Citrix NetScaler – Importing PKCS12 Cert and Key into FIPS MPX

Hi all! Here I demonstrate how to import an external PKCS#12 (PFX) certificate, that contains the private key, into the Citrix NetScaler FIPS HSM. Then I’ll install the server certificate using the FIPS key and bind to a vServer. The converted PFX (callback.cer) and the PFX certificate files after step 1 will be deleted from the file system after importing into the HSM. We want to do this because the private RSA key is listed in that file. After successfully importing the key into the HSM, we should install the certificate from a PKCS7 or export without the private key. You could manually remove that section of the .cer file if you wish as well.

The appliance used in this demo is a NetScaler MPX FIPS 14030 on software 10.5-59.1361.

Here is the CLI to perform these actions.

  1. convert ssl pkcs12 callback.cer -import -pkcs12File callback_cert.pfx -certFile callback_cert.pfx -password “********”
  2. import ssl fipsKey callback_fips_key -key “/nsconfig/ssl/callback.cer” -inform PEM -exponent 3
  3. <delete /nsconfig/ssl/callback.cer from filesystem>
  4. add ssl certKey callback_cert -cert callback_cert_noprivkey.cer -fipsKey callback_fips_key -inform PEM -expiryMonitor ENABLED -notificationPeriod 30 -bundle NO
  5. bind ssl vserver callback -priority 0 -certkeyName callback_cert -crlCheck Optional

Please let me know if you have any questions on this process. I’ve demo’d this via the GUI in the video below. Thanks for reading!

Leave a Reply

Fill in your details below or click an icon to log in: Logo

You are commenting using your account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s