[x]

Site Alert(s):

  • Server maintenance Saturday Nov 22, 2008, 12:00 PM - 3:00 PM. The Knowledge Center will be unavailable during this time.
Rate this Article:
You must be signed in to rate again
Article Feedback Print View
Alternate Languages: N/A

Exporting Root Certificates for the ICA Client for Macintosh on OS X 10.4 Tiger

Document ID: CTX108800   /   Created On: Feb 17, 2006   /   Updated On: May 21, 2008
Average Rating: 3

Symptoms

When connecting to Secure Gateway from a Macintosh with the native ICA Client, you receive an error message stating that the certificate is not trusted

Example:

"SSL Error 61: You have not chosen to trust 'verisign class 3 secure server CA', the issuer of the server's security certificate. Error #: 183")

Cause

The certificate for the Secure Gateway server is not one of the certificates that is included with the Macintosh Client for OS X. See CTX101702 – List of default public root certificates shipped with the Citrix MAC client. for included certificates.

Resolution

On OS X 10.4 (Tiger), it may be possible to export the certificate from the Macintosh Keychain utility.

1. Open the Keychain Access in the Applications > Utilities folder:

2. Highlight the X509Anchors Keychain in the menu (you may need to authenticate to do this).

3. Browse through the Certificate Authorities to find the one that has issued the certificate being used by the Secure Gateway – for this example, Thawte Premium Server CA:

4. Highlight the certificate and select File > Export from the menu bar:

5. The default File Format should be Certificate (.cer)

Note: You may need to rename the certificate to a .CRT extension for the client to properly identify the certificate.

6. Save the certificate to the ICA Client\keystore\cacerts folder (create this folder if it does not exist):


This document applies to:

Search
Knowledge Center
XenApp
XenApp Plugins (Clients)
XenServer
XenDesktop
NetScaler Application Delivery
Access Gateway
EdgeSight
Provisioning Server
WANScaler
Password Manager
Does it work with Citrix? Verify it - introducing the new Citrix Ready Community Verified