•
Use to inform the ERX router that a public key certificate has been copied to the router.
The router then verifies public certificates found on its disk against its private key and
prepares the certificates for use.
NOTE:
On reload, the router scans all certificate files and determines which files are
router public certificates and which are root CA certificates.
•
Example
host1(config)#
ipsec certificate-database refresh
•
There is no
no
version.
•
See ipsec certificate-database refresh.
ipsec certificate-request generate
•
Use to cause the router to generate a certificate request using certificate parameters
from the IPSec identity configuration.
•
Include a name for the certificate request file. The file name must have a .crq extension.
•
After the router generates the certificate, use offline methods to send the certificate
request file to the CA.
•
Example
host1(config)#
ipsec certificate-request generate rsa myrequest.crq
•
There is no
no
version.
•
See ipsec certificate-request generate.
ipsec crl
Use to control how the router handles CRLs during negotiation of IKE phase 1 signature
authentication. Specify one of the following keywords:
•
•
ignored
—Allows negotiations to succeed even if a CRL is invalid or the peer's
certificate appears in the CRL; this is the most lenient setting
•
optional
—If the router finds a valid CRL, it uses it; this is the default setting
•
required
—Requires a valid CRL; either the certificates that belong to the E Series
router or the peer must not appear in the CRL; this is the strictest setting
•
Example
host1(config)#
ipsec crl ignored
•
Use the
no
version to return the CRL setting to the default, optional.
Copyright © 2010, Juniper Networks, Inc.
216
JunosE 11.2.x IP Services Configuration Guide
Содержание JUNOSE 11.2.X IP SERVICES
Страница 6: ...Copyright 2010 Juniper Networks Inc vi...
Страница 8: ...Copyright 2010 Juniper Networks Inc viii JunosE 11 2 x IP Services Configuration Guide...
Страница 18: ...Copyright 2010 Juniper Networks Inc xviii JunosE 11 2 x IP Services Configuration Guide...
Страница 22: ...Copyright 2010 Juniper Networks Inc xxii JunosE 11 2 x IP Services Configuration Guide...
Страница 28: ...Copyright 2010 Juniper Networks Inc 2 JunosE 11 2 x IP Services Configuration Guide...
Страница 116: ...Copyright 2010 Juniper Networks Inc 90 JunosE 11 2 x IP Services Configuration Guide...
Страница 144: ...Copyright 2010 Juniper Networks Inc 118 JunosE 11 2 x IP Services Configuration Guide...
Страница 230: ...Copyright 2010 Juniper Networks Inc 204 JunosE 11 2 x IP Services Configuration Guide...
Страница 262: ...Copyright 2010 Juniper Networks Inc 236 JunosE 11 2 x IP Services Configuration Guide...
Страница 294: ...Copyright 2010 Juniper Networks Inc 268 JunosE 11 2 x IP Services Configuration Guide...
Страница 328: ...Copyright 2010 Juniper Networks Inc 302 JunosE 11 2 x IP Services Configuration Guide...
Страница 345: ...PART 2 Index Index on page 321 319 Copyright 2010 Juniper Networks Inc...
Страница 346: ...Copyright 2010 Juniper Networks Inc 320 JunosE 11 2 x IP Services Configuration Guide...
Страница 356: ...Copyright 2010 Juniper Networks Inc 330 JunosE 11 2 x IP Services Configuration Guide...