Software Installation and Upgrade
-
Secure Zero-Touch Provisioning (secure ZTP) (PTX10004, PTX10008, and PTX10016)—Starting in Junos OS Evolved Release 22.4R1, you can use RFC-8572-based secure ZTP to bootstrap your remotely located network devices that are in a factory-default state. Secure ZTP enables mutual authentication between the bootstrap server and the network device before the remote network device is accessed for initiating zero-touch provisioning.
To enable mutual authentication, you need a unique digital voucher, which is generated based on the DevID (Digital Device ID or Cryptographic Digital Identity) of the ntwork device. The DevID is embedded inside the Trusted Platform Module (TPM) 2.0 chip on the network device. Juniper Networks issues a digital voucher to customers for each eligible network device.
[See Secure Zero Touch Provisioning and Generate Voucher Certificate.]