Configuring SSL Relay on MetaFrame for Unix 1.1 using Versign Certificates
Configuring SSL Relay on MetaFrame for Unix 1.1 using Versign Certificates Configuring SSL Relay on MetaFrame for Unix 1.1 using Versign Certificates
Citrix states in their article: CTX845957
CTX845957 - Configuring SSL Relay on MetaFrame for Unix 1.1 using Versign Certificates
This document was published at: http://support.citrix.com/kb/entry.jspa?externalID=CTX845957
Document ID: CTX845957, Created on: Jan 17, 2002, Updated: Apr 23, 2003
Products: Citrix MetaFrame 1.1 for UNIX
This document lists the steps for configuring SSL Relay on MetaFrame for Unix 1.1 with Feature Release 1.
First, ensure that a Metaframe for Unix 1.1 Feature Release 1 license is installed and activated. Then follow these steps:
1. Login as the ctxssl user
2. cd /opt/CTXSssl/sbin
3. ctxcertreq citrix
This leads to interactive process where you enter the following:
CN - enter fully qualified domain name. Example: server.citrix.com
C - Country Code two letter. Example: US
ST - State. example: Florida (not the two-letter abbreviation)
L - Locality. You can leave this blank
O - Organization. Example: Citrix Systems
OU - Organization Unit. Example: Technical Support
4. A certificate request is generated and saved as citrix.req
5. Send the citrix.req certificate request file to Verisign via a web browser.
6. Versign processes the certificate request and issues a server certificate. You will recieve a email from Verisign with the issued certificate included as Base-64 encoded text. Copy and paste this block of text into a new text file. Save the file on your MetaFrame for UNIX server as /tmp//citrix.cer.
7. Login as ctxssl user
8. cd /opt/CTXSssl/sbin
9. ctxcertmgr -response /tmp/citrix.cer
10. Enter the database password which you set when requesting the certificate.
11. ctxsslcfg -add 443 -certificate citrix -forward add metaframe-server:1494 -forward add metaframe-server:80
12. Enter the certificate password.
13. ctxsrv start sslrelay
14. From the client, ensure that you can ping the MetaFrame for Unix server using its fully qualified domain name.
15. Connect to metaframe server using SSL+HTTPS by specifiying the fully qualified domain name.
16. Once connected, check the connection status to confirm that you are connected with 128-bit SSL.
User login
Who's new
- japhabept
- Rullydery
- eagenorce
- rittaarier
- swasseZex