This message was deleted.
# citrix-vad
s
This message was deleted.
l
If it's not external you don't really need to anything mate. It's integrated to AD, that being said you may need CRL checks when the CAs are offline. You can load balance the files, replicate them to a web service and then load balance them. Add that web location onto the CRL location on the CA.
c
Yeah as Leee you need to move the CRL/AIA to load balanced IIS servers here is a guide i have used in past https://www.sysadmins.lv/retired-msft-blogs/xdot509/installing-a-two-tier-pki-hierarc[…]high-availability-for-the-http-aia-and-cdp-repositories.aspx
I had a similar issue here who ever set it up had the CRL/AIA on the single suborbinate CA so anytime it was down FAS stopped working
if you run pkiview will show you the current CRL/AIA locations
l
It's generally really simple. You can choose the regularity of the CRL publication too. Personally I like to find a couple of webservers you can add a folder to, load balance them with an internal DNS entry (make it HTTPS if you want to publish externally) and you are good. Your CAs can then go down (root CA can actually be turned off unless signing anything) and everything will plod along nicely.
j
Cheers lads, I set it up for the customer in question ages ago.. the had an expiry on the CRL (theyre fault) but when I was helping them it made me think the only ref point is the root > online intermediate..
I said I would get it fixed .... here we are 🙂
l
Nice one John, just drop me a DM if you need a hand.
🍻 1
j
So at present.. if the intermediate location goes offline.. external access is down... regardless of having 2 fas per location..
It just needs to be HTTP... I was thinking of deploying the CA Web enrolment feature on each FAS server and adding the local target/location CRL/AIA to each and copying the files down.. would that work or does it need to be the same/load balanced? The thinking being each FAS server has itself to query, cheers
But I reckon the config (CRL/AIA) and LB URL needs to be set on the root?
l
Nothing wrong with hosting IIS on the FAS servers and load balancing that. Just bear in mind, you want to copy the root, intermediate and each FAS servers CRLs to that location to make it truly resilient.
Needs to be set on each CA.
j
Cool.. do I need to LB if each FAS server uses itself? Like a URL pointing to its local web share? ta
l
Well, yes because the issue is the intermediate right? Your intermediate needs it's CRL also stored there. Same for the Root CA too.
The FAS chain needs to be able to be validated all the way along.
j
Got it.. this PKI infra does a load of other stuff.. I was trying to get away with only creating a new CRL/AIA for Citrix connectivity, that might not be possible..
l
No mate not really. Not unless your FAS servers are their own CAs (which I'm actually a fan of for this very reason). Usually CAs internally are not well managed and poorly configured leading to knock on issues.
But... You can add an additional CRL location without changing the config you currently have in place. They are looped through one after the other so you won't impact anything.
j
Cool.. yeah they are SubCAs..
Ahh ok, think that might work then.. and just leave the customer to sort out their other services if they wish to do so..
l
Exactly. But you'll be making their solution more resilient also.
j
That sounds the least path of resistance.. add the additional URL to only the SubCAs doing Citrix..
l
Sorry John, no. You'll need the additional URL on the root CA, intermediate CA and FAS CAs to do it properly and make it bullet proof. But otherwise yes, you can do it this way.
c
The offline root CA normally just has the local certenroll path and you add your load balanced web server to the CDP/AIA extensions. You publish the CRL from the Root CA and then copy it from the cert enroll folder on the root CA to web server
👍 1
l
Spot on, because the CRL shouldn't really change if it's not signing new Intermediates.
c
yeah i norm set it to publish a new CRL every 5 years so i have to power it on every 5 years and publish a new CRL and copy the new files
👍 1
j
Nice one - cheers for taking the time lads 🙂
👍 1
o
Great thread! Lots of good ideas for the next time I have to do FAS with a customer
👍🏻 1