Switching

last person joined: yesterday 

Ask questions and share experiences about EX and QFX portfolios and all switching solutions across your data center, campus, and branch locations.
  • 1.  Generating HTTPS Certificate

    Posted 12-18-2008 15:34

    I am trying to generate a SSL certificate for an EX4200 switch with Junos 9.2, I am using the procedure that I have found at http://www.juniper.net/techpubs/en_US/junos9.2/topics/task/configuration/ex-series-ssl-certificates-generating.html. Where do I run the openssl command from? I can not run it from the switch interface.

     

    Thanks

    Paul McLean



  • 2.  RE: Generating HTTPS Certificate

    Posted 12-21-2008 22:35

    Hi Paul,

     

    What sort of error do you see when you try the openssl command?

     

    Thx

     

    -Keith



  • 3.  RE: Generating HTTPS Certificate

    Posted 12-22-2008 05:17

    looks like you need to run it from a BSD shell. You get this shell by default when logging into console if i'm not mistaken. I believe you can also spawn a shell with "start" in operational mode.

     

    Dennis



  • 4.  RE: Generating HTTPS Certificate

    Posted 12-22-2008 12:32

    Running it from the BSD prompt I get "openssl: Command not found."

     

    Running it from  operational mode I get "openssl         unknown command."

     

    Running it from  configuration mode I get "openssl         unknown command."

     

    The switches are running 9.2r2.15

     

    Thanks

    Paul McLean

     



  • 5.  RE: Generating HTTPS Certificate

    Posted 12-22-2008 12:52

    Are you running domestic or worldwide software ?

     

    Don't know if it might be a US/Canada only feature...

     

    Dennis



  • 6.  RE: Generating HTTPS Certificate

    Posted 12-22-2008 12:57

    The software version we are using is jinstall-ex-9.2R2.15-domestic-signed.tgz

     

    Paul 



  • 7.  RE: Generating HTTPS Certificate

    Posted 01-04-2009 15:30

    Update:

     

    OPENSSH is not included onthe switches at this stage, the SSL certificate needs to be generated by a seperate certificate server and then copied to the switches (I have not tested this yet).

     

    Paul 



  • 8.  RE: Generating HTTPS Certificate
    Best Answer

    Posted 01-05-2009 19:06

    Generated the SSL certificate on a Linux server (added the -days n command to have a exp date more than 30 days). You can use the certificate on as many switch as you want.

     

    Certificate in installed and tested - you do get an error when access the page as the certificate is generic and not for a specific switch.