host1(config-ipsec-identity)#
country CA
b.
Specify a common name.
host1(config-ipsec-identity)#
common-name Jim
c.
Specify a domain name.
host1(config-ipsec-identity)#
domain-name myerx.kanata.junipernetworks.com
d.
Specify an organization.
host1(config-ipsec-identity)#
organization juniperNetworks
host1(config-ipsec-identity)#
exit
host1(config)#
5.
Generate a certificate request using certificate parameters from the IPSec identity
configuration.
host1(config)#
ipsec certificate-request generate rsa myrequest.crq
6.
After the certificate request is generated, you need to copy the file from the router
and send it to the CA. Typically, you copy the file and paste it to a CA's Web page.
7.
When you receive the certificate from the CA, copy the certificate to the router, and
then inform the router that the new certificate exists.
host1(config)#
ipsec certificate-database refresh
8.
(Optional) Set the sensitivity of how the router handles CRLs.
host1(config)#
ipsec crl ignored
9.
(Optional) To delete RSA key pairs, use the
ipsec key zeroize
command.
host1(config)#
ipsec key zeroize rsa
authentication
•
Use to specify the authentication method that the router uses. For digital certificates,
the method is set to RSA signature.
•
Example
host1(config-ike-policy)#
authentication rsa-sig
•
Use the
no
version to restore the default, preshared keys.
•
See authentication.
common-name
•
Use to specify a common name used to generate certificate requests.
•
Example
host1(config-ipsec-identity)#
common-name Jim
•
Use the
no
version to remove the common name.
•
See common-name.
country
Copyright © 2010, Juniper Networks, Inc.
214
JunosE 11.2.x IP Services Configuration Guide
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...