating an SSL Certificate on a NetScaler Instance

You can update some parameters, such as the certificate file, key file, and certificate format of an SSL certificate that is installed on a NetScaler instance. You cannot modify the IP address and certificate name.

To update the SSL certificate on a NetScaler instance

  1. In the navigation pane, expand NetScaler, and then click SSL Certificates.
  2. In the SSL Certificates pane, click Update.
  3. In the Modify SSL Certificate dialog box, set the following parameters:
    • Certificate File*—The file name of the valid certificate. The certificate file must be present on the SDX appliance.
    • Key File—The file name of the private-key used to create the certificate. The key file must be present on the SDX appliance.
    • Certificate Format*—The format of the SSL certificate supported on the NetScaler. A NetScaler appliance supports the PEM and DER formats for SSL certificates.
    • Password—The pass-phrase that was used to encrypt the private-key. This option can be used to load encrypted private-keys. Maximum length: 32 characters.
      Note: Password protected private key is supported only for the PEM format.
    • Save Configuration—Specify whether the configuration needs to be saved on the NetScaler. Default value is false.
    • No Domain Check—Do not check the domain name while updating the certificate.

    *A required parameter

  4. Click OK, and then click Close.

Polling for SSL Certificates on the NetScaler Instances

If you add a new SSL certificate directly on a NetScaler instance after logging on to that instance, the Management Service is not aware of this new certificate. To avoid this, specify a polling interval after which the Management Service will poll all the NetScaler instances to check for new SSL certificates. You can also perform a poll at any time from the Management Service if, for example, you want to immediately get a list of all the SSL certificates from all the NetScaler instances.

To configure a polling interval

  1. In the navigation pane, expand NetScaler, and then click SSL Certificates.
  2. In the SSL Certificates pane, click Configure Polling Interval.
  3. In the Configure Polling Interval dialog box, set the following parameters:
    • Polling Interval*—The time after which the Management Service polls the NetScaler instances.
    • Interval Unit*—The unit of time. Possible values: Hours, Minutes. Default: Hours.

    *A required parameter

  4. Click OK, and then click Close.

To perform an immediate poll

  1. In the navigation pane, expand NetScaler, and then click SSL Certificates.
  2. In the SSL Certificates pane, click Poll Now.
  3. In the Confirm dialog box, click Yes. The SSL Certificates pane is refreshed and new certificates, if any, appear in the list.