CSR Creation for NetScreen ScreenOS 4.0 and 5.0 SSL Certificates
Connect to
the WebUI application.
In the
Options menu go to Configuration and select Date/Time.
Click the
'Sync Clock with Client' button.
Make sure
that the 'Automatically adjust clock for daylight savings changes' is set on
your computer and hit 'Yes'.
In the
Options menu go to Network and select DNS.
In Host
Name enter the internal device host name.
In the
Domain Name field, enter the fully qualified domain name used to access the
device, and click 'Apply'.
Now that
the clock is set and the Host/Domain names are configured you are ready to
start creating your CSR. In the Options menu go to Objects and select
Certificates.
Click the
'New' button and fill out the Certificate Subject Information fields. Under
the 'FQDN' (Fully Qualified Domain Name) field, enter the full domain name
of your device.
Click the 'Generate'
button.
Save the
Certificate Request (CSR) as a text file.
Copy and
Paste the CSR to the ipsCA Certificate Order form.
SSL Certificate Installation Juniper NetScreen ScreenOS 4.0 and 5.0
1.In the WebUI Options menu, select Objects
and Certificates.
2.Load the Primary certificate:
Select the circle to load a 'Cert'. Next to 'Show' select Local. 'Browse'
for the Primary (your_domain_name.crt) certificate that you downloaded from your
ipsCA Account, and hit Load.
3.Load the Intermediate Certificate:
Select the circle to load a 'Cert'. Next to 'Show' select CA. 'Browse'
for the Intermediate (ipsCA.crt) certificate that you downloaded from your ipsCA
Account, and hit Load.
4.Load the Root Certificate:
Select the circle to load a 'Cert'. Next to 'Show' select CA. 'Browse'
for the Root (TrustedRoot.crt) certificate that you downloaded from your ipsCA
Account, and hit Load.
5.Verify that your primary certificate loaded
as a 'Local' certificate. The Intermediate and Root certificates should have
loaded as CA certificates. If the Primary certificate loaded as a CA certificate
something is wrong. This usually happens because the domain is not properly
setup on the device. To resolve this you will need to configure the domain name
(see CSR creation instructions), create a new CSR for a new certificate, and
install the certificate again.
The SSL Certificate installation on your NetScreen Device is now complete.