How to renew or generate and install new certificate for Citrix Storefront Server
1) Start machine MAH-ALL-001à Click on startàgo to Administrative toolsàclick on Internet Information services (IIS) manager
2) Expand the system nameà goto Server Certificates and click on it
3) Click on Create Certificate Request from Right Pane
4) Request Certificate window Popups
Common name:MAH-ALL-001.training.lab
Organisation: TRAINING
Organisational unit: IT
i) To create an OU goto Actice Directory à select training.labà right click on domainà select newà organizational Unit à Give name as IT à click ok.
ii) In AD select Computers-à select the machine name-à righ clickà moveà Select the OU which we have created Previously.
City/Locality: Hyderabad
State/province: TS
Country/region: India
5) Click Nextà select the Microsoft RSA SChannel Cryptographic provider
6) Select the Bit Length à change it to 2048à Click Next
7) Now Select the location where the certificate Request is to be saved. Goto browseà
8) select the desired locationà give filename àClick Open
9) click finish
10) Goto AD server à Click on IE browser and Navigate to :url : ad.training.lab/certsrv à click on Continue to this Website à Enter the Credentials.
11) From the windowà click on Request a Certificate
12) Click on Advanced Certificate Request
13) Select the PKCS#7 File.
14) In the next window copy the content from the file we saved Previously and paste on the Saved Request Blockà from Certificate Template choose Web Server à Click on Submità Click Yes in the Confirmation Popup.
15) In the next window choose DER Encodedà click on Download Cerificateà Click on Save
16) Goto MAH-ALL-001 Machineà open Administrative Toolsàgoto Internet Information services (IIS) managerà Expand the system nameà goto Server Certificates and click on it
17) From the Right Paneà Click on Complete Certificate Request
18) In the next window Click on Browse
19) Navigate to the AD server from MAH-All-001 where we have downloaded our Certificate path: \\ad\c$\users\Administrator\Downloads
20) Click EnteràChoose the downloaded File certnew à Click Open
21) àin Friendly Name give name MAH-ALL-001.training.labà Click OK
22) From The left pane Click on Sites à ExpandàDefault websiteà Click on Bindings
From the Right pane
23) click on ADD.
24) Select Type from dropdown and select HTTPS from the SSL Certificate dropdown Select SSL Certificate which we created
25) Click Close
26) click Start menu and search for Storefront and open it
27) à from leftpane choose Server Groupà from the Right pane click on change Base URL
28) à Change Http to Httpsà Click Ok
29) Navigate to AD Machine Copy the changed URL and paste it in Browser
30) View the Certificate