The first time you login to citrix portal, you’ll need to download the Citrix Workspace App for Windows - VA Remote Access Information

image.png

Before you log in: install the VA certificate chain

<aside> 🚨

Do this on every non-VA OSDRI Windows computer before the first Citrix login. If the certificate chain is missing, Citrix may fail with ERR_CONNECTION_RESET before you ever get a certificate/PIV prompt.

</aside>

If Citrix Workspace is already installed, do not use Add Account inside the Citrix app. Close Citrix Workspace. The browser will hand the VA session to Citrix automatically.

Download these 3 VA/Federal certificates

  1. Department of Veterans Affairs CA: http://pki.treasury.gov/vaca_ee_aia.p7c
  2. US Treasury Root CA: http://pki.treasury.gov/vaca_aia.p7c
  3. Federal Common Policy CA G2: https://repo.fpki.gov/fcpca/fcpcag2.crt

Recommended OSDRI handling after download

Best option: do not make each new user extract the raw .p7c bundles again. A known-good extracted copy is kept on Seth's computer at C:\Users\sschultz\Downloads\va-piv-chain\.

Copy these three files from that folder to the new user's computer:

Put them together in a simple local folder such as C:\VA-Certs\. These are public CA certificates; they are not the user's private PIV key.

If you only have the raw downloads from the links above, the first two .p7c files are certificate bundles. Open each bundle in Windows, select/export the required certificate as a .cer file, and do not blindly install every certificate in the Treasury bundle. For vaca_aia.p7c, specifically use the non-expired US Treasury Root CA. The third download, fcpcag2.crt, is already a single certificate and can be installed directly.

Once the three correct certificates are in one folder, continue with the install commands below.