Solved

ssl certificate renewal

Posted on 2008-10-11
7
2,917 Views
Last Modified: 2012-05-05
i have an ssl certificate installed on a citrix access gateway enterprise. it is expiring in about two weeks time and i need to renew it. do i have to create a new csr for renewal. like if i go to the device i do have an option for updaing the certificate and when you click on the update it asks for a file name, key file name and a passphrase. procedure in citrix AGEE , create a key, create a csr using the key and the information like the server FQDN, Ou name, region etc. i was not the one who created the CSR earlier so i dont know the infor provided then. i know only the server FQDN, so it it ok id in the new csr i only mention the FQDN. need some assisnance in certificate renewal
0
Comment
Question by:mgmohiuddin
7 Comments
 
LVL 8

Assisted Solution

by:sstone55423
sstone55423 earned 300 total points
Comment Utility
This describes the process well.
 
http://support.citrix.com/article/CTX113627
 
0
 

Author Comment

by:mgmohiuddin
Comment Utility
yes, i have already seen this document, but i need a procedure to renew not to add a new one. my question is do i need to create a new crs,and how to update the certificate, not to add a new one
0
 
LVL 10

Accepted Solution

by:
JaredJ1 earned 200 total points
Comment Utility
Just create a CSR - then provide the contents of this file to your certificate provider (verisign or whoever). Once done, import the new certificate. You only need the FQDN to generate the CSR. All the other info is irrelevant really. If your website is https://citrixlogin.acme.com then your FQDN will just be "citrixlogin.acme.com"
0
Maximize Your Threat Intelligence Reporting

Reporting is one of the most important and least talked about aspects of a world-class threat intelligence program. Here’s how to do it right.

 

Author Comment

by:mgmohiuddin
Comment Utility
Thanks for the reply. Yes i did as you said, generated the CSR, got a new certificate issued from a commercial CA. hen i was trying to import it it did give me a warning that some code was missing, but it did configure the device with the certificate and is working fine. actually i just generated the CSR and gave it to my boss who actually ordered for the certificate. i think he used the option to renew the old certificate. but i added the certificate as if it is a new certificate. i hope it will not be an issue. our old cert is still valied for a week so i want to be sure that this new certificate is ok. it is working , i am just worried about the warning that i got during the import. the reason i did not renew the old one is as it was having a key length of 512, but the one i got is 1024, so is it ok to continue like this as it seems to be working or should i update the old certificate
0
 
LVL 8

Assisted Solution

by:sstone55423
sstone55423 earned 300 total points
Comment Utility
This will work fine.  The 1024 is substantially more secure.  I wouldn;t pay extra just for 1024 versus 512 key length for this application, but if it was the same price -- why not?
I'm glad it is working fine.
0
 

Author Comment

by:mgmohiuddin
Comment Utility
i hope the old one is not cached and is still using the old certificate in spite of configuring the device with a new certificate. this waringn i was talking about can be ignored i guess
0
 

Expert Comment

by:RattlesnakeIsland
Comment Utility
Same issue... I have the renewed certificate. Do I update the existing one? When I tried to add a new one the error was Resource already exists.
0

Featured Post

How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

Join & Write a Comment

SSL stands for “Secure Sockets Layer” and an SSL certificate is a critical component to keeping your website safe, secured, and compliant. Any ecommerce website must have an SSL certificate to ensure the safe handling of sensitive information like…
Exchange server is not supported in any cloud-hosted platform (other than Azure with Azure Premium Storage).
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now