Solved

Installing and SSL Cert on Citrix Xen App Server

Posted on 2014-01-07
5
19,684 Views
1 Endorsement
Last Modified: 2014-07-25
We have a server running Server 2008 with Citrix Xen App 5 Fundamentals.  We let the SSL cert expire and now we are having issues accessing the applications on this server.

We renewed the SSL cert with Go Daddy and tried to install the cert on the server.  When you login and try to access an application we get this error: Unable to launch your application. Contact your help desk with the following information: Cannot connect to the Citrix XenApp server.SSL Error 61: You have not chosen to trust Go Daddy Secure Certificate Authority - G2, the issuer of the server's security certificate.

Is there somethign we have to do in Citrix side?  We setup cert in IIS7 and binded it to site but we still get that error.

Can somone assist as users are not able to access applications right now.

Thanks in advance!
1
Comment
Question by:maximus7569
5 Comments
 
LVL 25

Expert Comment

by:Sekar Chinnakannu
ID: 39764392
0
 
LVL 23

Expert Comment

by:Dirk Kotte
ID: 39764409
mostly you have to install the sub-ca at the server too.
check the cert and sub-cert are installed at the machine-context rather than user-context.
0
 
LVL 36

Expert Comment

by:Mahesh
ID: 39764504
Just check with GoDaddy and obtain from them all root certificates \ intermediate certificates for the certificate chain and install those certificates on Citrix server 1st in appropriate certificate stores
Then go to certificate Properties \ certificate Path tab and check if you are able to view all  certification authorities and certificate status is OK

No matter from where you access Citrix App, root certificate of all certification authorities mentioned in certificate Chain (Certificate properties \ Certificate Path tab) must be installed on Citrix server and clients as well, otherwise you will receive errors
 
Mahesh
0
 
LVL 25

Accepted Solution

by:
Tony Johncock earned 500 total points
ID: 39764518
Go here: https://certs.godaddy.com/anonymous/repository.pki

Download the "Go Daddy Class 2 Certification Authority Root Certificate" and the "Go Daddy Secure Server Certificate (Intermediate Certificate)"

Install those onto the Citrix Server.

You may find, depending on the ages of the clients and their IE/OS versions you might have to do the same on them.
0
 
LVL 2

Expert Comment

by:firstcall
ID: 40220260
If using a Mac OS device with Citrix, request SHA1 instead of SHA2 cert from GoDaddy.  ICA client from Citrix does not support SHA2 at this time.

http://discussions.citrix.com/topic/351459-is-there-a-fix-yet-for-ctx136348-%E2%80%9Cconnection-error-citrix-receiver-could-not-establish-connection-with-the-remote-hostserver%E2%80%9D/
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

If you are a web developer, you would be aware of the <iframe> tag in HTML. The <iframe> stands for inline frame and is used to embed another document within the current HTML document. The embedded document could be even another website.
Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question