When enrolling an SRX device to ATP Cloud, the enrollment process might fail to complete successfully and return an error about the local certificate aamw-srx-cert key not existing.
The terminal output for enrollment contains the following errors.
...
Enroll local certificate aamw-srx-cert with CA server...
Configure SSL service...
error: [Error] Enrollment failed. Fail to set SSL services configuration.
Please run diagnostic process with the following cli command:
request services advanced-anti-malware diagnostics srxapi.atp-region.sky.junipersecurity.net detail pre-detection
Details:
nsd
certificate 'aamw-srx-cert': key does not exist .
1). This will occur if TPM is configured.
Check TPM status:
user@host> show security tpm status
TPM Status:
Enabled: yes
Owned: yes
Master Binding Key: created
Master Encryption Key: configured
TPM Family: 1.2
TPM Firmware version: 4.40
At this time, the original TPM module configuration is not supported with the ATP Cloud feature.
Only the following models which make use of the new Dev-ID with TPM 2.0 module support having TPM enabled alongside ATP cloud: SRX1600, SRX2300, SRX4300, SRX4700
2). Sometimes the commit gets stuck on the cluster and it does not allow the ssl services configuration to be successfully committed.
In this situation, we need to clear the stuck commit and then try to enroll the device to the cloud.
Documentation - Trusted Platform Module Overview