The Citrix License Server certificate is not in the Delivery Controller's trusted root store

book

Article ID: CTX235235

calendar_today

Updated On:

Description

License Server certificate not in the Delivery Controller's trusted root certificate store. This will impact Studio and Director managing and displaying information from the license server.

Resolution

To resolve this issue, add the License Server certificate to the trusted root store on the Delivery Controller.

For instructions, see [Adding certificates to the Trusted Root Certification Authorities store for a local computer] on the Microsoft web site.

For more information, see Citrix Documentation - Licensing


Note for Environments with Intermediate CAs

If your Citrix License Server certificate is issued by an Enterprise or Public CA that utilizes Intermediate CAs, Citrix Studio may still report that the certificate is untrusted, even if your Root and Intermediate chains are fully valid.

Due to a validation limitation, you must explicitly import the End-Entity (Leaf) Certificate into the Trusted Root store of the machine evaluating the connection.

Required Steps:

  1. Export the End-Entity (Leaf) certificate (the specific host certificate issued to your License Server) as a .cer or .pfx file.

  2. On the Delivery Controller(s) running Citrix Studio, open certlm.msc (Local Computer Certificate Store).

  3. Navigate to Trusted Root Certification Authorities > Certificates.

  4. Right-click and choose All Tasks > Import.

  5. Import the License Server's End-Entity certificate directly into this Root store.

  6. Restart the Citrix Studio console or reload the licensing node to force a validation refresh.

Issue/Introduction

License Server certificate not in the Delivery Controller's trusted root certificate store. This will impact Studio and Director managing and displaying information from the license server.