aethercert
Citrix and VMware

Automated certificate renewal for Citrix NetScaler ADC

NetScaler certificates are usually renewed in the GUI: upload, update the certkey, save - per appliance, per year. The NetScaler package does the same over the NITRO API from an agent inside your network.

The deployment steps defined in this package's manifest.

At a glance

Package
netscaler-target 2.0.0
Compatibility
NetScaler ADC / Citrix ADC >=13.0 <15.0
Runs from
Any Windows or Linux agent with network access to it
Mechanism
REST API
Authentication
Session login
Capabilities
Import certificate and keyRead inventoryActivate configuration
Deployment steps
deleteCertFile → uploadCertFile → deleteKeyFile → uploadKeyFile → checkCertKey → addCertKey* → updateCertKey* → saveConfig
Rollback
None
Key usage
Server authentication

* conditional step

What it does

An aethercert agent on your network logs in to the NetScaler management address with a NITRO session, uploads the renewed certificate and key to /nsconfig/ssl/, and either adds the sslcertkey object (first issue) or updates it in place (renewal). Finally it saves the running configuration.

Because renewals update the same sslcertkey, every virtual server it is bound to picks up the new certificate without being rebound.

How it runs

  1. 01

    deleteCertFile / uploadCertFile

    The previous certificate file is replaced through the NITRO systemfile API.

  2. 02

    deleteKeyFile / uploadKeyFile

    The private key file is replaced the same way.

  3. 03

    checkCertKey

    The package checks whether the sslcertkey object already exists.

  4. 04

    addCertKey / updateCertKey

    The certkey is added on first issue, or updated in place on renewal.

  5. 05

    saveConfig

    The running configuration is saved.

What you configure

  • NITRO management host (NSIP) and port
  • NITRO username and password (stored encrypted)
  • sslcertkey name
  • Certificate directory (default /nsconfig/ssl/)
  • Whether to accept a self-signed management certificate

Prerequisites

  • An agent with network access to the NetScaler management address
  • A NITRO user allowed to manage system files and SSL certkeys
  • Binding the certkey to SSL virtual servers once, on the appliance

Limitations

  • The first binding of the certkey to a virtual server is done on the NetScaler; renewals keep it.
  • Each appliance or HA pair address is its own deploy target.

Doing it by hand

The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.

Manual replacement guide

Frequently asked questions

Citrix NetScaler ADC

Does the private key pass through aethercert's cloud?

No. The agent that generated the key uploads it directly to the NetScaler over NITRO, inside your network.

Which NetScaler versions are supported?

The package declares NetScaler ADC / Citrix ADC 13.0 up to (not including) 15.0.

Automate Citrix NetScaler ADC

Enroll an agent, attach the package, and the next renewal installs itself.

Community plan, no card required. Open registration - your account is ready in a few minutes.