show pki certificate

Use this command to display certificate lists and certificate details.

Syntax

show pki certificate [pki-cert-list [fingerprint]]

Parameters

pki-cert-list (Optional) Specifies the name of the certificate list to display.
fingerprint (Optional) Specifies a specific public key fingerprint member of a certificate list to display. This options displays certificate information details as defined in RFC 5280.

Defaults

  • If pki-cert-list is not specified, all configured certificate lists display.
  • If fingerprint is not specified, all members of the specified certificate list display.

Mode

All command modes.

Examples

This example shows how to display the fingerprint a2:33:a9:df:df:8a:fb:9a:d2:f0:5e:c0:c3:8a:8a:4b:
ad:0a:6f:1b member of the myTrustedOcspSigningCerts list:

System(rw)->show pki certificate myTrustedOcspSigningCerts a2:33:a9:df:df:8a:fb:9a:d2:f0:5e:c0:c3:8a:8a:4b:ad:0a:6f:1b
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4 (0x4)
        Signature Algorithm: sha1WithRSAEncryption
        Issuer: C=US, O=Enterasys, OU=DoD, OU=PKI, CN=Esys JITC Root CA 2
        Validity
            Not Before: Feb 21 18:44:14 2012 GMT
            Not After : Feb 18 18:44:14 2022 GMT
        Subject: C=US, O=Enterasys, OU=DoD, OU=PKI, CN=Esys JITC Root CA 2 OCSP Delegate 2
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
            RSA Public Key: (2048 bit)
                Modulus (2048 bit):
                    00:ab:de:7f:15:88:a1:44:47:ff:7d:a2:c3:c9:92:
                    eb:83:08:73:49:34:fb:ff:33:37:69:47:7f:fb:3e:
                    4f:e3:1b:aa:59:94:aa:b8:82:03:1d:89:7c:21:8c:
                    d6:37:29:81:00:78:81:d3:14:d1:fa:8c:b2:06:f5:
                    ...
                    17:79:31:f9:ac:9f:c7:46:98:bc:51:ae:9e:88:ba:
                    46:b1
                Exponent: 65537 (0x10001)
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature, Certificate Sign, CRL Sign
            X509v3 Authority Key Identifier:
                keyid:57:24:01:5D:5B:25:E3:78:42:B2:47:DF:3F:7B:F9:83:90:CA:B2:E0
                DirName:/C=US/O=Enterasys/OU=DoD/OU=PKI/CN=Esys JITC Root CA 2
                serial:05
            X509v3 Subject Key Identifier:
                4B:D3:68:BB:FF:4A:6D:7D:87:17:31:5C:B1:6A:89:7F:71:E4:97:22
            X509v3 Basic Constraints: critical
                CA:FALSE
            X509v3 Extended Key Usage:
                OCSP Signing
            OCSP No Check:
    Signature Algorithm: sha1WithRSAEncryption
        97:29:e9:f6:b1:7b:fa:f0:06:80:ec:92:b5:b8:98:55:0f:dc:
        51:b9:6c:3b:3b:e2:77:43:cc:c0:e0:1f:c1:33:9b:e4:86:26:
        ...
        ef:36:72:6b:e4:b2:7e:c6:ac:f4:81:f4:83:24:1d:fc:e5:94:
        cc:ea:8e:1b
-----BEGIN TRUSTED CERTIFICATE-----
MIIELjCCAxagAwIBAgIBBDANBgkqhkiG9w0BAQUFADBbMQswCQYDVQQGEwJVUzES
MBAGA1UEChMJRW50ZXJhc3lzMQwwCgYDVQQLEwNEb0QxDDAKBgNVBAsTA1BLSTEc
MBoGA1UEAxMTRXN5cyBKSVRDIFJvb3QgQ0EgMjAeFw0xMjAyMjExODQ0MTRaFw0y
MjAyMTgxODQ0MTRaMGsxCzAJBgNVBAYTAlVTMRIwEAYDVQQKEwlFbnRlcmFzeXMx
DDAKBgNVBAsTA0RvRDEMMAoGA1UECxMDUEtJMSwwKgYDVQQDEyNFc3lzIEpJVEMg
Um9vdCBDQSAyIE9DU1AgRGVsZWdhdGUgMjCCASIwDQYJKoZIhvcNAQEBBQADggEP
ADCCAQoCggEBAKvefxWIoURH/32iw8mS64MIc0k0+/8zN2lHf/s+T+MbqlmUqriC
Ax2JfCGM1jcpgQB4gdMU0fqMsgb1aQ5Vy3adtAzj7jZ9IS3OmX2O0ZBRi4rXr1dg
NukkfOdSBg68/pzzjdaZEsbeeXNdZnbtlemex+9KvBJ9TLw8pt4ZxQF12AIulRAI
Ov4WVcpnHHQL7WAcEcF56xqcYLkDYKDHhqkwanM8kEnHptWvTVqv9hEr054wu88a
lqzPYLnhNdY8mqsOAFuBM/kJcblSZjb+VI4bfwOAAn/SikbBqn9+9jG4lE1WUPDB
sWIdfZt6p+7tF3kx+ayfx0aYvFGunoi6RrECAwEAAaOB7DCB6TAOBgNVHQ8BAf8E
BAMCAYYwgYMGA1UdIwR8MHqAFFckAV1bJeN4QrJH3z97+YOQyrLgoV+kXTBbMQsw
CQYDVQQGEwJVUzESMBAGA1UEChMJRW50ZXJhc3lzMQwwCgYDVQQLEwNEb0QxDDAK
BgNVBAsTA1BLSTEcMBoGA1UEAxMTRXN5cyBKSVRDIFJvb3QgQ0EgMoIBBTAdBgNV
HQ4EFgQUS9Nou/9KbX2HFzFcsWqJf3HklyIwDAYDVR0TAQH/BAIwADATBgNVHSUE
DDAKBggrBgEFBQcDCTAPBgkrBgEFBQcwAQUEAgUAMA0GCSqGSIb3DQEBBQUAA4IB
AQCXKen2sXv68AaA7JK1uJhVD9xRuWw7O+J3Q8zA4B/BM5vkhiZZMK+Ro70HaQSI
ebAjrXsZ1VUD1pS5nkud2TawYwICyL8jxxbIX9nnIC6esr9shmCaxv/pCXMI5iZr
3zPism/n8OJpk6ZR75F/8Tnt8lUXrSFvJdwxb76nFR6zPStNorSuSgrZaGtmftUj
xZs7/PKXxWoryZmfua6oIg7SACWApBSu6Jhj7lgS6wAvow4K3WCbso+afmnpcNT7
kMkWJO7J4jUaKS/yjn8xkO2HhZZ+g1Lh1lK00i+hOx515aUHj2DpxMNQtiTvNnJr
5LJ+xqz0gfSDJB385ZTM6o4b
-----END TRUSTED CERTIFICATE-----
System(rw)->