cancel
Showing results for 
Search instead for 
Did you mean: 

Certificate expired

JonR_
New Contributor

Certificate expired

I am new to the NetScreen and working with certificates. I have 1 model SA-2000 that recently had its certificate expired. I followed the menus and made a new .CERT file. The instructions then say to sent it to a CA to be validated. We have a server that uses Microsoft CA for small in-house web applications that i wanted to use. Am i correct that i can use my CA server to issue this certificate or will i still have to pony up for a VeriSign one since my SA-2000 does need to be access by external users?
4 REPLIES 4
muttbarker_
Valued Contributor

Re: Certificate expired

You do not have to use a verisign type cert authority. You can use your in-house CA, or one of the good "free" CA's like cacert.org -- the issue will be that you users may not have that CA's root certificate in their browser so when they go to login they will get a cert error. They will need to put the root cert in to get around the errors or just do an exception for the cert from the SA box.

JonR_
New Contributor

Re: Certificate expired

I tried to use my CA but it told gave me an error message:

"The request contains no certificate template information. Denied by Policy Module, the request does not contain a certificate template extension or the Certificate Template request attribute. "

I looked that up at MS website and it refers to another technet article talking about domain controllers and certificates. I think my best bet is just to go with VeriSign. Thanks for the info though.

muttbarker_
Valued Contributor

Re: Certificate expired

Hey Jon - your choice obviously. I can tell you that we use a cert from cacert.org with no problems on all our internal boxes rather than paying for verisign and it works just fine.

Welcome to the Juniper Forums by the way!

Mrkool_
Super Contributor

Re: Certificate expired

initially when you setup the SA it asks you to create a cert and that is a self signed cert. you can use that cert if you want but like Kevin said your users will get the trusted CA error. If you do decide to go with verisign do not fall for their GIMMICKS get the cheapest cert you can find as the more expensive certs do not give you anything additional just alot of HOOO HAA Smiley Happy