Support Support Downloads Knowledge Base Juniper Support Portal Community

Knowledge Base

Search our Knowledge Base sites to find answers to your questions.

Ask All Knowledge Base Sites All Knowledge Base Sites JunosE Defect (KA)Knowledge BaseSecurity AdvisoriesTechnical BulletinsTechnotes Sign in to display secure content and recently viewed articles

How to replace certificate for web management on NSMXpress

0

0

Article ID: KB15078 KB Last Updated: 03 Jan 2017Version: 4.0
Summary:
NSM WebUI login (https://NSMXpress_IP/admin ) uses a self-signed certificate stored on NSMXpress server. This certificate can be replaced with user-generated certificates.
Symptoms:

Cause:

Solution:
To replace the self signed certificate with custom certificates follow the steps below:
  1. Login to NSMXpress using admin user
  2. Change to root user:  #sudo su -
  3. Enter: # grep SSLCertificate /etc/httpd/conf.d/ssl.conf | grep -v ^#    (this will give you the path where self-signed certificates are installed)
    Example:
    SSLCertificateFile /etc/httpd/conf/ssl.crt/server.crt
    SSLCertificateKeyFile /etc/httpd/conf/ssl.key/server.key
  4. Replace the files /etc/httpd/conf/ssl.crt/server.crt and /etc/httpd/conf/ssl.key/server.key with corresponding files from new certificate.
  5. Restart httpd service: #service httpd restart

Now the WebUI  - https://NSMXpress_IP/admin will contain new certificate.

For examples on creating a certificate use KB11255

Note :

Do not use keys generated from NSM server utlitiy through process KB25918 to replace the httpd keys in this KB. You could use the below command on the NSM appliance to create certificates for web management on NSMxpress appliance-

Example :
openssl req -new -newkey rsa:2048 -nodes -keyout server.key -out server.csr


Comment on this article > Affected Products Browse the Knowledge Base for more articles related to these product categories. Select a category to begin.

Getting Up and Running with Junos

Getting Up and Running with Junos Security Alerts and Vulnerabilities Product Alerts and Software Release Notices Problem Report (PR) Search Tool EOL Notices and Bulletins JTAC User Guide Customer Care User Guide Pathfinder SRX High Availability Configurator SRX VPN Configurator Training Courses and Videos End User Licence Agreement Global Search