host1(config-ca-identity)#
crl ignored
7.
(Optional) Specify the wait period between certificate request retries.
host1(config-ca-identity)#
enrollment retry-period 5
8.
(Optional) Specify the absolute time limit on enrollment.
host1(config-ca-identity)#
enrollment retry-limit 60
9.
(Optional) Specify the URL of your network's HTTP proxy server.
host1(config-ca-identity)#
root proxy url http://192.168.5.45
host1(config-ca-identity)#
exit
10.
Retrieve the CA certificate.
host1(config)#
ipsec ca authenticate trustedca1
11.
Enroll with the CA and retrieve the router's certificate from the CA.
host1(config)#
ipsec ca enroll trustedca1 My498pWd
12.
(Optional) To delete RSA key pairs, use the
ipsec key zeroize
command.
authentication
■
Use to specify the authentication method that the router uses. For digital
certificates, the method is set to RSA signature.
■
Example
host1(config-ike-policy)#
authentication rsa-sig
■
Use the
no
version to restore the default, preshared keys.
■
See authentication.
crl
Use to control how the router handles certificate revocation lists (CRLs) during
negotiation of online IKE phase 1 signature authentication. Specify one of the
following keywords:
■
■
ignored
—Allows negotiations to succeed even if a CRL is invalid or the peer's
certificate appears in the CRL; this is the most lenient setting
■
optional
—If the router finds a valid CRL, it uses it; this is the default setting
■
required
—Requires a valid CRL; either the certificates that belong to the E
Series router or the peer must not appear in the CRL; this is the strictest
setting
■
Example
host1(config-ca-identity)#
crl ignored
228
■
Configuring Digital Certificates Using the Online Method
JUNOSe 11.0.x IP Services Configuration Guide
Содержание JUNOSE 11.0.X IP SERVICES
Страница 6: ...vi...
Страница 8: ...viii JUNOSe 11 0 x IP Services Configuration Guide...
Страница 18: ...xviii Table of Contents JUNOSe 11 0 x IP Services Configuration Guide...
Страница 20: ...xx List of Figures JUNOSe 11 0 x IP Services Configuration Guide...
Страница 22: ...xxii List of Tables JUNOSe 11 0 x IP Services Configuration Guide...
Страница 28: ...2 Chapters JUNOSe 11 0 x IP Services Configuration Guide...
Страница 138: ...112 Monitoring J Flow Statistics JUNOSe 11 0 x IP Services Configuration Guide...
Страница 286: ...260 Monitoring IP Tunnels JUNOSe 11 0 x IP Services Configuration Guide...
Страница 312: ...286 Monitoring IP Reassembly JUNOSe 11 0 x IP Services Configuration Guide...
Страница 357: ...Part 2 Index Index on page 333 Index 331...
Страница 358: ...332 Index JUNOSe 11 0 x IP Services Configuration Guide...