This article explains how to make xnm-ssl connections over OPENSSL and execute RPC commands.
Generating Certificates using OpenSSL.
a) Most Linux distributions are pre-installed with OpenSSL. In this demo, we are generating a self-signed certificate. Alternatively, you can register the cert with CA.
c) Copy the contents of both the files into a single file. For the purpose of this demo, I am naming it cert_key.pem
$ openssl req -x509 -newkey rsa:4096 -keyout key1.pem -out cert1.pem -days 365 Generating a 4096 bit RSA private key ............................................................................... ..........++ writing new private key to 'key1.pem' Enter PEM pass phrase: xxxxxxx Verifying - Enter PEM pass phrase:
----- You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you can leave some blank For some fields there will be a default value, If you enter '.', the field will be left blank. ----- Country Name (2 letter code) [AU]:US State or Province Name (full name) [Some-State]:VA Locality Name (eg, city) []:Herndon Organization Name (eg, company) [Internet Widgits Pty Ltd]:Juniper
Copy the file "cert_key.pem" which contains both private key and cert to the Junos device which you want to establish openssl connection.
$ scp cert_key.pem [email protected]:/var/tmp Password: xxxxxx cert_key.pem 100% 5574 52.7KB/s 00:00
Load the copied file "cert_key.pem" to the Junos device as the local certificate. Note you will need to enter private key passphrase set during the generation of the cert in step 1.
root@SRX1500# set security certificates local <new_cert_key> load-key-file /var/tmp/cert_key.pem error: Private Key: Encrypted Enter private key passphrase:xxxxxx
Set the certificate to "xnm-ssl" system services connection type and commit the configuration.
root@SRX1500# set system services xnm-ssl local-certificate <new_cert_key> root@SRX1500# commit
Make xnm-ssl connection on port 3220 using openssl.
$ openssl s_client -connect 10.85.241.145:3220 CONNECTED(00000003) depth=0 C = US, ST = VA, L = Herndon, O = Juniper, OU = JTAC, CN = DB3017AK7638, emailAddress = [email protected] verify error:num=18:self signed certificate verify return:1 depth=0 C = US, ST = VA, L = Herndon, O = Juniper, OU = JTAC, CN = DB3017AK7638, emailAddress = [email protected] verify return:1 --- Certificate chain 0 s:/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected] i:/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected] --- Server certificate -----BEGIN CERTIFICATE----- MIIF3TCCA8WgAwIBAgIJAJCS9cB2UMR+MA0GCSqGSIb3DQEBCwUAMIGEMQswCQYD VQQGEwJVUzELMAkGA1UECAwCVkExEDAOBgNVBAcMB0hlcm5kb24xEDAOBgNVBAoM B0p1bmlwZXIxDTALBgNVBAsMBEpUQUMxFTATBgNVBAMMDERCMzAxN0FLNzYzODEe MBwGCSqGSIb3DQEJARYPYWJjQGp1bmlwZXIubmV0MB4XDTE4MTAwMjEzMjI0M1oX DTE5MTAwMjEzMjI0M1owgYQxCzAJBgNVBAYTAlVTMQswCQYDVQQIDAJWQTEQMA4G A1UEBwwHSGVybmRvbjEQMA4GA1UECgwHSnVuaXBlcjENMAsGA1UECwwESlRBQzEV MBMGA1UEAwwMREIzMDE3QUs3NjM4MR4wHAYJKoZIhvcNAQkBFg9hYmNAanVuaXBl ci5uZXQwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQDlNOf3BirJpDna