1Y0-201 · Question #158
Scenario: A user is unable to launch a virtual desktop through NetScaler. A Citrix Administrator notices a warning on the browser's certificate section. What are two likely causes of this issue?…
The correct answer is B. The certificate is expired. C. The certificate is NOT linked to the root CA. A browser certificate warning on the NetScaler gateway is triggered when the presented SSL certificate is expired or when the certificate chain cannot be validated back to a trusted root CA.
Question
Scenario: A user is unable to launch a virtual desktop through NetScaler. A Citrix Administrator notices a warning on the browser's certificate section. What are two likely causes of this issue? (Choose two.)
Options
- AThe certificate is 3DES.
- BThe certificate is expired.
- CThe certificate is NOT linked to the root CA.
- DThe certificate is NOT installed on the virtual desktop.
How the community answered
(30 responses)- A13% (4)
- B80% (24)
- D7% (2)
Why each option
A browser certificate warning on the NetScaler gateway is triggered when the presented SSL certificate is expired or when the certificate chain cannot be validated back to a trusted root CA.
3DES is a cipher suite algorithm, not a certificate attribute that causes a browser certificate warning; cipher-related issues would appear as connection or security protocol errors rather than a certificate section warning.
An expired certificate causes all modern browsers to display a warning because the certificate's validity period has passed, making trust verification fail immediately.
If the certificate is not linked to the root CA - meaning intermediate certificates are missing or the CA chain is broken - the browser cannot build a trusted path and displays a warning indicating the certificate is not trusted.
The browser validates the SSL certificate presented by NetScaler Gateway, not one installed on the virtual desktop, so the absence of a certificate on the virtual desktop would not produce a browser certificate warning.
Concept tested: SSL certificate trust chain and expiry validation on NetScaler Gateway
Source: https://docs.citrix.com/en-us/citrix-adc/current-release/ssl/ssl-certificates.html
Topics
Community Discussion
No community discussion yet for this question.