Use the commands in this section to view certificate attributes, the certificate configuration, and the public key PEM string.
Viewing common attributes
Go to CLI enable mode:
hostname > enableDisplay the attributes.
To view common information about all certificates:
hostname # show crypto certificateTo view common attributes for a specific certificate:
hostname # show crypto certificate name <certificateName>
Viewing all attributes
Go to CLI enable mode:
hostname > enableShow the attributes.
To view all attributes for all certificates:
hostname # show crypto certificate detailTo view all attributes for a specific certificate:
hostname # show crypto certificate name <certificateName> detail
Viewing the certificate configuration
Go to CLI enable mode:
hostname > enableShow the configuration:
hostname # show configurationScroll to the
X.509 certificates configurationsection of the output.
Note
The command output indicates whether a private key is defined for each certificate. Private key PEM strings are omitted for security.
Viewing the public key PEM string
Go to CLI enable mode:
hostname > enableShow the public key PEM string.
To view the source data for all certificates:
hostname # show crypto certificate public-pemTo view the source data for a specific certificate:
hostname # show crypto certificate name <certificateName> public-pem
Examples
Common attributes for all certificates
The following example shows common attributes for all certificates in the certificate database.
hostname # show crypto certificate
Certificate with name 'server' (default-cert)
Private Key: present
Serial Number: 0x71a676d9a1j5d8a316488f9d683kkc0
SHA-1 Fingerprint: 7g04933d77491wgeg2h78d2a6f34s50cech324c78Validity: Starts: 2015/02/26 15:40:47 Expires: 2017/11/21 15:40:47
Issuer: Common Name: acme-hostname Country: US State or Province: NY Locality: Albany Organization: Acme, Inc Organizational Unit: IT
Issuer: Common Name: Symantec Class 3 EV SSLCA - G3 Country: US State or Province: CA Locality: Mountain View Organization: Symantec Corporation Organizational Unit: Symantec Trust Network
Certificate with name 'system-self-signed' Private Key: present Serial Number: 0x54a623d9a1f5d7a207788f2e683ffc0 SHA-1 Fingerprint: 7k04833m77951wgjr2h94d2a6f34b60pgph984v43
Validity: Starts: 2015/04/22 15:40:47 Expires: 2016/04/21 15:40:47
Subject: Common Name: acme-hostname Country: US State or Province: CA Locality: Milpitas Organization: FireEye, Inc. Organizational Unit: Network Security Management
Issuer: Common Name: acme-hostname Country: US State or Province: CA Locality: Milpitas Organization: FireEye, Inc. Organizational Unit: Network Security Management
All attributes for a specific certificate
The following example shows all attributes for the system self-signed certificate.
hostname # show crypto certificate name system-self-signed detail
Certificate with name 'system-self-signed' (default-cert)
Comment: system-generated self-signed certificate
Private Key: present
Serial Number: 0x54a623d9a1f5d7a207788f2e683ffc0
SHA-1 Fingerprint: 7k04833m77951wgjr2h94d2a6f34b60pgph984v43
Version: 3
Subject Public Key Algorithm: rsaEncryption
Subject Public Key Length: 3072 bits
Signature algorithm: sha256WithRSAEncryptionValidity: Starts: 2015/04/22 15:40:47 Expires: 2016/04/21 15:40:47
Subject: emailAddress=admin,CN=acme-hostname,OU=Network Security Management,O=FireEye\, Incl,L=Milpitas,ST=California,C=US Common Name: acme-hostname Country: US State or Province: CA Locality: Milpitas Organization: FireEye, Inc. Organizational Unit: Network Security Management E-mail Address: admin
Issuer: emailAddress=admin,acme-hostname,OU=Network Security Management,O=FireEye\, Incl,L=Milpitas,ST=California,C=US Common Name: acme-hostname Country: US State or Province: CA Locality: Milpitas Organization: FireEye, Inc. Organizational Unit: Network Security Management E-mail Address: admin
Certificate configuration
The following example shows the certificate configuration for an appliance.
hostname # show configuration
...
##
## X.509 certificates configuration
##
## Certificate name system-self-signed, ID 9c077abarhb9e10d698c98e03431bbba410965b8
## (public-cert config omitted since private-key config is hidden)
crypto certificate min-key-size 2048
crypto certificate secure-hashes-only
##Public key PEM string
The following example shows the public key PEM string for the "server" certificate.
hostname # show crypto certificate name server public-pem
-----BEGIN CERTIFICATE-----
MIIDuzCCAqOgAwIBAgIBADANBgkqhkiG9w0BAQUFADB4MQswCQYDVQQGEwJVUzEL
MAkGA1UECAwCQ0ExETAPBgNVBAcMCE1pbGlwdGFzMRQwEgYDVQQKDAtGaXJlRXll
IEluYzEUMBIGA1UECwwLRW5naW5lZXJpbmcxHTAbBgNVBAMMFHZwczEuZW5nLmZp
cmVleWUuY29tMB4XDTE1MDIyNjIzNDA0N1oXDTE3MTEyMTIzNDA0N1oweDELMAkG
A1UEBhMCVVMxCzAJBgNVBAgMAkNBMREwDwYDVQQHDAhNaWxpcHRhczEUMBIGA1UE
CgwLRmlyZUV5ZSBJbmMxFDASBgNVBAsMC0VuZ2luZWVyaW5nMR0wGwYDVQQDDBR2
cHMxLmVuZy5maXJlZXllLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoC
ggEBAJt3LsgIYXyWiaRoAsLJnSxbQdwLuRZV74qEpVv1cRAwxymVu4/iXSWTFYmU
OZGFeHKK/2R/twISBHBhCuoGUYirg0KiM7bWmFPdAJXID6cAhPghkHwLHPTF4+Po
rXfc2m0W24G1Hi0o10oY7TPe2R5HctwGaoVtQ3znzESsuXKl+8qF+UVaP6qliDeX
Qyc9h/rGLQE50+9jluq1sWHfhszi4ireTqTu18iZesOeWSW+XzVcPRFy8pxwRMoW
w52Eczz2tZNudw2Bnozx25xlOIUvMLvrWeSenonqnrnQBPAtm7g/kBmSE4eHX7cr
D6KxczmuCvAfIZLZBibM2Vu6slUCAwEAAaNQME4wHQYDVR0OBBYEFMT6ayAuFjvN
7yVCVXMQX8Pgd3YtMB8GA1UdIwQYMBaAFMT6ayAuFjvN7yVCVXMQX8Pgd3YtMAwG
A1UdEwQFMAMBAf8wDQYJKoZIhvcNAQEFBQADggEBAHTmrw4j6s0ut72n8P1pzGuD
6OYnuufKkHDaCC58g7OMMeOMu11XWScCy/44q2WMs1oNhKrcQHivHilKrAXB8Str
a2bSHcWutnu1OamRmglrkFmhS10NrNUIu5OwluTO3QF7FxA1EBwqEJ/8YrKhQb4p
aL4b0xRuNleRmy4GnR/k3a7Jllf9/qnpXYWIdtkyHOqx/854wxsdOiZYU9U1ZYEe
4Es9hEk5pkRvnioS0lJZWTGmt9a0EjpgZXIMcSxukeyZ4UPKaie8gypIPtK+ia9e
vXwAvTn745uZs06piroFhIOkPkG1H4pahgdi4uPntSosmHI63i0bc9VnN7QK0Rg=
-----END CERTIFICATE-----