Storefront to connector https communication fails after updating Server Certificate on Connector

book

Article ID: CTX695964

calendar_today

Updated On:

Description

Storefront to connector comms fails if the server certificate on the connector is replaced.

In the system event logs we can see event id 15021.

When we review the service monitor on Netscaler to verify https communication with the connector we can see the status is down.

The customer has configured HTTPS communication with the connector as per: 

https://docs.citrix.com/en-us/citrix-cloud/citrix-cloud-resource-locations/citrix-cloud-connector/installation.html#https-configuration

 

 

Environment

Citrix is not responsible for and does not endorse or accept any responsibility for the contents or your use of these third party Web sites. Citrix is providing these links to you only as a convenience, and the inclusion of any link does not imply endorsement by Citrix of the linked Web site. It is your responsibility to take precautions to ensure that whatever Web site you use is free of viruses or other harmful items.

Cause

Binding is no longer valid as it refers to a cert that no longer exists on the Connector

Resolution

Queried broker specific appids on connector:

Get-WmiObject -Class Win32_Product | Select-String -Pattern "broker"

 

Removed binding:

Netsh http delete sslcert [ipport=]IP Address:port

Ref: https://learn.microsoft.com/en-us/windows/win32/http/delete-sslcert

 

Added binding back using known Appid from Get-WMIObject command above:

netsh http add sslcert ipport=<IP address>:<Port number> certhash=<Certificate thumbprint> appid={Any GUID}

 

Issue/Introduction

After updating the Server certificate on a connector, Storefront is no longer able to reach the connector over HTTPS