Solved

Uploaded new SSL cert now CSG won't start

Posted on 2012-03-26
8
1,626 Views
Last Modified: 2012-04-10
Hi,
My client's Citrix SSL certificate expired this weekend. I created a new one from StartSSL and I imported it into the Certificate folder successfully but when I went into QuickStart and tried to apply it at the External Access. Citrix went through the wizard but threw an error at the end saying that the certificate had been deleted which it really wasn't. I clicked ok at that prompt and the wizard then disabled external access. Now the Secure gateway service will not start and when I click through the Secure gateway configuration it tells me that it can't find the STA server.

Can anyone help? The particulars of the server are listed below. Thanks!

Windows 2008 R2
Citrix XenApp 6 Fundamentals build: 6.0.36399.0
Secure Gateway 3.2
0
Comment
Question by:blkfoot
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
8 Comments
 
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771472
run secure-gateway diagnostics.
What's the result?
0
 

Author Comment

by:blkfoot
ID: 37771499
I'm not able to run the Secure Gateway Diagnostics because the Secure Gateway isn't configured but I can't configure the Secure Gateway because it can't find the STA.
0
 
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771569
your STA runns on the same or different server?
which port you use to contact the STA?
Are the STA-call SSL protected?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 

Author Comment

by:blkfoot
ID: 37771630
The STA runs on the same server.  I'm not sure how tell which port I use.  The default website is set to 80 and the Citrix site that was created during the install is 8080.  I have tried appending both ports to the FQDN but it still fails.  The Secure Gateway service will not start either i assume because of this.

Sorry, I don't have much of a Citrix background so if there is something I should look at let me know.
0
 
LVL 24

Expert Comment

by:Dirk Kotte
ID: 37771679
the STA should run within you IIS default webpage.
you can use the IP 127.0.0.1 as URL (or 127.0.0.1:8080)
 
if you configure the STA within CSG-Config you should see the STA-ID.

if you only change the certificate within CSG - why are the old config are lost?
0
 

Author Comment

by:blkfoot
ID: 37771714
I did try and use the IP address and appended the port with it for the URL and it still won't find the STA.  

I cannot find the STA ID because I can't configure CSG.

I don't understand why the old config was lost either other than when I tried to update the cert from the QuickStart interface it wouldn't accept it and then disabled the External Access.

I am ordering a new cert so i am hoping this will solve the problem.

When I look in the logs for the Secure gateway this is what I see:
[Mon Mar 26 15:05:02 2012] Unable to load SSL Certificate for server citrix.erckhotels.com:443 [hint: SSLCertificateHash]
0
 

Accepted Solution

by:
blkfoot earned 0 total points
ID: 37813548
The customer has decided to uninstall Citrix and move to MS Remote Desktop Services.
0
 

Author Closing Comment

by:blkfoot
ID: 37826795
No solution was found so the customer decided to go a different way.
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Policies #XenDesktop #VDI #POC #Citrix Univeral Printer Driver #Citrix UPD
ADCs have gained traction within the last decade, largely due to increased demand for legacy load balancing appliances to handle more advanced application delivery requirements and improve application performance.
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…
This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question