Description

This article explains how to make xnm-ssl connections over OPENSSL and execute RPC commands.

Solution

  1. Generating Certificates using OpenSSL. 

    Notes:

    a) Most Linux distributions are pre-installed with OpenSSL. In this demo, we are generating a self-signed certificate. Alternatively, you can register the cert with CA.

    b) When the below command is executed and after following the prompts on the CLI, two files are generated: key1.pem and cert1.pem

    c) Copy the contents of both the files into a single file. For the purpose of this demo, I am naming it cert_key.pem 


    $ openssl req -x509 -newkey rsa:4096 -keyout key1.pem -out cert1.pem -days 365
    Generating a 4096 bit RSA private key
    ...............................................................................
    ..........++
    writing new private key to 'key1.pem'
    Enter PEM pass phrase: xxxxxxx
    Verifying - Enter PEM pass phrase:

    -----
    You are about to be asked to enter information that will be incorporated
    into your certificate request.
    What you are about to enter is what is called a Distinguished Name or a DN.
    There are quite a few fields but you can leave some blank
    For some fields there will be a default value,
    If you enter '.', the field will be left blank.
    -----
    Country Name (2 letter code) [AU]:US
    State or Province Name (full name) [Some-State]:VA
    Locality Name (eg, city) []:Herndon
    Organization Name (eg, company) [Internet Widgits Pty Ltd]:Juniper


    Organizational Unit Name (eg, section) []:JTAC
    Common Name (e.g. server FQDN or YOUR name) []:DB3017AK7638
    Email Address []:[email protected]
  2. Copy the file "cert_key.pem" which contains both private key and cert to the Junos device which you want to establish openssl connection.

    $  scp cert_key.pem [email protected]:/var/tmp
    Password: xxxxxx
    cert_key.pem                                                     100% 5574    52.7KB/s   00:00
  3. Load the copied file "cert_key.pem" to the Junos device as the local certificate. Note you will need to enter private key passphrase set during the generation of the cert in step 1.

    root@SRX1500# set security certificates local <new_cert_key> load-key-file /var/tmp/cert_key.pem 
    error: Private Key: Encrypted
    Enter private key passphrase:xxxxxx
  4. Set the certificate to "xnm-ssl" system services connection type and commit the configuration.

    root@SRX1500# set system services xnm-ssl local-certificate <new_cert_key>
    root@SRX1500# commit
  5. Make xnm-ssl connection on port 3220 using openssl.

