Thanks all for your input, have resolved the issue! The problem was that I exported the root certificate in der format to upload to the juniper sa series appliance. so I also exported the created client certificates in der format which didn't include the private key. Resolution - i exported the client certificate in pfx format with a password which worked fine. I found the best way to install the certificates on the iPad/iPhone for junos pulse was via the IPCU, so created a configuration profile with the root and client cert included and emailed it. Notes. I removed and re-installed junos pulse when adding or removing a profile (testing) so it found the new client cert. Another issue I found with the IPCU was if I created a VPN profile with juniper ssl and certificate authentication and chose the client cert from the payload was that when I open it in the email it would say 'invalid profile', after removing the VPN profile it worked fine. when installing the IPCU config profile on the ipad/iphone it will say 'not verified' but this still works fine.
... View more