DTR Vantage

Licensing portal ↗Request a demo

Certificate automation for NetScaler

Renewing a certificate is the easy part. Installing it on every appliance that serves it, linking the chain, moving every binding and proving it worked is the part that fails at 2 a.m. That is what DTR Vantage automates.

Certificate deployment
available
from a folder of renewed files
Renew and deploy (ACME)
early access
from your certificate authority
Preview
before every run
every binding read from the appliance first
After a run
a report
what changed, the appliance's own words, a rollback plan
The direct answer. DTR Vantage deploys renewed certificates to NetScaler appliances as workflows. Certificate deployment takes the renewed files from a folder (a share the service account reads) and Renew and deploy obtains them from your certificate authority over ACME. Either way, Vantage reads every binding of the certificate on the appliance before it changes anything, shows you the plan, installs the new certificate, links its chain, moves every binding, reads the result back and keeps a report.

What a buyer asks, answered

The questionThe answer today
Can it renew certificates from our certificate authority?Over ACME, as the Renew and deploy workflow: early access. The private key is generated on the appliance and never leaves it; an external account binding credential is used once and never stored. From any other CA process, drop the renewed files in a folder and Certificate deployment picks them up.
Does it install the certificate and update the right bindings?Yes. Before anything is sent it reads every place the certificate is bound on the appliance, including virtual servers you did not name, and shows them. You choose how it lands: in place (every binding kept), or as a new certificate named with the date and time with every binding moved onto it.
What about a certificate shared by other services?The preview says so in words ("shared by two virtual servers, including one outside your selection") and deployment waits for you to acknowledge it or change the targets.
Does it handle many appliances?One workflow covers every appliance, a category, chosen appliances or single virtual servers. Each appliance is worked on its own; one that refuses stops there, the others carry on, and the report says which.
Does it check that it worked?It reads the certificate back from the appliance after the change and records what the appliance reports. The SSL/TLS Checker shows what a client on the internet sees.
What happens if it fails?The run stops for that appliance and says why in the appliance's own words. Dated installs leave the previous certificate in place, so the report carries a rollback plan: what to undo, newest first.
Can we control timing and approval?Manual only, or on a schedule (daily, weekly, every few hours), paused when you want. A run is previewed first; the actions are for administrators only and every change is audited.
Which platforms?NetScaler (ADC and Gateway) today. The Windows server certificates Vantage already reads are tracked for expiry on the Windows Certificates view; deploying to them is on the roadmap.

In the product

Automation

Automation

The jobs that go wrong at 2 a.m., as workflows with a preview before anything is sent and a report after. Certificate deployment takes renewed files from a share and Renew and deploy obtains them over ACME; both read every binding on the appliance first, install the new certificate dated or in place, move every binding and read the result back, with a rollback plan. SSH commands runs a checked list across chosen appliances, Certificate cleanup removes what expired and is bound to nothing, and Reporting builds any of the dashboard’s reports on a schedule and e-mails it or writes it to a folder. Every run is kept, and every kind is licensed with the module it acts on.

  • Four questions per workflow: where from, where to, when, and what will change
  • A certificate shared outside your selection waits for you to acknowledge it
  • Run history with Succeeded, Partially completed, Failed and Preview said apart; the reports kept here to download
  • Reports e-mailed through your own mail server (Resend, Office 365 or a relay), the password encrypted and never shown
A certificate deployment's review: each certificate with its current and new expiry, the services it affects, the action planned and the exceptions, before anything is sent
Click to zoom
Where it should go: appliances, a category, or chosen virtual servers, gateways and AAA servers, searchable
Click to zoom
Every workflow of every kind in one list with its schedule, last run and next run
Click to zoom
Run history: Succeeded, Partially completed, Failed and Preview said apart
Click to zoom
Reports built on a schedule, how each was delivered, kept to download
Click to zoom
Tools

Utilities

Tools over material you already have, for administrators. The certificate converter opens a PFX, shows the chain as a ladder and whether a private key is in it, and writes the certificate, key and chain in the names a deployment workflow reads, with the key encrypted or said plainly to be unencrypted; neither password is stored and the file is not kept. Trace analysis reads a pcap or pcapng from anywhere — or a capture Vantage takes on a NetScaler — and answers where the connection failed: DNS, TCP or TLS, with the packets that show it, the addresses named from the estate map and what Vantage recorded in the same minutes.

  • The first failure by stage, as a verdict, with the evidence behind each line
  • The capture is not kept; the report is held for an hour
Trace analysis: where the connection failed, the connections and what Vantage recorded at the time
Click to zoom
The certificate converter: what is in the PFX, the chain as a ladder, a private key or not
Click to zoom

How a deployment runs

  1. Where are the certificates? A folder, or your CA.
  2. Where should they go? Appliances, a category, or chosen virtual servers.
  3. When should it run? Manual only, or on a schedule.
  4. What will change? The preview: every certificate, the services it affects, the action planned, and any exception.
  5. Deploy. Then the result: succeeded, partially completed or failed, with the verification and the log.

Try the pieces in the Vantage Toolkit

Two of the steps are in the Vantage Toolkit, at no cost and with no account:

  • SSL/TLS Checker: expiry, chain, name and TLS versions as the internet sees them.
  • PFX to PEM: the files a deployment reads, made in your browser, named the way the workflow expects.