•
CA—Certificate authority that the router uses to generate certificate requests
•
enrollment url—URL of the SCEP server where the router sends certificate requests
•
issuer id—Name of the CA issuer providing the digital certificates
•
retry period—Number of minutes that the router waits after receiving no response
from the CA before resending a certificate request
•
retry limit—Number of minutes during which the router continues to send a certificate
request to the CA
•
crl setting—Setting that controls how the router checks the certificate revocation
lists
•
proxy url—HTTP proxy server used to retrieve the root CA certificate, if any
•
Example
host1#
show ipsec ca identity mysecureca1
CA: mysecureca1 parameters:
enrollment url:http://192.168.10.124/scepurl
issuer id :BetaSecurityCorp
retry period :1
retry limit :60
crl setting :optional
proxy url :
•
See show ipsec ca identity.
show ipsec certificates
show ike certificates
NOTE:
The
show ike certificates
command has been replaced by the show ipsec
certificates command and may be removed completely in a future release.
•
Use to display the IKE certificates and CRLs on the router. Specify the type of certificate
you want to display:
•
all
—All certificates configured on the router
•
crl
—Certificate revocation lists
•
peer
—Peer certificates
•
public-certs
—Public certificates
•
root-cas
—Root CA certificates
•
Use the
hex-format
keyword to display certificate data, such as serial numbers, in
hexadecimal format. Doing so allows easier comparison with CAs, such as Microsoft,
that display certificates in hexadecimal format.
229
Copyright © 2010, Juniper Networks, Inc.
Chapter 8: Configuring Digital Certificates
Summary of Contents for JUNOSE 11.2.X IP SERVICES
Page 6: ...Copyright 2010 Juniper Networks Inc vi...
Page 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Page 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Page 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Page 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Page 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Page 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Page 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Page 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Page 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Page 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Page 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Page 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Page 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...