The following instructions will guide you through the SSL installation process on a Citrix Access Gateway 5.0 Server. If you have more than one server or device, you will need to install the certificate on each server or device you need to secure. If you still have not generated your certificate and completed the validation process, reference our CSR Generation Instructions and disregard the steps below.

What You'll Need

1. Your server certificate

This is the certificate you received from the CA for your domain. You may have been sent this via email. If not, you can download it by visiting your Account Dashboard and clicking on your order.

2. Your intermediate certificates

These files allow the devices connecting to your server to identify the issuing CA. There may be more than one of these certificates. If you got your certificate in a ZIP folder, it should also contain the Intermediate certificate(s), which is sometimes referred to as a CA Bundle. If not, download the appropriate CA Bundle for your certificate.

3. Your private key

This file should be on your server, or in your possession if you generated your CSR from a free generator tool. On certain platforms, such as Microsoft IIS, the private key is not immediately visible to you but the server is keeping track of it.

Installation Instructions

Installing a Server Certificate

1. In the Access Gateway Management Console, click the Certificates

Access Gateway Management Console

2. Click Import and then select Server (.pem) to import a CA signed root certificate

 

3. Find the certificate, select it, click Open

 

4. Specify a Private Key Password

 

5. The certificate is now successfully installed

 

Installing an Intermediate CA Certificate

1. In the Access Gateway Management Console, click the Certificates

click the Certificates

2. Click Import and then select Server (.pem) to import a CA signed root certificate.

 

3. Find the certificate, select it, click Open.

 

4. Congratulations, your Intermediate is now successfully installed.

 

Activating the SSL Server Certificate

1. In the Access Gateway Management Console, click the Certificates tab.

2. In the Certificates tab, choose the certificate you’d like to activate and then click Make Active.

3. A green checkmark should indicate successful activation.

 

Congratulations! You’ve successfully installed your SSL certificate! To check your work, visit the website in your browser at https://yourdomain.tld and view the certificate/site information to see if HTTPS/SSL is working properly. Remember, you may need to restart your server for changes to take effect.