Hi;
the initial certificate request is not generated from this SSG140 device, as what you mentioned, it is from other computer, I export the cert with the key. This is the way I did for the another non Juniper firewall, it works for that.
For the SSG140, can I import any pfx file to the device?