Automated certificate renewal for Citrix NetScaler ADC
NetScaler certificates are usually renewed in the GUI: upload, update the certkey, save - per appliance, per year. The NetScaler package does the same over the NITRO API from an agent inside your network.
package netscaler-target 2.0.0
deleteCertFileuploadCertFiledeleteKeyFileuploadKeyFilecheckCertKeyaddCertKeywhen configuredupdateCertKeywhen configuredsaveConfig
At a glance
- Package
netscaler-target 2.0.0- Compatibility
NetScaler ADC / Citrix ADC >=13.0 <15.0- Runs from
- Any Windows or Linux agent with network access to it
- Mechanism
- REST API
- Authentication
- Session login
- Capabilities
- Import certificate and keyRead inventoryActivate configuration
- Deployment steps
- deleteCertFile → uploadCertFile → deleteKeyFile → uploadKeyFile → checkCertKey → addCertKey* → updateCertKey* → saveConfig
- Rollback
- None
- Key usage
- Server authentication
* conditional step
What it does
An aethercert agent on your network logs in to the NetScaler management address with a NITRO session, uploads the renewed certificate and key to /nsconfig/ssl/, and either adds the sslcertkey object (first issue) or updates it in place (renewal). Finally it saves the running configuration.
Because renewals update the same sslcertkey, every virtual server it is bound to picks up the new certificate without being rebound.
How it runs
- 01
deleteCertFile / uploadCertFile
The previous certificate file is replaced through the NITRO systemfile API.
- 02
deleteKeyFile / uploadKeyFile
The private key file is replaced the same way.
- 03
checkCertKey
The package checks whether the sslcertkey object already exists.
- 04
addCertKey / updateCertKey
The certkey is added on first issue, or updated in place on renewal.
- 05
saveConfig
The running configuration is saved.
What you configure
- NITRO management host (NSIP) and port
- NITRO username and password (stored encrypted)
- sslcertkey name
- Certificate directory (default /nsconfig/ssl/)
- Whether to accept a self-signed management certificate
Prerequisites
- An agent with network access to the NetScaler management address
- A NITRO user allowed to manage system files and SSL certkeys
- Binding the certkey to SSL virtual servers once, on the appliance
Limitations
- The first binding of the certkey to a virtual server is done on the NetScaler; renewals keep it.
- Each appliance or HA pair address is its own deploy target.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Citrix and VMware
Documentation
Frequently asked questions
Citrix NetScaler ADC
Does the private key pass through aethercert's cloud?
No. The agent that generated the key uploads it directly to the NetScaler over NITRO, inside your network.
Which NetScaler versions are supported?
The package declares NetScaler ADC / Citrix ADC 13.0 up to (not including) 15.0.
Automate Citrix NetScaler ADC
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.