According to the Citrix Virtual Apps and Desktops 7 Deployment and Administration guide1, to connect to an SSL offload virtual server without any SSL errors, the client must trust the certificate that is bound to the virtual server. This means that the root certificate of the certificate authority (CA) that issued the server certificate must be installed on the client's device. Additionally, the server certificate must be bound to the load-balancing virtual server that is configured for SSL offload, not to the back-end servers. This way, the Citrix ADC can terminate the SSL connection and communicate with the back-end servers using HTTP or TCP.