[Last Call] Learn how to a build a cloud-first strategyRegister Now


Uploaded new SSL cert now CSG won't start

Posted on 2012-03-26
Medium Priority
Last Modified: 2012-04-10
My client's Citrix SSL certificate expired this weekend. I created a new one from StartSSL and I imported it into the Certificate folder successfully but when I went into QuickStart and tried to apply it at the External Access. Citrix went through the wizard but threw an error at the end saying that the certificate had been deleted which it really wasn't. I clicked ok at that prompt and the wizard then disabled external access. Now the Secure gateway service will not start and when I click through the Secure gateway configuration it tells me that it can't find the STA server.

Can anyone help? The particulars of the server are listed below. Thanks!

Windows 2008 R2
Citrix XenApp 6 Fundamentals build: 6.0.36399.0
Secure Gateway 3.2
Question by:blkfoot
  • 5
  • 3
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771472
run secure-gateway diagnostics.
What's the result?

Author Comment

ID: 37771499
I'm not able to run the Secure Gateway Diagnostics because the Secure Gateway isn't configured but I can't configure the Secure Gateway because it can't find the STA.
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771569
your STA runns on the same or different server?
which port you use to contact the STA?
Are the STA-call SSL protected?
Nothing ever in the clear!

This technical paper will help you implement VMware’s VM encryption as well as implement Veeam encryption which together will achieve the nothing ever in the clear goal. If a bad guy steals VMs, backups or traffic they get nothing.


Author Comment

ID: 37771630
The STA runs on the same server.  I'm not sure how tell which port I use.  The default website is set to 80 and the Citrix site that was created during the install is 8080.  I have tried appending both ports to the FQDN but it still fails.  The Secure Gateway service will not start either i assume because of this.

Sorry, I don't have much of a Citrix background so if there is something I should look at let me know.
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771679
the STA should run within you IIS default webpage.
you can use the IP as URL (or
if you configure the STA within CSG-Config you should see the STA-ID.

if you only change the certificate within CSG - why are the old config are lost?

Author Comment

ID: 37771714
I did try and use the IP address and appended the port with it for the URL and it still won't find the STA.  

I cannot find the STA ID because I can't configure CSG.

I don't understand why the old config was lost either other than when I tried to update the cert from the QuickStart interface it wouldn't accept it and then disabled the External Access.

I am ordering a new cert so i am hoping this will solve the problem.

When I look in the logs for the Secure gateway this is what I see:
[Mon Mar 26 15:05:02 2012] Unable to load SSL Certificate for server citrix.erckhotels.com:443 [hint: SSLCertificateHash]

Accepted Solution

blkfoot earned 0 total points
ID: 37813548
The customer has decided to uninstall Citrix and move to MS Remote Desktop Services.

Author Closing Comment

ID: 37826795
No solution was found so the customer decided to go a different way.

Featured Post

Free Tool: IP Lookup

Get more info about an IP address or domain name, such as organization, abuse contacts and geolocation.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After several days of searching and hunting for limited documentation, I wanted to share this guide to hopefully save someone the hassle of trying to figure this out on their own. I have tested this on Xendesktop 7.1 and PS 4.5 running simultaneous…
#Citrix #XenApp #Citrix Scout #Citrix Insight Services #Microsoft VMMAP #Microsoft ADEXPLORE #Microsoft RAMMAP #Microsoft TCPVIEW #Microsoft AUTORUNS #Microsoft PROCESS EXPLORER #Microsoft PROCESS MONITOR
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.
Suggested Courses

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question