In the manual method, an operator obtains the root CA certificate, typically through
a Web browser, and copies the certificate file to the E Series router so that the router
can use it as part of IKE negotiations.
In the automatic method, the router uses SCEP and HTTP to authenticate with the
CA and retrieve the certificate. The requested root CA certificate is automatically
downloaded to the router.
NOTE:
You cannot view certificate files by their filenames if the files were created
by online enrollment. However, the certificate information will appear in the output
for
show
commands.
Obtaining a Public Key Certificate
After the public key is generated, the router must obtain a public key certificate from
a CA, a process called certificate enrollment. The procedure to obtain public keys
depends on whether the offline or online digital certificate process is being used.
The standards supported for certificate enrollment are PKCS #10 certificate requests,
PKCS #7 responses, and X.509v3 certificates. For manual enrollment, certificates
are encoded in base64 (MIME) so that the files are easily transferred through
cut-and-paste operations and e-mail.
Offline Certificate Enrollment
Offline certificate enrollment works as follows:
1.
An operator generates a certificate request by supplying identity information.
2.
The ERX router creates a certificate request file and makes it available to the
operator.
3.
The operator supplies the certificate request file to a CA for approval, typically
by copying and pasting the file to a Web page.
4.
The CA approves the request and generates a certificate.
5.
The operator copies the certificate file onto the ERX router so that it can be used
for IKE negotiations.
Online Certificate Enrollment
Online certificate enrollment works as follows:
NOTE:
The ERX router must have a root CA certificate for the specified CA before
online certificate enrollment.
IKE Authentication with Digital Certificates
■
217
Chapter 8: Configuring Digital Certificates
Summary of Contents for IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Page 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Page 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Page 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Page 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Page 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Page 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Page 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Page 357: ...Part 2 Index Index on page 333 Index 331...
Page 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...