Citrix NetScaler ADC Integration Guide

Overview

CertSecure Manager automates SSL/TLS certificate renewal on Citrix NetScaler ADC through a dedicated Load Balancer renewal agent, in the same way it supports BIG-IP F5.

Configuration Steps

Step 1: Download the NetScaler Renewal Agent

  • In CertSecure Manager, go to Utilities → Integrations → Load Balancers.
  • Click the Citrix NetScaler icon, then click Download to obtain the renewal agent.
  • Generate the registration token if prompted, for use during agent setup.

Step 2: Install and Run the Agent

  • Set up and start the NetScaler renewal agent on a host that can reach the NetScaler ADC management interface (NITRO/management API).
  • Provide the NetScaler management credentials the agent will use to read and update certificate-key pairs.
  • Confirm the agent appears under Load Balancers once it is running.

Note: Ensure the agent’s service account has permission to view and update certificate-key pairs on the NetScaler ADC.

Step 3: Onboard Certificate-Key Pairs

  • Right-click the NetScaler agent and select Update CSR Details.
  • Onboard the intended NetScaler certificate-key pairs and provide the CSR details for each (common name, SAN, key length, organization fields, CA, and template).
  • Save the onboarded configuration.

Step 4: Renew and Automate

  • Manually renew by right-clicking the agent, selecting the certificate-key pair, and clicking Renew or Schedule Renewal.
  • To automate renewal and rebinding for all onboarded pairs, enable the Automation Status toggle.