Juniper IP SERVICES - CONFIGURATION GUIDE V 11.1.X Configuration Manual page 250

Ip services configuration guide
Table of Contents

Advertisement

JUNOSe 11.1.x IP Services Configuration Guide
NOTE: This command has been replaced by "ipsec crl" on page 225 and may be
removed completely in a future release.
ipsec certificate-database refresh
NOTE: On reload, the router scans all certificate files and determines which files are
router public certificates and which are root CA certificates.
ipsec certificate-request generate
ipsec crl
224
Configuring Digital Certificates Using the Offline Method
required Requires a valid CRL; either the certificates that belong to the E
Series router or the peer must not appear in the CRL; this is the strictest
setting
Example
host1(config)#ike crl ignored
Use the no version to return the CRL setting to the default, optional.
See ike crl.
Use to inform the ERX router that a public key certificate has been copied to the
router. The router then verifies public certificates found on its disk against its
private key and prepares the certificates for use.
Example
host1(config)#ipsec certificate-database refresh
There is no no version.
See ipsec certificate-database refresh.
Use to cause the router to generate a certificate request using certificate
parameters from the IPSec identity configuration.
Include a name for the certificate request file. The file name must have a .crq
extension.
After the router generates the certificate, use offline methods to send the
certificate request file to the CA.
Example
host1(config)#ipsec certificate-request generate rsa myrequest.crq
There is no no version.
See ipsec certificate-request generate.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.1.x ip servicesJunose v 11.1

Table of Contents