Error: "Internal failure in SSL cert/key generation tool" When Importing PCKS12 Certificate on NetScaler Appliance

Error: "Internal failure in SSL cert/key generation tool" When Importing PCKS12 Certificate on NetScaler Appliance

book

Article ID: CTX135439

calendar_today

Updated On:

Description

When importing PCKS12 certificate on a NetScaler or Access Gateway Enterprise Edition appliance, the following error message is displayed.
“Internal failure in SSL cert/key generation tool”
User-added image

Resolution

To avoid this issue, type the correct password in the Import Password field when importing PCKS12 certificate on a NetScaler appliance.
User-added image

Note: this issue may also happen if your password contains a $ character

Problem Cause

This issue occurs because the user has typed an incorrect password for the Import Password field when importing PCKS12 certificate on an NetScaler appliance.

The NetScaler appliance does not recognize the incorrect password and displays this error because the Microsoft IIS server has generated the PCKS12 certificate.

If you reproduce the same scenario using a certificate where the NetScaler appliance generated the Certificate Signing Request (CSR), the error message “Invalid Password” appears:

User-added image

User-added image

Issue/Introduction

When importing PCKS12 certificate on a NetScaler or Access Gateway Enterprise Edition appliance the error message “Internal failure in SSL cert/key generation tool” appears. This article contains resolution for this issue.

Additional Information

CTX120668 - How to Export Certificates used on NetScaler as a pfx File