Automated certificate renewal for Citrix StoreFront
StoreFront serves its stores through IIS, so its certificate lives in an IIS HTTPS binding. The StoreFront package renews it there, verifies the binding and restores the previous one if something goes wrong.
package citrix-storefront-target 3.0.0
importensureBindingassignBindingverifyBindingcleanupwhen configured
At a glance
- Package
citrix-storefront-target 3.0.0- Compatibility
StoreFront >=3.0 <2600.0- Runs from
- A Windows agent on the server
- Mechanism
- PowerShell
- Authentication
- Local - no remote login
- Capabilities
- Import certificate and keyCreate bindingUpdate bindingVerify deploymentRemove old certificate
- Deployment steps
- import → ensureBinding → assignBinding → verifyBinding → cleanup*
- Rollback
- Defined by the package
- Key usage
- Server authentication
* conditional step
What it does
The agent on the StoreFront server imports the certificate into the machine store, ensures the HTTPS binding exists on the StoreFront IIS site and switches it to the new certificate.
A verification step confirms the binding; on failure, a rollback restores the previous binding so StoreFront keeps serving.
How it runs
- 01
import
Certificate and key are imported into the machine store.
- 02
ensureBinding / assignBinding
The IIS HTTPS binding is created if needed and switched to the new certificate.
- 03
verifyBinding
The binding is checked to reference the new certificate.
- 04
cleanup
The previous certificate is removed, if enabled.
What you configure
- IIS site name (default: Default Web Site)
- Binding host name and port
- Certificate store, friendly name and clean-up
Prerequisites
- A Windows agent on each StoreFront server
- A certificate for the store's base URL
Limitations
- Each StoreFront server in a server group runs its own deploy target.
Doing it by hand
The documentation has a step-by-step guide for replacing this certificate manually - useful for a first install, or to see exactly what the package automates.
Related features
Solutions
More in Citrix and VMware
Documentation
Automate Citrix StoreFront
Enroll an agent, attach the package, and the next renewal installs itself.
Community plan, no card required. Open registration - your account is ready in a few minutes.