ca-profile (Security PKI)


ca-profile ca-profile-name {administrator {e-mail-address e-mail-address;}ca-identity ca-identity ;enrollment {retry number;retry-interval seconds;url url-name;}revocation-check {crl {disable {on-download-failure;}refresh-interval hours;url url-name;}disable;ocsp {connection-failure (disable | fallback-crl);disable-responder-revocation-check;nonce-payload (enable | disable);url ocsp-url;}use-ocsp;}routing-instance routing-instance-name ;}

Hierarchy Level

[edit security pki]

Release Information

Statement modified in Junos OS Release 8.5. Support for ocsp and use-ocsp options added in Junos OS Release 12.1X46-D20.


Configure certificate authority (CA) profile.


ca-profile-name —Name of a trusted CA.

The remaining statements are explained separately.

Required Privilege Level

security—To view this statement in the configuration.

security-control—To add this statement to the configuration.

Related Documentation