Viewing certificates using the CLI

Prev Next

Use the commands in this section to view certificate attributes, the certificate configuration, and the public key PEM string.

Viewing common attributes

To view common certificate attributes:
  1. Go to CLI enable mode:

    hostname > enable
  2. Display the attributes.

    • To view common information about all certificates:

      hostname # show crypto certificate
    • To view common attributes for a specific certificate:

      hostname # show crypto certificate name <certificateName>

Viewing all attributes

To view all certificate attributes:
  1. Go to CLI enable mode:

    hostname > enable
  2. Show the attributes.

    • To view all attributes for all certificates:

      hostname # show crypto certificate detail
    • To view all attributes for a specific certificate:

      hostname # show crypto certificate name <certificateName> detail 

Viewing the certificate configuration

To view the certificate configuration:
  1. Go to CLI enable mode:

    hostname > enable
  2. Show the configuration:

    hostname # show configuration
  3. Scroll to the X.509 certificates configuration section of the output.

Note

The command output indicates whether a private key is defined for each certificate. Private key PEM strings are omitted for security.

Viewing the public key PEM string

To view the public key PEM string:
  1. Go to CLI enable mode:

    hostname > enable
  2. Show the public key PEM string.

    • To view the source data for all certificates:

      hostname # show crypto certificate public-pem
    • To view the source data for a specific certificate:

      hostname # show crypto certificate name <certificateName> public-pem

Examples

Common attributes for all certificates

The following example shows common attributes for all certificates in the certificate database.

hostname # show crypto certificate
Certificate with name 'server' (default-cert)
   Private Key:                 present
   Serial Number:               0x71a676d9a1j5d8a316488f9d683kkc0
   SHA-1 Fingerprint:           7g04933d77491wgeg2h78d2a6f34s50cech324c78
   Validity:
      Starts:                  2015/02/26 15:40:47
      Expires:                 2017/11/21 15:40:47
   Issuer:
      Common Name:             acme-hostname
      Country:                 US
      State or Province:       NY
      Locality:                Albany
      Organization:            Acme, Inc
      Organizational Unit:     IT
   Issuer:
      Common Name:             Symantec Class 3 EV SSLCA - G3
      Country:                 US
      State or Province:       CA
      Locality:                Mountain View
      Organization:            Symantec Corporation
      Organizational Unit:     Symantec Trust Network
Certificate with name 'system-self-signed'
   Private Key:                 present
   Serial Number:               0x54a623d9a1f5d7a207788f2e683ffc0
   SHA-1 Fingerprint:           7k04833m77951wgjr2h94d2a6f34b60pgph984v43
   Validity:
      Starts:                  2015/04/22 15:40:47
      Expires:                 2016/04/21 15:40:47
   Subject:
      Common Name:             acme-hostname
      Country:                 US
      State or Province:       CA
      Locality:                Milpitas
      Organization:            FireEye, Inc.
      Organizational Unit:     Network Security Management
   Issuer:
      Common Name:             acme-hostname
      Country:                 US
      State or Province:       CA
      Locality:                Milpitas
      Organization:            FireEye, Inc.
      Organizational Unit:     Network Security Management

All attributes for a specific certificate

The following example shows all attributes for the system self-signed certificate.

hostname # show crypto certificate name system-self-signed detail
Certificate with name 'system-self-signed' (default-cert)
   Comment:                     system-generated self-signed certificate
   Private Key:                 present
   Serial Number:               0x54a623d9a1f5d7a207788f2e683ffc0
   SHA-1 Fingerprint:           7k04833m77951wgjr2h94d2a6f34b60pgph984v43
   Version:                     3
   Subject Public Key Algorithm: rsaEncryption
   Subject Public Key Length:   3072 bits
   Signature algorithm:         sha256WithRSAEncryption
   Validity:
      Starts:                  2015/04/22 15:40:47
      Expires:                 2016/04/21 15:40:47
   Subject: emailAddress=admin,CN=acme-hostname,OU=Network Security Management,O=FireEye\, Incl,L=Milpitas,ST=California,C=US
      Common Name:             acme-hostname
      Country:                 US
      State or Province:       CA
      Locality:                Milpitas
      Organization:            FireEye, Inc.
      Organizational Unit:     Network Security Management
      E-mail Address:          admin
   Issuer: emailAddress=admin,acme-hostname,OU=Network Security Management,O=FireEye\, Incl,L=Milpitas,ST=California,C=US
      Common Name:             acme-hostname
      Country:                 US
      State or Province:       CA
      Locality:                Milpitas
      Organization:            FireEye, Inc.
      Organizational Unit:     Network Security Management
      E-mail Address:          admin

