Manual generation of the App Layering agent self-signed certificate

Manual generation of the App Layering agent self-signed certificate

book

Article ID: CTX266977

calendar_today

Updated On:

Description

Replace the self signed certificate which expires 2 years post agent installation.


Instructions

1) Login to the host with the agent reporting the expiration of the certificate

2) Open the command prompt as administrator

3) Enter and execute - C:\Program Files (x86)\Citrix\Agent\Citrix.AppLayering.Agent.Service.exe" addcert -port=8016 -force
     NOTE: If the port was altered, as part of the agent installation, replace 8016 with the correct port number.
     To determine if the port was changed review the registry entry,

     HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Citrix.AppLayering.Agent\Parameters:ListeningPort


Alternate method:

Uninstall, reinstall the agent in the host then manually re-register with ELM, following the steps in the below doc,

https://docs.citrix.com/en-us/citrix-app-layering/4/install-agent.html

 

Additional Information

A warning message similar to the below may be seen:

"Priority: High (Impact: Individual, Urgency: High)
Classification: Infrastructure Services, Server, Report an Issue
 
Description:
Event  can not be resolved by the NOC and must be escalated. Please contact the NOC for additional information.
 
Event Error Message: Resolution state: New Source: Cert CN=UnideskAgent, O=Unidesk Corporation Alert: Certificate lifespan alert 
 
Auto-created via rule: [SCOM] Catch-All
 
Alert: Certificate lifespan alert
Source: Cert CN=UnideskAgent, O=Unidesk Corporation
Path: [CustPVS_HostName]-INT.ORG;My
Last modified by: System
Last modified time: 11/25/2019 6:53:57 PM
Alert description: The certificate expires in 21 days on 12/18/2019 00:00:00 UTC.
Certificate Subject: CN=UnideskAgent, O=Unidesk Corporation
Certificate Issuer: CN=Unidesk Agent Temporary Authority, O=Unidesk Corporation
Serial number: 22C46BDE814CD3AD
Store Name: Personal
 
Store Key: My
Store Provider: SystemRegistry
Store Type: LocalMachine
Monitoring User: NT AUTHORITY\SYSTEM
 
Chain Time Details:
 
 
 
 
"This message is intended for the use of the person or entity to which it is addressed and may contain information that is confidential or privileged, the disclosure of which is governed by applicable law. If the reader of this message is not the intended recipient, you are hereby notified that any dissemination, distribution, or copying of this information is strictly prohibited. If you have received this message by error, please notify us immediately and destroy the related message.""