{"id":6456,"date":"2014-01-24T16:00:01","date_gmt":"2014-01-24T15:00:01","guid":{"rendered":"https:\/\/ingmarverheij.com\/?p=6456"},"modified":"2014-01-21T17:51:32","modified_gmt":"2014-01-21T16:51:32","slug":"citrix-receiver-chosen-trust-comodo-high-assurance-secure-server-ca-issuer-servers-certificate","status":"publish","type":"post","link":"https:\/\/ingmarverheij.com\/en\/citrix-receiver-chosen-trust-comodo-high-assurance-secure-server-ca-issuer-servers-certificate\/","title":{"rendered":"Citrix Receiver: You have not chosen to trust &ldquo;COMODO High-Assurance Secure Server CA&rdquo;, the issuer of the server&#8217;s certificate"},"content":{"rendered":"<p><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Citrix-Receiver.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; float: right; padding-top: 0px; padding-left: 0px; margin: 0px 0px 0px 5px; display: inline; padding-right: 0px; border: 0px;\" title=\"Citrix Receiver\" alt=\"Citrix Receiver\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Citrix-Receiver_thumb.png\" width=\"154\" height=\"106\" align=\"right\" border=\"0\" \/><\/a>Recently I started using a MacBook to replace my Windows laptop. Since I work as a technical consultant with Citrix products I frequently connect to a Citrix XenApp \/ XenDesktop environment, amongst other to our lab.<\/p>\n<p>While the installation was straightforward (just go to <a href=\"https:\/\/receiver.citrix.com\/\" target=\"_blank\">receiver.citrix.com<\/a> and click on <strong>Download Reveiver for Mac<\/strong>) I quickly faced a dialog telling me I haven\u2019t chosen to trust the CA certificate with no option to solve this\u2026<\/p>\n<p><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/You-have-not-chosen-to-trust-COMODO-High-Assurance-Secure-Server-CA-the-issuer-of-the-servers-ce.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; float: none; padding-top: 0px; padding-left: 0px; margin-left: auto; display: block; padding-right: 0px; margin-right: auto; border-width: 0px;\" title=\"You have not chosen to trust &quot;COMODO High-Assurance Secure Server CA&quot;, the issuer of the server's certificate\" alt=\"You have not chosen to trust , the issuer of the server's certificate\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/You-have-not-chosen-to-trust-COMODO-High-Assurance-Secure-Server-CA-the-issuer-of-the-servers-ce1.png\" width=\"354\" height=\"140\" border=\"0\" \/><\/a><\/p>\n<p><!--more--><\/p>\n<p>What I find interesting is that both Safari \/ Chrome didn\u2019t complain about the trust. This most likely has to do with the way the certificates are chained. Where the browsers \u201csee\u201d the entire chain (<strong>AddTrust External CA Root<\/strong> &gt;&gt; <strong>COMODO High-Assurance Secure Server CA<\/strong> &gt;&gt; <strong>&lt;server certificate&gt;<\/strong>) the Citrix Receiver only sees the server certificates and expects the signing certificate in the keychain.<\/p>\n<p>The solution is as easy as it sounds, just add the signing certificate to the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Keychain_(Apple)\" target=\"_blank\">Keychain<\/a>.<\/p>\n<p>&nbsp;<\/p>\n<h1>Export the certificate<\/h1>\n<p>First we need to get our hands on the certificate of the signing party (in this case the COMODO certificate). One way of retrieving the root \/ intermediate certificate is by downloading it from the signing part, COMODO provides a download portal containing all their root \/ intermediate certificates (<a href=\"https:\/\/support.comodo.com\/index.php?_m=downloads&amp;_a=view&amp;parentcategoryid=1&amp;pcid=30&amp;nav=0,30\" target=\"_blank\">link<\/a>).<\/p>\n<p align=\"center\"><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Comodo-Support-Center-Downloads-Root-Intermediats.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Comodo - Support Center - Downloads - Root &amp; Intermediat(s)\" alt=\"Comodo - Support Center - Downloads - Root &amp; Intermediat(s)\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Comodo-Support-Center-Downloads-Root-Intermediats_thumb.png\" width=\"354\" height=\"354\" border=\"0\" \/><\/a><\/p>\n<p>But not all certificates are easy to find or not available at all (for instance when the CA is hosted by your company or a third party). Fortunately you can easily export it via Safari. It just not that obvious when you\u2019re a stubborn-Windows-user like me.<\/p>\n<ul>\n<li>In <strong>Safari<\/strong> browse to a website signed with the same certificate (most likely Citrix Storefront)<\/li>\n<li>Click on the <strong>https lock icon<\/strong> to open the certificate <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Safari-Address-bar.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Safari - Address bar\" alt=\"Safari - Address bar\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Safari-Address-bar_thumb.png\" width=\"354\" height=\"54\" border=\"0\" \/><\/a><\/li>\n<li>Click on <strong>Show Certificate <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Safari-is-using-an-encrypted-connection-to.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Safari is using an encrypted connection to\" alt=\"Safari is using an encrypted connection to\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Safari-is-using-an-encrypted-connection-to_thumb.png\" width=\"354\" height=\"113\" border=\"0\" \/><\/a> <br clear=\"all\" \/><\/strong><\/li>\n<li>Select the signing certificate (COMODO High-Assurance\u2026) , click on the certifcate icon (!) and <strong>drag<\/strong> it to a Finder (the OSX equivalent of Windows Explorer) and <strong>drop<\/strong> it in a folder <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/COMODO-High-Assurance-Secure-Server-CA.