show crypto certificate decode raw pem

Prev Next

Shows the raw openssl x509 output that is decoded from a valid X.509 certificate Privacy Enhanced Email (PEM) string. The command shows information about the PEM-encoded certificate, and errors that are found during the decoding process.

For details about how to configure a CA certificate bundle, refer to the Trellix System Security Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

show crypto certificate decode raw pem ["<pem_string>"]

Parameters

pem_string

(Optional) The PEM-encrypted ASCII string of the certificate that is enclosed with double quotation marks.

Example

The following example shows the raw openssl x509 output that is decoded from a valid X.509 certificate PEM string.

hostname # show crypto certificate decode raw pem
"""-----BEGIN CERTIFICATE-----
MIIFpTCCA42gAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwbTELMAkGA1UEBhMCVVMx
EzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAoMC0ZpcmVleWUgSW5jMRQwEgYD
...
vURBPtSwN1/pylT/1A6zyIHzrwWBxLUY01ycq3egkfIcGW/85OQJOx2SG4AzvrKR
QIkfy/98EI8f
-----END CERTIFICATE-----"""
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4096 (0x1000)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=California, O=Fireeye Inc, OU=Engineering, CN=Buzz Intermediate CA
        Validity
            Not Before: Oct 27 22:20:09 2016 GMT
            Not After : Nov  6 22:20:09 2017 GMT
    Subject: C=US, ST=California, L=Milpitas, O=Fireeye Inc, OU=Engineering, CN=172.16.216.20
    Subject Public Key Info:
        Public Key Algorithm: rsaEncryption
            Public-Key: (2048 bit)
            Modulus:
                00:d4:49:53:c5:f4:e7:22:cd:86:57:c2:e1:78:f4:
                a4:c1:93:94:aa:35:8c:fa:c1:47:32:10:aa:c3:31:
                ...
                4a:b5
            Exponent: 65537 (0x10001)
    X509v3 extensions:
        X509v3 Basic Constraints:
            CA:FALSE
        Netscape Cert Type:
            SSL Server
        Netscape Comment:
            OpenSSL Generated Server Certificate
        X509v3 Subject Key Identifier:
            94:FF:B7:E7:38:F6:62:3D:7C:2D:DC:1F:AF:D2:C7:DD:C4:96:6B:87
        X509v3 Authority Key Identifier:
        keyid:21:01:9E:EE:8C:D9:0E:A3:61:35:8D:37:03:BB:33:26:4C:79:76:0E
        DirName:/C=US/ST=California/L=Milpitas/O=Fireeye Inc/OU=Engineering/CN=Buzz Root CA
        serial:10:00
        X509v3 Key Usage: critical
            Digital Signature, Key Encipherment
        X509v3 Extended Key Usage:
            TLS Web Server Authentication
        Signature Algorithm: sha256WithRSAEncryption
             a0:b1:d7:fc:0e:ec:a7:f1:4d:81:c6:29:7b:51:7d:44:96:3a:
             88:da:f0:c3:0d:dd:a2:d6:ea:48:58:c2:d2:ef:d1:9d:99:54:
             df:c5:9c:31:6e:bf:13:c3:7c:d6:26:ab:e5:62:88:e2:38:dd:
             ...
             89:1f:cb:ff:7c:10:8f:1f

User role

Admin

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Network Security: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0