Monday, 7 February 2011

Migrating Citrix Secure Gateway Certificates to Access Gateway

This Citrix article CTX113627 details a possible process to migrate your Certificates from Citrix Secure Gateway to Access Gateway. It Also details the process to create a new Certificate request and add this to the Access Gateway

Heres a basic run down on the process.

Option 1 - To Export your current Certificate as a PKCS#12
Basically get the certificate up in the MMC snap in and right click and Export. As long as you get the option
to export with the private Key you should be ok. As you need to put both the private and public keys onto the Access Gateway.

Option 2 - Make a nice new Certificate Key Pair
AG - SSL Settings - Make a RSA request which makes you a new Private key file (.KEY)
AG - SSL Settings - Make a Certificate Request to make a request file (.REQ)
Windows - Use Something like WINSCP to get the REQ file off the Access Gateway and onto your PC.
Windows - Connect to CA webpage and copy the contents of the REQ file into the CA request form.
Windows - Through the CA console Issue the the Certificate
Windows - Connect to Licence Webpage and download the Certificate making sure to select (BASE 64)
Windows  Use something like WINSCP to upload the .CER file to the Access Gateway
AG - SSL settings - Add new Certficate - Combine the .CER and the .KEY from earlier to create a Certificate Key Pair
AG - Access Gateway - Virtual Server - Attatch the Certifcate to the AG Vserver
Windows - Ensure Client devices have the CA as trusted root authority.

The Citrix Full Article
http://support.citrix.com/article/CTX113627

No comments:

Post a Comment