The first time you login to citrix portal, you’ll need to download the Citrix Workspace App for Windows - VA Remote Access Information

<aside> 🚨
Do this on every non-VA OSDRI Windows computer before the first Citrix login. If the certificate chain is missing, Citrix may fail with ERR_CONNECTION_RESET before you ever get a certificate/PIV prompt.
</aside>
If Citrix Workspace is already installed, do not use Add Account inside the Citrix app. Close Citrix Workspace. The browser will hand the VA session to Citrix automatically.
Best option: do not make each new user extract the raw .p7c bundles again. A known-good extracted copy is kept on Seth's computer at C:\Users\sschultz\Downloads\va-piv-chain\.
Copy these three files from that folder to the new user's computer:
1-VA-CA.cer2-Treasury-Root.cer3-FCPCA-G2-root.cerPut them together in a simple local folder such as C:\VA-Certs\. These are public CA certificates; they are not the user's private PIV key.
If you only have the raw downloads from the links above, the first two .p7c files are certificate bundles. Open each bundle in Windows, select/export the required certificate as a .cer file, and do not blindly install every certificate in the Treasury bundle. For vaca_aia.p7c, specifically use the non-expired US Treasury Root CA. The third download, fcpcag2.crt, is already a single certificate and can be installed directly.
Once the three correct certificates are in one folder, continue with the install commands below.