Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win


Uploaded new SSL cert now CSG won't start

Posted on 2012-03-26
Medium Priority
Last Modified: 2012-04-10
My client's Citrix SSL certificate expired this weekend. I created a new one from StartSSL and I imported it into the Certificate folder successfully but when I went into QuickStart and tried to apply it at the External Access. Citrix went through the wizard but threw an error at the end saying that the certificate had been deleted which it really wasn't. I clicked ok at that prompt and the wizard then disabled external access. Now the Secure gateway service will not start and when I click through the Secure gateway configuration it tells me that it can't find the STA server.

Can anyone help? The particulars of the server are listed below. Thanks!

Windows 2008 R2
Citrix XenApp 6 Fundamentals build: 6.0.36399.0
Secure Gateway 3.2
Question by:blkfoot
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771472
run secure-gateway diagnostics.
What's the result?

Author Comment

ID: 37771499
I'm not able to run the Secure Gateway Diagnostics because the Secure Gateway isn't configured but I can't configure the Secure Gateway because it can't find the STA.
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771569
your STA runns on the same or different server?
which port you use to contact the STA?
Are the STA-call SSL protected?
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.


Author Comment

ID: 37771630
The STA runs on the same server.  I'm not sure how tell which port I use.  The default website is set to 80 and the Citrix site that was created during the install is 8080.  I have tried appending both ports to the FQDN but it still fails.  The Secure Gateway service will not start either i assume because of this.

Sorry, I don't have much of a Citrix background so if there is something I should look at let me know.
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771679
the STA should run within you IIS default webpage.
you can use the IP as URL (or
if you configure the STA within CSG-Config you should see the STA-ID.

if you only change the certificate within CSG - why are the old config are lost?

Author Comment

ID: 37771714
I did try and use the IP address and appended the port with it for the URL and it still won't find the STA.  

I cannot find the STA ID because I can't configure CSG.

I don't understand why the old config was lost either other than when I tried to update the cert from the QuickStart interface it wouldn't accept it and then disabled the External Access.

I am ordering a new cert so i am hoping this will solve the problem.

When I look in the logs for the Secure gateway this is what I see:
[Mon Mar 26 15:05:02 2012] Unable to load SSL Certificate for server citrix.erckhotels.com:443 [hint: SSLCertificateHash]

Accepted Solution

blkfoot earned 0 total points
ID: 37813548
The customer has decided to uninstall Citrix and move to MS Remote Desktop Services.

Author Closing Comment

ID: 37826795
No solution was found so the customer decided to go a different way.

Featured Post

 [eBook] Windows Nano Server

Download this FREE eBook and learn all you need to get started with Windows Nano Server, including deployment options, remote management
and troubleshooting tips and tricks

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If your vDisk VHD file gets deleted from the image store accidentally or on purpose, you won't be able to remove the vDisk from the PVS console. There is a known workaround that is solid.
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

618 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question