Citrix NetScaler
Manages certificates in Citrix NetScaler SSL certkeys. Created automatically via NetScaler Discovery.
How it's created
NetScaler Stores are automatically provisioned during Discovery when the Create Stores automatically option is enabled. Each SSL certkey found becomes a Store in the CLM.
Store details
| Card | Description |
|---|---|
| Total | Total certificates in the certkey |
| Expiring | Certificates nearing expiration |
Citrix NetScaler Integration Section (Read-only) — displays the data collected during discovery: NetScaler integration, host (NSIP), linked agent, and SSL type. To change the host or credentials, edit the source integration in Integrations → Load Balancers → NetScaler.
SSLCertKey on NetScaler Section (Read-only) — displays partition, certkey name, cert path, and key path.
Certificate Chain (Bundle) — editable toggle:
- Active: the deploy sends the intermediate CA chain to NetScaler as a separate sslcertkey and links it to the main certkey via
action=link - Inactive: no link is created and only the leaf certificate is presented during the TLS handshake
Current Certificate — displays common name, issuer, validity, and thumbprint of the currently installed certificate.
Bindings on NetScaler — lists where the certkey is bound:
- LB Virtual Servers
- CS Virtual Servers
- SSL Services
- SSL Service Groups
Installed Certificates — lists all certificates installed on the store with issuer, issuance date, validity, bind status, and the result of the last deploy. Click View history to see the full log of past deploys.
Install a certificate
On the details screen, click Install Certificate, select the certificate from the inventory, and confirm. The CLM performs the deploy to the certkey via the linked agent.