Solved

Netscaler Gateway Licensing

Posted on 2013-12-08
9
1,457 Views
Last Modified: 2016-10-25
I've got about 10 hours now into trying to move from the Citrix Secure Gateway product over to StoreFront 2.1 and Netscaler Gateway.  I've run into a lot of challenges, but where I am absolutely stuck is through the process of installing an SSL certificate on the ESXi based Netscaler Gateway Appliance.  I get this error when attempting to pair the cert and key:

"Certificate with key size greater than RSA512 or DSA512 bits not supported"

Like I said, I've been troubleshooting this for quite a while.  Google searching says that my Netscaler license is borked..  I've reallocated it multiple times using the hostname of the device as well as the MAC.  I even went as far as to implement a trial license in the hope that my "actual" license wasn't compatible for some reason.  Same problem.

I am running Netscaler Gateway version 10.1 build: 120.1316, Trying to install a GoDaddy standard single domain SSL.
0
Comment
Question by:4roi
  • 4
  • 3
  • 2
9 Comments
 
LVL 30

Expert Comment

by:Britt Thompson
ID: 39704547
When you generate your cert request from the netscaler use a 2048 level of encryption. It sounds like you may not have generated the csr from the netscaler so it's not accepting the cert.
0
 

Author Comment

by:4roi
ID: 39704640
Sorry, not the issue.  I did generate the Netscaler as well as specify 2048 bit.  The error message indicates that the device doesn't support anything greater that 512 bit which is incorrect.  Google indicates this might be a licensing issue, but I think you'll find above that I ruled that out.

I also tried issuing the cert to a Windows server then exporting the PFX.  Converted the PFX to PEM and get the same error when attempting to pair the keys.  Fun....
0
 
LVL 23

Expert Comment

by:Dirk Kotte
ID: 39704646
this appearance (no certs with more than 513 bit) i have with missing license only.
after installing your license or the trial license at the netscaler take a look to configuration/system/licenses.  You shoud see licenses for "Netscaler Gateway".
post a screenshot if there are obscurities.
0
Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

 
LVL 30

Expert Comment

by:Britt Thompson
ID: 39704649
Weird. I've spent my fair share of time rotting in front of a netscaler and can understand your frustration.

Have you tried a trial license to see if that generated different results?
0
 

Author Comment

by:4roi
ID: 39704655
Yep, tried provisioning a trial license too...  Ah!  Completely frustrating.  It's making WI and CSG look really attractive again..  Geez...
0
 
LVL 30

Expert Comment

by:Britt Thompson
ID: 39704663
Is it possible you're using a feature that's not covered by the license you're using?
0
 
LVL 23

Expert Comment

by:Dirk Kotte
ID: 39720873
do you have applied the latest fixes?
please post a screenshot of the ns licensing page.
0
 

Accepted Solution

by:
4roi earned 0 total points
ID: 39722926
So I ended up calling support on this one.  Turns out that you actually need two different licenses.  A base license AND an end user license for each SSL VPN session.  I had only installed the end user license, thus I experienced the issue.  The funny thing was that support didn't know exactly what license I should be using.  As a reseller, installing this new "Netscaler Gateway" product, they couldn't tell me if the older CAG appliance licenses I had access to would actually function.  Because the Netscaler Gateway product replaces CAG, I assumed they would, but support couldn't confirm.  It wasn't until we provisioned both the CAG appliance end user license and base license using the "host name" that it actually worked.  The support person I spoke with was actually surprised.  Lol.

Another interesting twist is that when I provisioned the "trail" license for Netscaler Gateway, they didn't give me a base license!!  So, even the trial license would have never functioned.  Thanks Citrix.  Made this one real easy.  Guess they like to hear from everyone that needs to install one.  Makes them feel closer to the customers I think...  Yikes.
0
 

Author Closing Comment

by:4roi
ID: 39733419
Solved my own problem.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
User Being Logged Out of AD 6 65
GPO not being applied to Win7 Pro Image 5 47
Extend AD schema for SCCM 2012 3 26
check which file take most of the disk space 16 36
Citrix policies are the most efficient method to configure and tune XenDesktop environments, allowing organizations to control connection, security and bandwidth settings based on various combinations of users, devices or connection types.  Citrix …
If your vDisk VHD file gets deleted from the image store accidentally or on purpose, you won't be able to remove the vDisk from the PVS console. There is a known workaround that is solid.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
How to install and configure Citrix XenApp 6.5 - Part 1. In this video tutorial we have explained step by step installation of Citrix XenApp 6.5 Server on Windows Server 2008 R2 is explained in this video. We have explained the difference between…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question