6.5.11 Citrix NetScaler

Select the correct topology and configure SSH key or password access

Choose the NetScaler template for your topology: single appliance, HA pair, or cluster. Each supports two authentication methods:

  • Private Key Auth signs in with an SSH key file.
  • Password Auth signs in with a username and password.

All templates require SSH and SCP access from the agent host.

Choose the topology

Template Connect it to Notes
Citrix NetScaler Single Host The appliance’s management IP (NSIP).  
Citrix NetScaler HA Pair Either appliance’s NSIP. The agent must reach both appliances, and the login must work on both. CertKit finds the active one itself.
Citrix NetScaler Cluster The cluster management IP (CLIP), not one appliance’s IP. The login must work on every appliance in the cluster.

SSH key requirements (Private Key Auth)

  • Windows OpenSSH client tools must be available on the agent host.
  • Create a private key dedicated to CertKit and store it on the agent host.
  • Add the public key to the NetScaler user’s authorized keys. For nsroot, the standard location is /nsconfig/ssh/authorized_keys.
  • Set SSH private key path on the agent host to the full path.

The template locks down the key file’s permissions before connecting, because SSH refuses a key other accounts can read.

Password requirements (Password Auth)

The password templates require Posh-SSH 3.0 or later. Install the module on the agent host from an elevated PowerShell prompt:

Install-Module -Name Posh-SSH -Scope AllUsers -Force

Use -Scope AllUsers so the agent’s service account can load the module. For an offline host, run Save-Module -Name Posh-SSH -Path <folder> on another machine and copy the module and its dependencies to C:\Program Files\WindowsPowerShell\Modules.

Enter the account in NetScaler username and NetScaler password. CertKit stores the password encrypted.

Posh-SSH saves the appliance’s host key on the first connection. If the key changes after a rebuild, verify the new key, then run Remove-SSHTrustedHost -HostName <host> as the agent’s service account and deploy again.

Certificate-key pair behavior

Set SSL certkey pair name to the existing certkey under Traffic Management > SSL > Certificates. Renewals update that certkey in place, so existing virtual server, service, and Gateway bindings remain intact.

If the certkey does not exist, the template creates it. A new certkey serves no traffic until you bind it once in NetScaler.

The templates install and link intermediate certificates so the appliance serves the full chain. Routine renewals update certificate contents without changing bindings or chain links.

Common problems

  • “This certificate is already installed on the NetScaler as certkey …”: NetScaler allows a certificate to exist only once. Set SSL certkey pair name to the existing certkey named in the error, or remove that certkey, and redeploy.
  • HA deployment fails before uploading: the agent must reach both appliances’ management IPs (NSIPs), both must be UP, and HA command propagation must be on (set HA node -haProp ENABLED).
  • “This NetScaler is not part of an HA pair”: use the Single Host template for a stand-alone appliance.
  • Cluster deployment rejects the address: NetScaler cluster management IP (CLIP) must be the cluster’s IP address, not a hostname and not one appliance’s own IP.
  • Cluster nodes not healthy or not synchronized: the template won’t deploy to an unhealthy cluster. Fix the cluster, then deploy again.
  • Wrong template: don’t use the cluster template for an HA pair. They sync differently.
  • Password template can’t find Posh-SSH: reinstall it with -Scope AllUsers.

For a product overview, see certificate automation for Citrix NetScaler.