Table 15: Outcome of IKE Phase 1 Negotiations
CRL Setting
Required
Optional
Ignored
Condition
Succeed
Succeed
Succeed
CRL OK
Fail
Succeed
Succeed
CRL expired
Fail
Succeed
Succeed
Missing CRL
Fail
Fail
Succeed
Peer Cert revoked
Fail
Fail
Succeed
ERX Cert revoked
File Extensions
Table 16 on page 211 describes the file extensions that the ERX routers use for digital
certificates that are created by the offline process.
During the online digital certificate process, the certificate files are kept in NVS in hidden
areas and are not visible to users (the files do not appear when you enter a
dir
shell
command). Use the
show
commands to display information for the online certificate
files. The router's private keys are similarly hidden from users.
Table 16: File Extensions (Offline Configuration)
Description
File Extension
Used for certificate request files that are generated on the ERX router and taken
to CAs for obtaining a certificate.
.crq
Used for public certificate files. The public certificates for root CAs and the
router public certificates are copied to the ERX router. They are automatically
recognized as belonging to the ERX router or CA by certificate subject name
and issuer name (in a CA they are the same). The ERX router supports multiple
CAs.
.cer
Used for certificate revocation lists that are obtained offline from CAs and
copied to the ERX router. CRLs indicate which certificates from a particular CA
are revoked.
.crl
Certificate Chains
In a basic CA model, there is a single CA from which the ERX router obtains the root CA
certificates and the router's public key certificates. The E Series router also supports CA
hierarchies, which consist of a top-level root CA and one or more sub-CAs (also called
issuing CAs).
In a CA hierarchy, the router obtains its public key certificates and the CA certificate from
a sub-CA. The sub-CA's certificate is signed by the root CA.
211
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Digital Certificates
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...