NOTE:
For more information about setting up IKE policies, see “Defining an IKE
Policy” on page 156 in “Configuring IPSec” on page 125.
3.
Enter IPSec Identity Configuration mode.
host1(config)#
ipsec identity
host1(config-ipsec-identity)#
4.
Specify the information that the router uses to generate a certificate request.
a.
Specify a country name.
host1(config-ipsec-identity)#
country CA
b.
Specify a common name.
host1(config-ipsec-identity)#
common-name Jim
c.
Specify a domain name.
host1(config-ipsec-identity)#
domain-name myerx.kanata.junipernetworks.com
d.
Specify an organization.
host1(config-ipsec-identity)#
organization juniperNetworks
host1(config-ipsec-identity)#
exit
host1(config)#
5.
Generate a certificate request using certificate parameters from the IPSec identity
configuration.
host1(config)#
ipsec certificate-request generate rsa myrequest.crq
6.
After the certificate request is generated, you need to copy the file from the
router and send it to the CA. Typically, you copy the file and paste it to a CA's
Web page.
7.
When you receive the certificate from the CA, copy the certificate to the router,
and then inform the router that the new certificate exists.
host1(config)#
ipsec certificate-database refresh
8.
(Optional) Set the sensitivity of how the router handles CRLs.
host1(config)#
ipsec crl ignored
9.
(Optional) To delete RSA key pairs, use the
ipsec key zeroize
command.
host1(config)#
ipsec key zeroize rsa
authentication
222
■
Configuring Digital Certificates Using the Offline Method
JUNOSe 11.1.x IP Services Configuration Guide
Содержание IP SERVICES - CONFIGURATION GUIDE V 11.1.X
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 1 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 1 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 1 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 1 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 1 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 1 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 1 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 1 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 1 x IP Services Configuration Guide...