    $ openssl s_client -connect 10.85.241.145:3220
    CONNECTED(00000003)
    depth=0 C = US, ST = VA, L = Herndon, O = Juniper, OU = JTAC, CN = DB3017AK7638, emailAddress = [email protected]
    verify error:num=18:self signed certificate
    verify return:1
    depth=0 C = US, ST = VA, L = Herndon, O = Juniper, OU = JTAC, CN = DB3017AK7638, emailAddress = [email protected]
    verify return:1
    ---
    Certificate chain
     0 s:/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected]
       i:/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected]
    ---
    Server certificate
    -----BEGIN CERTIFICATE-----
    MIIF3TCCA8WgAwIBAgIJAJCS9cB2UMR+MA0GCSqGSIb3DQEBCwUAMIGEMQswCQYD
    VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xEDAOBgNVBAoM
    B0p1bmlwZXIxDTALBgNVBAsMBEpUQUMxFTATBgNVBAMMDERCMzAxN0FLNzYzODEe
    MBwGCSqGSIb3DQEJARYPYWJjQGp1bmlwZXIubmV0MB4XDTE4MTAwMjEzMjI0M1oX
    DTE5MTAwMjEzMjI0M1owgYQxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJWQTEQMA4G
    A1UEBwwHSGVybmRvbjEQMA4GA1UECgwHSnVuaXBlcjENMAsGA1UECwwESlRBQzEV
    MBMGA1UEAwwMREIzMDE3QUs3NjM4MR4wHAYJKoZIhvcNAQkBFg9hYmNAanVuaXBl
    ci5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDlNOf3BirJpDna
    n0S/U3Ai7soyJcRGzwoEk/R1V//LhIABAT0Us8HUCLQzVF5XV7meeaaq5iZNdQwB
    kt0zIRXxToYedG5to7ghnedW87j3A0eTaloyWofqW/ql8P7vNZklDTo1OZYfGsjZ
    JWlz0+f5bLw7wQwuk/Tb6N6NvWRDTii24s+geb/VzwzQyfmEIeXi0c2oS6gYYAjk
    i+XZBSSSiFFVaYXI1nAU9GcoKcQm8UYCsQqXVCEEXFqRTrTDxum7dRMnyod94oYJ
    i7s82SxxIN77v8W5ZDaiNSAq5/X+XeU2lvwTmkslYfoTJg4tazAngf3lmcfQbFAb
    L36J7Vj/7f+UwVEfi0FdiOH0SjtxG3o9baaZ7b0Gm29805jmCLXOV91J2ERO0yh5
    TEvKk245xO5em9SrYEg0UoHOiXlsUq4KegdNLHNr8iH+4IIVj1ef9HUU1MOiQobv
    cuUiXuG/Vtl1gIUVZZCYYrQwrJ935QnW2ADZdQeXhx3zSazmJKUNTzmg0ad9dAtg
    XwyLFjj0ENmSvh53HpSm/ZktxSn/bZm5A8gLaWaINxGtj+rpZun16aa5rkHeaCuq
    ED0FHyvgrJKdM36WL/1+Z0gtGLK9bd5H32jkmsKzsc2Fu8t6lstZkxaV5Om39egh
    ZEhTVq88OT51QAhhLFzYkkB8iavroQIDAQABo1AwTjAdBgNVHQ4EFgQUaQpaR3P+
    0RCCrCz3dCdBZATRWNcwHwYDVR0jBBgwFoAUaQpaR3P+0RCCrCz3dCdBZATRWNcw
    DAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEAmd5vlNWmrA7mlj+r5aTS
    dTv99WYUllpfMgvOpRodfzJBGrMHqWqKxuzdPbXJIWy/QO5LJrh6waq04sf/4h5n
    IPs3cYi7uV3RC95SvjgB3Jzqwp0KhXDSYvuduEzdyD8bg37QbmFhOXi3xMnYrLLe
    J5ufi1HCC03n2pgdkv6WptKj/gbngtLU42LEAiC60mWonQJc/v4D/hveZFukTyoz
    yIOrcqPQStRHdPidv3RLhBtixot5Y6FT0JW6YOVvWuUu6uu0uAPp5yWYKWjUtLnL
    rLPfr8sfMmgRvX/51MkvNxzpxcJops5fbZYwNJTKpcd7xl6ziQmq9OZOMPwNIWuA
    mfV+2aNtg6erO+8OK1HFtAvwwe6CDaibE9BYVxHvSAIfQv1DId9o6WoY4Xcx1IvO
    hwUqs/h1smPahnR12H8pQMxorUeQc1R5vHp6OeCh0lhEUs94YMu1XUjiaR536omC
    lqTKjneX9zm4w8krbOwld9F/mxedTg0v8aV9CbEDBgBu288qQL/eOWTIS3BjGI6Z
    Q5fAHpTiU8cgcbrV7Ng/Aox/nUiWNrnGdnG5jYTmh+Fh98qFeVldGQ8uw5UopXCC
    7Q3LUXmYh6R3Aw6MlDdU0Dw8omw3JItiNRIbbX+C7LtI3jjg+KI5YBDM/ELaU1SK
    kTiFSgj25feO0pDg+sgzKik=
    -----END CERTIFICATE-----
    subject=/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected]
    issuer=/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected]
    ---
    No client certificate CA names sent
    Peer signing digest: SHA512
    Server Temp Key: ECDH, P-256, 256 bits
    ---
    SSL handshake has read 2273 bytes and written 434 bytes
    ---
    New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
    Server public key is 4096 bit
    Secure Renegotiation IS supported
    Compression: NONE
    Expansion: NONE
    No ALPN negotiated
    SSL-Session:
        Protocol  : TLSv1.2
        Cipher    : ECDHE-RSA-AES256-GCM-SHA384
        Session-ID: D71981DA9CB6F36A233297A9D16D989D5FA5F5047FF62F9230D7F234323879F0
        Session-ID-ctx:
        Master-Key: 7755DBE8E91632A271C83AAEC068F48C68F4F8C78D4ACB523674F05CC0E1AF02064B357C1AC13AE4694967CC274BBABE
        Key-Arg   : None
        PSK identity: None
        PSK identity hint: None
        SRP username: None
        Start Time: 1538489545
        Timeout   : 300 (sec)
        Verify return code: 18 (self signed certificate)
    ---

    <junoscript xmlns="http://xml.juniper.net/xnm/1.1/xnm" xmlns:junos="http://xml.juniper.net/junos/15.1X49/junos" schemaLocation="http://xml.juniper.net/junos/15.1X49/junos junos/15.1X49/junos.xsd" os="JUNOS" release="15.1X49-D130.6" hostname="SRX1500" version="1.0">
  6.  Run a sample RPC to verify the connection is working.


    <junoscript version="1.0">
    <rpc>
    <request-login>
      <username> xxxxx
      <challenge-response> xxxxxx


    <rpc>
    <get-interface-information>
      <interface-name> ge-0/0/1
      <detail/>

    <rpc-reply xmlns:junos="http://xml.juniper.net/junos/15.1X49/junos">

    <authentication-response>
    <status> success
    <message> root