request security certificate (signed)
Syntax
request security certificate enroll filename filename subject subject
alternative-subject alternative-subject certification-authority certification-authority encoding
(binary | pem) key-file key-file domain-name domain-name
Release Information
Command introduced before Junos OS Release 7.4.
Command introduced in Junos OS Release 9.0 for EX Series switches.
Description
(Encryption interface on M Series and T Series routers and EX Series switches only)
Obtain a signed certificate from a certificate authority (CA). The signed certificate
validates the CA and the owner of the certificate. The results are saved in a specified file
to the
/var/etc/ikecert
directory.
Options
filename
filename
—File that stores the certificate.
subject
subject
—Distinguished name (
dn
), which consists of a set of components—for
example, an organization (
o
), an organization unit (
ou
), a country (
c
), and a locality
(
l
).
alternative-subject
alternative-subject
—Tunnel source address.
certification-authority
certification-authority
—Name of the certificate authority profile in
the configuration.
encoding (binary | pem)
—File format used for the certificate. The format can be a binary
file or privacy-enhanced mail (PEM), an ASCII base64-encoded format. The default
format is binary.
key-file
key-file
—File containing a local private key.
domain-name
domain-name
—Fully qualified domain name.
Required Privilege
Level
maintenance
List of Sample Output
request security certificate (signed) on page 618
Output Fields
When you enter this command, you are provided feedback on the status of your request.
request security
certificate (signed)
user@host>
request security certificate enroll filename host.crt subject c=uk,o=london
alternative-subject 10.50.1.4 certification-authority verisign key-file host-1.prv domain-name
host.juniper.net
request security
certificate (signed)
CA name: juniper.net CA file: ca_verisign
local pub/private key pair: host.prv
subject: c=uk,o=london domain name: host.juniper.net
alternative subject: 10.50.1.4
Encoding: binary
Certificate enrollment has started. To view the status of your enrollment, check
the key management process (kmd) log file at /var/log/kmd. <--------------
Copyright © 2010, Juniper Networks, Inc.
618
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...