Certificate configuration

The following example shows the certificate configuration for an appliance.

hostname # show configuration
...
##
## X.509 certificates configuration
##
## Certificate name system-self-signed, ID 9c077abarhb9e10d698c98e03431bbba410965b8
## (public-cert config omitted since private-key config is hidden)
  crypto certificate min-key-size 2048
  crypto certificate secure-hashes-only

##

Public key PEM string

The following example shows the public key PEM string for the "server" certificate.

hostname # show crypto certificate name server public-pem
-----BEGIN CERTIFICATE-----
MIIDuzCCAqOgAwIBAgIBADANBgkqhkiG9w0BAQUFADB4MQswCQYDVQQGEwJVUzEL
MAkGA1UECAwCQ0ExETAPBgNVBAcMCE1pbGlwdGFzMRQwEgYDVQQKDAtGaXJlRXll
IEluYzEUMBIGA1UECwwLRW5naW5lZXJpbmcxHTAbBgNVBAMMFHZwczEuZW5nLmZp
cmVleWUuY29tMB4XDTE1MDIyNjIzNDA0N1oXDTE3MTEyMTIzNDA0N1oweDELMAkG
A1UEBhMCVVMxCzAJBgNVBAgMAkNBMREwDwYDVQQHDAhNaWxpcHRhczEUMBIGA1UE
CgwLRmlyZUV5ZSBJbmMxFDASBgNVBAsMC0VuZ2luZWVyaW5nMR0wGwYDVQQDDBR2
cHMxLmVuZy5maXJlZXllLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAJt3LsgIYXyWiaRoAsLJnSxbQdwLuRZV74qEpVv1cRAwxymVu4/iXSWTFYmU
OZGFeHKK/2R/twISBHBhCuoGUYirg0KiM7bWmFPdAJXID6cAhPghkHwLHPTF4+Po
rXfc2m0W24G1Hi0o10oY7TPe2R5HctwGaoVtQ3znzESsuXKl+8qF+UVaP6qliDeX
Qyc9h/rGLQE50+9jluq1sWHfhszi4ireTqTu18iZesOeWSW+XzVcPRFy8pxwRMoW
w52Eczz2tZNudw2Bnozx25xlOIUvMLvrWeSenonqnrnQBPAtm7g/kBmSE4eHX7cr
D6KxczmuCvAfIZLZBibM2Vu6slUCAwEAAaNQME4wHQYDVR0OBBYEFMT6ayAuFjvN
7yVCVXMQX8Pgd3YtMB8GA1UdIwQYMBaAFMT6ayAuFjvN7yVCVXMQX8Pgd3YtMAwG
A1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAHTmrw4j6s0ut72n8P1pzGuD
6OYnuufKkHDaCC58g7OMMeOMu11XWScCy/44q2WMs1oNhKrcQHivHilKrAXB8Str
a2bSHcWutnu1OamRmglrkFmhS10NrNUIu5OwluTO3QF7FxA1EBwqEJ/8YrKhQb4p
aL4b0xRuNleRmy4GnR/k3a7Jllf9/qnpXYWIdtkyHOqx/854wxsdOiZYU9U1ZYEe
4Es9hEk5pkRvnioS0lJZWTGmt9a0EjpgZXIMcSxukeyZ4UPKaie8gypIPtK+ia9e
vXwAvTn745uZs06piroFhIOkPkG1H4pahgdi4uPntSosmHI63i0bc9VnN7QK0Rg=
-----END CERTIFICATE-----