Shows the raw openssl x509 output that is decoded from a valid X.509 certificate Privacy Enhanced Email (PEM) string. The command shows information about the PEM-encoded certificate, and errors that are found during the decoding process.
For details about how to configure a CA certificate bundle, refer to the Trellix System Security Guide.
Note
This command is not currently used on the Intelligent Virtual Execution - Server compute node.
Syntax
show crypto certificate decode raw pem ["<pem_string>"]
Parameters
pem_string
(Optional) The PEM-encrypted ASCII string of the certificate that is enclosed with double quotation marks.
Example
The following example shows the raw openssl x509 output that is decoded from a valid X.509 certificate PEM string.
hostname # show crypto certificate decode raw pem """-----BEGIN CERTIFICATE----- MIIFpTCCA42gAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwbTELMAkGA1UEBhMCVVMx EzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAoMC0ZpcmVleWUgSW5jMRQwEgYD ... vURBPtSwN1/pylT/1A6zyIHzrwWBxLUY01ycq3egkfIcGW/85OQJOx2SG4AzvrKR QIkfy/98EI8f -----END CERTIFICATE-----""" Certificate: Data: Version: 3 (0x2) Serial Number: 4096 (0x1000) Signature Algorithm: sha256WithRSAEncryption Issuer: C=US, ST=California, O=Fireeye Inc, OU=Engineering, CN=Buzz Intermediate CA Validity Not Before: Oct 27 22:20:09 2016 GMT Not After : Nov 6 22:20:09 2017 GMT Subject: C=US, ST=California, L=Milpitas, O=Fireeye Inc, OU=Engineering, CN=172.16.216.20 Subject Public Key Info: Public Key Algorithm: rsaEncryption Public-Key: (2048 bit) Modulus: 00:d4:49:53:c5:f4:e7:22:cd:86:57:c2:e1:78:f4: a4:c1:93:94:aa:35:8c:fa:c1:47:32:10:aa:c3:31: ... 4a:b5 Exponent: 65537 (0x10001) X509v3 extensions: X509v3 Basic Constraints: CA:FALSE Netscape Cert Type: SSL Server Netscape Comment: OpenSSL Generated Server Certificate X509v3 Subject Key Identifier: 94:FF:B7:E7:38:F6:62:3D:7C:2D:DC:1F:AF:D2:C7:DD:C4:96:6B:87 X509v3 Authority Key Identifier: keyid:21:01:9E:EE:8C:D9:0E:A3:61:35:8D:37:03:BB:33:26:4C:79:76:0E DirName:/C=US/ST=California/L=Milpitas/O=Fireeye Inc/OU=Engineering/CN=Buzz Root CA serial:10:00 X509v3 Key Usage: critical Digital Signature, Key Encipherment X509v3 Extended Key Usage: TLS Web Server Authentication Signature Algorithm: sha256WithRSAEncryption a0:b1:d7:fc:0e:ec:a7:f1:4d:81:c6:29:7b:51:7d:44:96:3a: 88:da:f0:c3:0d:dd:a2:d6:ea:48:58:c2:d2:ef:d1:9d:99:54: df:c5:9c:31:6e:bf:13:c3:7c:d6:26:ab:e5:62:88:e2:38:dd: ... 89:1f:cb:ff:7c:10:8f:1f
User role
Admin
Command mode
Enable
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Central Management System: Release 7.9.1
Network Security: Release 7.9.1
Endpoint Security (HX): Release 2.5
Intelligent Virtual Execution - Server: Release 7.9.1
Email Security — Server: Release 7.9.0