Citrix Gateway

Validating the Server Certificate During an SSL Handshake

The Citrix Gateway appliance can now be configured to validate the server certificate provided by the back-end server during an SSL handshake.

To configure Citrix Gateway global parameters to support PAC for outbound proxy by using the configuration utility

Bind the CA certificate

  1. Navigate toConfiguration>Citrix Gateway>Citrix Gateway Policy Manager>Certificate Bindings.**
  2. On theCertificate Bindingsscreen, click the+icon.
  3. On theCA Certificate(s) Bindingscreen, clickAdd Bindingand clickInstall.
  4. Select the certificate file name in theCertificate File Namefield and clickInstall.
  5. On theCA Certificate(s) Bindingscreen, select the certificate and clickBind.
  6. ClickDone.

Enabling the certificate validation:

  1. Navigate toCitrix Gateway> Global settings.
  2. ClickChange Global Settings.**
  3. SelectEnabledfrom theBackend Server Certificate Validationdrop-down menu and clickOK.

To configure Citrix Gateway global parameters to support server certificate with the command line

At the command prompt, type the following commands:

bind vpn global cacert DNPGCA1 set vpn parameter backendcertValidation ENABLED 
Validating the Server Certificate During an SSL Handshake

In this article