Link to home
Start Free TrialLog in
Avatar of thegordo
thegordoFlag for United Kingdom of Great Britain and Northern Ireland

asked on

Citrix Access Gateway with AAC - configuration of certificates

Hi all

Could anyone please provide me with some detailed steps on how to setup a CAG / AAC 4.5 (Advanced) implementation with certificates?

For testing purposes I just want to configure this so that I can connect to the CAG/AAC without purchasing a cert but using the one that comes with it if possible...
I intend to buy one from Verisign later...

Apparently I need a server cert and a root cert but am unsure as to which one is installed where, and where the certs are obtained from (on the AAC?)

Please do not send just random links - I am quite knowledgable in Citrix and have tried the usual googling/Citrix Knowledge base searches...

Many thanks

JG
ASKER CERTIFIED SOLUTION
Avatar of t_swartz
t_swartz

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Avatar of thegordo

ASKER

So say I have a remote client, a CAG and a AAC server. Does your solution above secure the comms between the CAG and the AAC or the client and the CAG?

Sorry but I am being stupid...!
Avatar of t_swartz
t_swartz

Not stupid, it is confusing to me as well. The setup you are refering to secures the communications between the cag and the client. You can secure the comms between the aac and the cag as well as I recall. In the setup you have, the cag just becomes a gateway, the aac server does all the access control, about the only thing the cag does that I can figure out for sure is allow those connections and provide a web interface to deliver the apps you specify within the access control manager console (that is configuring the settings on the aac). Side note, something I learned in setting mine up, on general cag/aac operation, as you publish different things for your users, you have to go into the citrix access server configuration tool and deploy the logon points. As you edit the changes, you remove and redeploy those logon points so the settings take effect.
Many thanks for your help - much appreciated!