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"COMODO High-Assurance Secure Server CA\" alt=\"COMODO High-Assurance Secure Server CA\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/COMODO-High-Assurance-Secure-Server-CA_thumb.png\" width=\"354\" height=\"261\" border=\"0\" \/><\/a><\/li>\n<li>That\u2019s it, you just exported the certificate to a .cer file <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Finder.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Finder\" alt=\"Finder\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Finder_thumb.png\" width=\"354\" height=\"255\" border=\"0\" \/><\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<h1>Import the certificate<\/h1>\n<p>Now you\u2019ve got the certificate file you can import it in the <a href=\"https:\/\/en.wikipedia.org\/wiki\/Keychain_(Apple)\" target=\"_blank\">Keychain<\/a>. Just like exporting, once you know how it\u2019s done it\u2019s easier then brushing your teeth.<\/p>\n<p>&nbsp;<\/p>\n<h6>Option 1 \u2013 In five steps<\/h6>\n<ul>\n<li>Open <strong>Keychain Access <\/strong><em>Tip: Press \u2318 + space to open Spotlight<\/em><\/li>\n<li>Click on the <strong>lock<\/strong> icon (top left) to unlock Keychain Access, select the <strong>keychain<\/strong> <strong>Login<\/strong> and <strong>category<\/strong> <strong>Certificates<\/strong> <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Access-Default.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Keychain Access - Default\" alt=\"Keychain Access - Default\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Access-Default_thumb.png\" width=\"354\" height=\"233\" border=\"0\" \/><\/a><\/li>\n<li>Select <strong>File<\/strong> &gt;&gt; <strong>Import items<\/strong> (or \u21e7 + \u2318 + I) <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Acces-File-Import-Items.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border-width: 0px;\" title=\"Keychain Acces - File - Import Items\" alt=\"Keychain Acces - File - Import Items\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Acces-File-Import-Items_thumb.png\" width=\"354\" height=\"294\" border=\"0\" \/><\/a><\/li>\n<li>Select the <strong>certificate file <\/strong>you exported in the previous step and select the <strong>Keychain login <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Import-Item.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"Import Item\" alt=\"Import Item\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Import-Item_thumb.png\" width=\"354\" height=\"220\" border=\"0\" \/><\/a> <br clear=\"all\" \/><\/strong><\/li>\n<li>That\u2019s it! <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Access-COMODO-High-Assurance-Secure-Server-CA.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-top: 0px; padding-left: 0px; display: inline; padding-right: 0px; border: 0px;\" title=\"Keychain Access - COMODO High-Assurance Secure Server CA\" alt=\"Keychain Access - COMODO High-Assurance Secure Server CA\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Keychain-Access-COMODO-High-Assurance-Secure-Server-CA_thumb.png\" width=\"354\" height=\"221\" border=\"0\" \/><\/a><\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<h6>Option 2 \u2013 In one step<\/h6>\n<p>Even easier is it to<strong> double click<\/strong> on the certificate file. This will open the <strong>Add Certificates <\/strong>dialog where you can select the Keychain (<strong>login<\/strong>), all you then have to do is click on <strong>Add<\/strong>. <br clear=\"all\" \/><a href=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Add-Certificates.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; float: none; padding-top: 0px; padding-left: 0px; margin-left: auto; display: block; padding-right: 0px; margin-right: auto; border: 0px;\" title=\"Add Certificates\" alt=\"Add Certificates\" src=\"https:\/\/ingmarverheij.com\/wp-content\/uploads\/2014\/01\/Add-Certificates_thumb.png\" width=\"354\" height=\"201\" border=\"0\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>.<\/p>","protected":false},"excerpt":{"rendered":"<p>Recently I started using a MacBook to replace my Windows laptop. Since I work as a technical consultant with Citrix products I frequently connect to a Citrix XenApp \/ XenDesktop environment, amongst other to our lab. While the installation was straightforward (just go to receiver.citrix.com and click on Download Reveiver for Mac) I quickly faced [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-container-style":"default","site-container-layout":"default","site-sidebar-layout":"default","disable-article-header":"default","disable-site-header":"default","disable-site-footer":"default","disable-content-area-spacing":"default","footnotes":""},"categories":[19],"tags":[581,667,645,643,644,467],"class_list":["post-6456","post","type-post","status-publish","format-standard","hentry","category-citrix","tag-certificates","tag-citrix","tag-comodo","tag-mac","tag-osx","tag-receiver"],"_links":{"self":[{"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/posts\/6456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/comments?post=6456"}],"version-history":[{"count":6,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/posts\/6456\/revisions"}],"predecessor-version":[{"id":6515,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/posts\/6456\/revisions\/6515"}],"wp:attachment":[{"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/media?parent=6456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/categories?post=6456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ingmarverheij.com\/en\/wp-json\/wp\/v2\/tags?post=6456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}