[j-nsp] Generating SSL certificate

WALLER PAUL Paul.Waller at alcatel-lucent.com.au
Tue Jun 24 23:20:50 EDT 2008


Hi all,

 

We're having a problem with JunoScope where it is not backing up a
router, we're getting the below error from the log messages file (see
below) from our Juniper M320 router.

 

Logs on MCRT01MTE:

 

MCRT01MTE_RE0 stunnel[10241]: stunnel 4.04 on i386-unknown-freebsd4.2
FORK+LIBWRAP with OpenSSL 0.9.8a 11 Oct 2005

MCRT01MTE_RE0 stunnel[10241]: Error reading certificate file:
/var/etc/ssl/junoscript.pem

MCRT01MTE_RE0 stunnel[10241]: error stack: 140DC009 : error:140DC009:SSL
routines:SSL_CTX_use_certificate_chain_file:PEM lib

MCRT01MTE_RE0 stunnel[10241]: SSL_CTX_use_certificate_chain_file:
906D066: error:0906D066:PEM routines:PEM_read_bio:bad end line

MCRT01MTE_RE0 inetd[4538]: /usr/libexec/stunnel[10241]: exited, status 1

MCRT01MTE_RE0 stunnel[10242]: stunnel 4.04 on i386-unknown-freebsd4.2
FORK+LIBWRAP with OpenSSL 0.9.8a 11 Oct 2005

MCRT01MTE_RE0 stunnel[10242]: Error reading certificate file:
/var/etc/ssl/junoscript.pem

MCRT01MTE_RE0 stunnel[10242]: error stack: 140DC009 : error:140DC009:SSL
routines:SSL_CTX_use_certificate_chain_file:PEM lib

MCRT01MTE_RE0 stunnel[10242]: SSL_CTX_use_certificate_chain_file:
906D066: error:0906D066:PEM routines:PEM_read_bio:bad end line

MCRT01MTE_RE0 inetd[4538]: /usr/libexec/stunnel[10242]: exited, status 1

 

JunoScope Error message:

 

There was a problem retrieving the configuration: could not open
connection: MCRT01MTE_RE0

 

We believe it may be a problem with the ssl certificate so we've tried
creating a new certificate, I have tried the openssl command but all I
get is "command not found message". What am I doing wrong, do I need to
install openssl on my router?

 

MCRT01MTE_RE0 <mailto:munnsj at MCRT01MTE_RE0> > start shell
% openssl req -x509 -nodes -newkey rsa:1024 -keyout newkey.pem -out
newkey.pem 

openssl: Command not found. 

 

JunOS version 8.5R3.4

 

 

Regards,

Paul 

 

 



More information about the juniper-nsp mailing list