Link to home
Start Free TrialLog in
Avatar of maximus7569
maximus7569

asked on

Installing and SSL Cert on Citrix Xen App Server

We have a server running Server 2008 with Citrix Xen App 5 Fundamentals.  We let the SSL cert expire and now we are having issues accessing the applications on this server.

We renewed the SSL cert with Go Daddy and tried to install the cert on the server.  When you login and try to access an application we get this error: Unable to launch your application. Contact your help desk with the following information: Cannot connect to the Citrix XenApp server.SSL Error 61: You have not chosen to trust Go Daddy Secure Certificate Authority - G2, the issuer of the server's security certificate.

Is there somethign we have to do in Citrix side?  We setup cert in IIS7 and binded it to site but we still get that error.

Can somone assist as users are not able to access applications right now.

Thanks in advance!
Avatar of Sekar Chinnakannu
Sekar Chinnakannu
Flag of Singapore image

mostly you have to install the sub-ca at the server too.
check the cert and sub-cert are installed at the machine-context rather than user-context.
Just check with GoDaddy and obtain from them all root certificates \ intermediate certificates for the certificate chain and install those certificates on Citrix server 1st in appropriate certificate stores
Then go to certificate Properties \ certificate Path tab and check if you are able to view all  certification authorities and certificate status is OK

No matter from where you access Citrix App, root certificate of all certification authorities mentioned in certificate Chain (Certificate properties \ Certificate Path tab) must be installed on Citrix server and clients as well, otherwise you will receive errors
 
Mahesh
ASKER CERTIFIED SOLUTION
Avatar of Tony J
Tony J
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
If using a Mac OS device with Citrix, request SHA1 instead of SHA2 cert from GoDaddy.  ICA client from Citrix does not support SHA2 at this time.

http://discussions.citrix.com/topic/351459-is-there-a-fix-yet-for-ctx136348-%E2%80%9Cconnection-error-citrix-receiver-could-not-establish-connection-with-the-remote-hostserver%E2%80%9D/