SSL Certificate Install on a Juniper SRX for Pulse Secure
Problem
A customer wanted the Pulse splash page on their SRX300 to stop presenting a self-signed certificate.
When browsing to https://<customer-ip> you receive a certificate error before getting the “The SRX no longer provides hosting of the Pulse Client for direct download.” message. This is because the SSL certificate is self-signed. The way around that is loading a trusted SSL certificate.
Fix
Have the customer choose a new DNS subdomain and create a DNS record pointing the new subdomain at the external IP of the firewall.
The customer should be able to provide a wildcard cert for *.domainname.com, or if they have a specific subdomain certificate that will work too.
- Receive a
Cert.pem(certificate chain) andCert.key(private key) from the customer. - Build a combined file:
- Open
Cert.pemand copy the section starting with-----BEGIN CERTIFICATE-----and ending with-----END CERTIFICATE-----into a new text file. - Open
Cert.key. It should begin with-----BEGIN RSA PRIVATE KEY-----and end with-----END RSA PRIVATE KEY-----. Copy it into the same new file. - Save the new file as
CertKey.pem.
- Open
- SCP
CertKey.pemto/var/tmpon the SRX.- You may have trouble getting into the SRX with SCP if you are running Junos 19.1R1 or later. See Juniper’s SFTP server configuration for reference.
- SSH to the SRX and load the certificate. We set the web-management certificate because Pulse on an SRX listens on tcp/443 by default.
set security certificates local wildcard load-key-file /var/tmp/CertKey.pem
set services web-management https local-certificate wildcard
Verify
Commit the changes and browse to the new subdomain. It should load with no certificate errors. You may have to restart your browser for the new certificate to load properly.