n0S/U3Ai7soyJcRGzwoEk/R1V//LhIABAT0Us8HUCLQzVF5XV7meeaaq5iZNdQwB kt0zIRXxToYedG5to7ghnedW87j3A0eTaloyWofqW/ql8P7vNZklDTo1OZYfGsjZ JWlz0+f5bLw7wQwuk/Tb6N6NvWRDTii24s+geb/VzwzQyfmEIeXi0c2oS6gYYAjk i+XZBSSSiFFVaYXI1nAU9GcoKcQm8UYCsQqXVCEEXFqRTrTDxum7dRMnyod94oYJ i7s82SxxIN77v8W5ZDaiNSAq5/X+XeU2lvwTmkslYfoTJg4tazAngf3lmcfQbFAb L36J7Vj/7f+UwVEfi0FdiOH0SjtxG3o9baaZ7b0Gm29805jmCLXOV91J2ERO0yh5 TEvKk245xO5em9SrYEg0UoHOiXlsUq4KegdNLHNr8iH+4IIVj1ef9HUU1MOiQobv cuUiXuG/Vtl1gIUVZZCYYrQwrJ935QnW2ADZdQeXhx3zSazmJKUNTzmg0ad9dAtg XwyLFjj0ENmSvh53HpSm/ZktxSn/bZm5A8gLaWaINxGtj+rpZun16aa5rkHeaCuq ED0FHyvgrJKdM36WL/1+Z0gtGLK9bd5H32jkmsKzsc2Fu8t6lstZkxaV5Om39egh ZEhTVq88OT51QAhhLFzYkkB8iavroQIDAQABo1AwTjAdBgNVHQ4EFgQUaQpaR3P+ 0RCCrCz3dCdBZATRWNcwHwYDVR0jBBgwFoAUaQpaR3P+0RCCrCz3dCdBZATRWNcw DAYDVR0TBAUwAwEB/zANBgkqhkiG9w0BAQsFAAOCAgEAmd5vlNWmrA7mlj+r5aTS dTv99WYUllpfMgvOpRodfzJBGrMHqWqKxuzdPbXJIWy/QO5LJrh6waq04sf/4h5n IPs3cYi7uV3RC95SvjgB3Jzqwp0KhXDSYvuduEzdyD8bg37QbmFhOXi3xMnYrLLe J5ufi1HCC03n2pgdkv6WptKj/gbngtLU42LEAiC60mWonQJc/v4D/hveZFukTyoz yIOrcqPQStRHdPidv3RLhBtixot5Y6FT0JW6YOVvWuUu6uu0uAPp5yWYKWjUtLnL rLPfr8sfMmgRvX/51MkvNxzpxcJops5fbZYwNJTKpcd7xl6ziQmq9OZOMPwNIWuA mfV+2aNtg6erO+8OK1HFtAvwwe6CDaibE9BYVxHvSAIfQv1DId9o6WoY4Xcx1IvO hwUqs/h1smPahnR12H8pQMxorUeQc1R5vHp6OeCh0lhEUs94YMu1XUjiaR536omC lqTKjneX9zm4w8krbOwld9F/mxedTg0v8aV9CbEDBgBu288qQL/eOWTIS3BjGI6Z Q5fAHpTiU8cgcbrV7Ng/Aox/nUiWNrnGdnG5jYTmh+Fh98qFeVldGQ8uw5UopXCC 7Q3LUXmYh6R3Aw6MlDdU0Dw8omw3JItiNRIbbX+C7LtI3jjg+KI5YBDM/ELaU1SK kTiFSgj25feO0pDg+sgzKik= -----END CERTIFICATE----- subject=/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected] issuer=/C=US/ST=VA/L=Herndon/O=Juniper/OU=JTAC/CN=DB3017AK7638/[email protected] --- No client certificate CA names sent Peer signing digest: SHA512 Server Temp Key: ECDH, P-256, 256 bits --- SSL handshake has read 2273 bytes and written 434 bytes --- New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384 Server public key is 4096 bit Secure Renegotiation IS supported Compression: NONE Expansion: NONE No ALPN negotiated SSL-Session: Protocol : TLSv1.2 Cipher : ECDHE-RSA-AES256-GCM-SHA384 Session-ID: D71981DA9CB6F36A233297A9D16D989D5FA5F5047FF62F9230D7F234323879F0 Session-ID-ctx: Master-Key: 7755DBE8E91632A271C83AAEC068F48C68F4F8C78D4ACB523674F05CC0E1AF02064B357C1AC13AE4694967CC274BBABE Key-Arg : None PSK identity: None PSK identity hint: None SRP username: None Start Time: 1538489545 Timeout : 300 (sec) Verify return code: 18 (self signed certificate) --- <junoscript xmlns="http://xml.juniper.net/xnm/1.1/xnm" xmlns:junos="http://xml.juniper.net/junos/15.1X49/junos" schemaLocation="http://xml.juniper.net/junos/15.1X49/junos junos/15.1X49/junos.xsd" os="JUNOS" release="15.1X49-D130.6" hostname="SRX1500" version="1.0">
Run a sample RPC to verify the connection is working.
<junoscript version="1.0"> <rpc> <request-login> <username> xxxxx <challenge-response> xxxxxx <rpc> <get-interface-information> <interface-name> ge-0/0/1 <detail/> <rpc-reply xmlns:junos="http://xml.juniper.net/junos/15.1X49/junos"> <authentication-response> <status> success <message> root