•
Use to specify a country name used to generate certificate requests.
•
Example
host1(config-ipsec-identity)#
country CA
•
Use the
no
version to remove the country name.
•
See country.
domain-name
•
Use to specify the domain name that the router uses in IKE authentication messages
and to generate certificate requests.
•
The domain name is used in the SubjectAlternative DNS certificate extensions and as
an FQDN (fully qualified domain name) ID payload for IKE negotiations.
•
Example
host1(config-ipsec-identity)#
domain-name myerx.kanata.junipernetworks.com
•
Use the
no
version to remove the domain name.
•
See domain-name.
ike crl
Use to control how the router handles CRLs during negotiation of IKE phase 1 signature
authentication. Specify one of the following keywords:
•
•
ignored
—Allows negotiations to succeed even if a CRL is invalid or the peer's
certificate appears in the CRL; this is the most lenient setting
•
optional
—If the router finds a valid CRL, it uses it; this is the default setting
•
required
—Requires a valid CRL; either the certificates that belong to the E Series
router or the peer must not appear in the CRL; this is the strictest setting
•
Example
host1(config)#
ike crl ignored
•
Use the
no
version to return the CRL setting to the default, optional.
NOTE:
This command has been replaced by “ipsec crl” on page 216 and may be removed
completely in a future release.
•
See ike crl.
ipsec certificate-database refresh
215
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Digital Certificates
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...