Differences between revisions 7 and 12 (spanning 5 versions)
Revision 7 as of 2014-02-15 22:30:42
Size: 942
Comment:
Revision 12 as of 2014-02-16 08:11:01
Size: 1416
Comment:
Deletions are marked like this. Additions are marked like this.
Line 3: Line 3:
= NOTES FOR WORK IN PROGRESS, NOT FIXED YET =
Line 14: Line 13:

Still doesn't work ... poop on this!
-------
=== INSTEAD ===
'''Make 12.1 work''' by adding new Root-R*.crt files [[https://support.globalsign.com/customer/portal/articles/1426602-download-globalsign-root-and-intermediate-certificates|here]] or [[http://tiny.cc/citcert|here]]. I downloaded Root-R1.crt, Root-R2.crt, and Root-R3.crt, and added them to the .../Citrix/ICAClient/keystore/cacerts/ directory. Probably only Root-R1.crt is needed, but I don't want to go through this nonsense again, any time soon.

Citrix Fix

Citrix Receiver 13.0, RHEL/CentOS/ScientificLinux 6.5 32 bit


As of the beginning of February 2014, accessing websites using Citrix Receiver 12.1 fails with this (useless) error message:


  • SSL error

  • Contact your help desk with the following information:
  • The server sent an expired security certificate. The
  • certificate "GlobalSign Root CA" is valid from 01

  • September 1998 to 28 January 2014 (SSL error 70).


The recommended fix is using Citrix Receiver 13.0, using this RPM. However, this new version requires libxerces-c-3.1.so and libwebkitgtk-1.0.so.0 . libxerces is available here

Still doesn't work ... poop on this!


INSTEAD

Make 12.1 work by adding new Root-R*.crt files here or here. I downloaded Root-R1.crt, Root-R2.crt, and Root-R3.crt, and added them to the .../Citrix/ICAClient/keystore/cacerts/ directory. Probably only Root-R1.crt is needed, but I don't want to go through this nonsense again, any time soon.

CitrixFix (last edited 2014-02-16 08:11:01 by KeithLofstrom)