This message was deleted.
# citrix-netscaler
s
This message was deleted.
k
@John Billekens has a framework for this
k
But I think if this passes we'll start going towards LE certs
j
Thanks @Kees Baggerman, indeed I've written a script to automate this. I explained this in a Citrix blog a while ago: https://www.citrix.com/blogs/2019/06/24/why-certificates-are-more-important-today-than-ever/ if you have questions or suggestions, please let me know.
r
^---- This script rocks. Love it.
John's will also swap out the Storefront cert with the same LE cert
m
@John Billekens Do you know if this scripts works with Citrix Gateway VPX? This is the Gateway only VPX Edition, that's not really an ADC. If not, I would have to test that.
Here is the License view:
I searched a bit through the code, seems like there is already a solution for that, interesting.
r
yes, it works with gateway using LBVip
i've hounded him for enough features over the years. 😄
😁 1
j
It should work in many situations. I haven't added something to use certs in other partitions, although that is on my to do list. Important thing is that there need to be a http (80) vip answering from the internet on the ip resolved from the fqdn. Because the validation is dome via http not https. Normally cou can use a cs vip for that or a Load Balance vip using the same ip as the gateway.
If not, let me know
m
@Ryan Gallier You have a working example for a Gateway only license setup?
r
I do. Generally i have a gateway vserver, and an LBVip, on the same IP. The LBVip i use as an 80 to 443 redirect. The script can piggie back on that.
❤️ 1
first I create an API user
.\GenLeCertForNS.ps1 -CreateUserPermissions -CreateApiUser -LBVipName "LAB-HTTP-to-HTTPS-Redirect" -ApiUsername "LAB-leuser" -ApiPassword "LEP@ssw0rd" -NSCPName "LABLePermissions" -NSUsername nsroot -NSPassword "nsroot" -ManagementURL "https://10.13.8.251" -SaveNSConfig
Then create the cert
.\GenLeCertForNS.ps1 -ConfigFile .\config.json -Username "LAB-leuser" -CN "gateway.fqdn.com" -EmailAddress "somedude@gmail.com" -PfxPassword "P@ssw0rd" -CertDir "C:\Certs" -ManagementURL "https://10.13.8.251" -UseLbVip -LbName "LAB_HTTPS_Redirect" -CertKeyNameToUpdate "gateway.fqdn.com" -DisableIPCheck -UpdateIIS -SaveADCConfig -Production
Then you just run it nightly with a script.
powershell.exe -executionpolicy bypass c:\scripts\GenLeCertForNS.ps1 -AutoRun -ConfigFile .\config.json -Production
m
That is just wonderful!
Will test that on a Gateway only VPX tomorrow! Thank you very much!
@Ryan Gallier @John Billekens Which "version" of the script should one use? 1. https://github.com/j81blog/GenLeCertForNS/blob/master/GenLeCertForNS.ps1 2. https://github.com/j81blog/GenLeCertForNS/blob/dev/GenLeCertForNS.ps1 3. https://github.com/j81blog/GenLeCertForNS/releases/latest I would guess and say nr 1. is the correct one to use in production?
2.15.0
m
Seems like Master and Dev Branch are the same (at the moment).
j
Yes currently both are the same 🙂
Sorry for my late replies, been very busy starting my own freelance consultant buissiness