host1(config-ca-identity)#
enrollment retry-period 40
•
Use the
no
version to restore the default, 1 minute.
•
See enrollment retry-period.
enrollment url
•
Use to specify the URL of the SCEP server, in the format http://
server_ipaddress
. You
can then use the
ipsec ca authentication
command to retrieve CA certificates from
the SCEP server, and the
ipsec ca enroll
command to retrieve the router's public key
certificates from the server.
•
Example
host1(config-ca-identity)#
enrollment url http://192.168.99.105/scepurl
•
Use the
no
version to delete the enrollment URL specification.
•
See enrollment url.
ipsec ca authenticate
•
Use to retrieve the specified CA's certificate. If authentication is successful, the
fingerprint is sent, and an ikeEnrollment message is logged at severity info.
•
The CA must be previously declared by the
ipsec ca identity
command.
•
Example
host1(config)#
ipsec ca authenticate trustedca1
host1(config)#INFO 10/18/2003 03:45:16 ikeEnrollment (): Received CA certificate for
ca:trustedca1
INFO 10/18/2003 03:45:16 ikeEnrollment (): Received CA certificate for ca:trustedca1
fingerprint:28:19:ba:76:d8:e0:bb:22:60:cd:b9:2d:dc:b8:58:01
host1(config)#
•
Use the
no ipsec ca identity
command for the specified CA, or boot the router using
the factory defaults to remove the CA certificate that was generated during the online
configuration.
•
There is no
no
version.
•
See ipsec ca authenticate.
ipsec ca enroll
•
Use to enroll with the specified CA and to retrieve the router's public key certificate
during online digital certificate configuration. If enrollment is successful, the CA sends
the certificate to the router and logs an ikeEnrollment message is logged at severity
info.
•
Use the password option, if required by the CA, to access the CA and enable enrollment.
•
The CA must be previously declared by the
ipsec ca identity
command.
•
Example
host1(config)#
ipsec ca enroll trustedca1 My498pWd
host1(config)#INFO 10/18/2003 03:49:33 ikeEnrollment (): Received erx certificate for
ca:trustedca1
221
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Digital Certificates
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...