XenServer - Install a trusted CA certificate on the pool

Information

Using a certificate on the pool allows encrypted communications with the pool master through SSL. This check verifies that a certificate is installed on the pool. It does not verify whether the issuer is trusted.

http://www.citrix.com/support/security-compliance/common-criteria.html

Solution

Copy the certificate from a public or private CA to the pool master host. The certificate must be in Privacy Enhanced Mail (PEM) format. To install the certificate run this command:


xe pool-certificate-install filename=<ca_certificate_name.pem>

For more information see the Common Criteria Evaluated Configuration Guide for Citrix XenServer 6.0.2.