SSL Certificate Install on a Juniper SRX for Pulse Secure

· Networking

#juniper #srx #ssl #pulse-secure

Problem

A customer wanted the Pulse splash page on their SRX300 to stop presenting a self-signed certificate.

When browsing to https://<customer-ip> you receive a certificate error before getting the “The SRX no longer provides hosting of the Pulse Client for direct download.” message. This is because the SSL certificate is self-signed. The way around that is loading a trusted SSL certificate.

Fix

Have the customer choose a new DNS subdomain and create a DNS record pointing the new subdomain at the external IP of the firewall.

The customer should be able to provide a wildcard cert for *.domainname.com, or if they have a specific subdomain certificate that will work too.

  1. Receive a Cert.pem (certificate chain) and Cert.key (private key) from the customer.
  2. Build a combined file:
    • Open Cert.pem and copy the section starting with -----BEGIN CERTIFICATE----- and ending with -----END CERTIFICATE----- into a new text file.
    • Open Cert.key. It should begin with -----BEGIN RSA PRIVATE KEY----- and end with -----END RSA PRIVATE KEY-----. Copy it into the same new file.
    • Save the new file as CertKey.pem.
  3. SCP CertKey.pem to /var/tmp on the SRX.
    • You may have trouble getting into the SRX with SCP if you are running Junos 19.1R1 or later. See Juniper’s SFTP server configuration for reference.
  4. SSH to the SRX and load the certificate. We set the web-management certificate because Pulse on an SRX listens on tcp/443 by default.
set security certificates local wildcard load-key-file /var/tmp/CertKey.pem
set services web-management https local-certificate wildcard

Verify

Commit the changes and browse to the new subdomain. It should load with no certificate errors. You may have to restart your browser for the new certificate to load properly.

← all posts