Create a certificate signing request
Create a CSR by using the NetScaler Gateway wizard
-
In the configuration utility, click the Configuration tab and then in the navigation pane, click NetScaler Gateway.
-
In the details pane, under Getting Started, click NetScaler Gateway wizard.
-
Follow the directions in the wizard until you come to the Specify a server certificate page.
-
Click Create a Certificate Signing Request and complete the fields. Note: The fully qualified domain name (FQDN) does not need to be the same as the NetScaler Gateway host name. The FQDN is used for user logon.
-
Click Create to save the certificate on your computer, and then click Close.
-
Exit the NetScaler Gateway wizard without saving your settings.
Create a CSRÂ by using the NetScaler GUI
-
Navigate to Traffic Management > SSL > SSL Files and select Create Certificate Signing Request (CSR).
-
Complete the settings for the certificate and then click Create.
Install the signed certificate on NetScaler Gateway
Pair the signed certificate with a private key by using the GUI
-
Copy the certificate to NetScaler Gateway to the folder nsconfig/ssl by using a Secure Shell (SSH) program such as WinSCP.
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand SSL > Certificates.
-
In the SSL Certificate page, click Get Started.
-
In the details pane, click Install.
-
In Certificate-Key Pair Name, type the name of the certificate.
-
In Certificate File Name, click Appliance.
-
Navigate to the certificate, click Select, and then click Open.
-
In Key File Name, click Appliance. The name of the private key is the same name as the Certificate Signing Request (CSR). The private key is located on NetScaler Gateway in the directory \\nsconfig\\ssl.
-
Choose the private key, and then click Open.
-
If the certificate is PEM-format, in Password, type the password for the private key.
-
If you want to configure notification for when the certificate expires, select Notify When Expires.
-
In Notification Period, type the number of days, click Create, and then click Close.
Bind the certificate and private key to a virtual server by using the GUI
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Virtual Servers.
-
In the details pane, click a virtual server, and then click Open.
-
On the Certificates tab, under Available, select a certificate, click Add, and then click OK.
Bind the certificate and private key to a virtual server by using the CLI
bind ssl vserver <vServerName> -certkeyName <string> -ocspCheck ( Mandatory | Optional )
bind ssl vserver TestClient -CertkeyName ag51.xm.nsi.test.com -CA -ocspCheck Mandatory
Unbind test certificates from the virtual server by using the GUI
-
In the configuration utility, on the Configuration tab, in the navigation pane, expand NetScaler Gateway > Virtual Servers.
-
In the details pane, click a virtual server, and then click Open.
-
On the Certificates tab, under Configured, select the test certificate, and then click Remove.