show pki

Displays information on PKI, including information on certificates and other options.
Syntax
show pki{certificates{local|trustpoint}|counters| crls|enrollment-profile |entity|key|logging-statistics|trustpoint}
Parameters
certificates
Displays PKI certificates.
counters
Displays PKI counters.
crls
Displays the PKI certification revocation list if there is one.
enrollment-profile
Displays PKI enrollment profile.
entity
Displays PKI entity.
key
Displays router public keys.
logging-statistics
Displays PKI logging statistics.
trustpoint
Displays PKI trustpoint information.
Modes

User EXEC mode

Examples

The following example shows output for the show pki certificates local command.

device# show pki certificates local 
----------------PKI LOCAL CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4100 (0x1004)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
        Validity
            Not Before: Feb 23 16:19:43 2018 GMT
            Not After : Feb 21 16:19:43 2028 GMT
        Subject: CN=ICX RSA, ST=KA, C=IN, O=NEBU, OU=Ruckus Arris

The following example shows output for the show pki certificates trustpoint command.

device# show pki certificates trustpoint 
----------------PKI TRUSTPOINT CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e2:11:82:3f:37:c2:6f:c0
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
        Validity
            Not Before: Feb 23 05:38:11 2018 GMT
            Not After : Feb 23 05:38:11 2023 GMT
        Subject: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA

The following example shows output for the show pki counters command.

device# show pki counters
------------PKI-COUNTERS----------
PKI Sessions Started: 3701
PKI Sessions Ended: 3701
PKI Sessions Active: 0
Successful Validations: 35
Failed Validations: 3855
Bypassed Validations: 0
Pending Validations: 5
CRLs checked: 0
CRL - fetch attempts: 0
CRL - failed attempts: 0

The following example shows output for the show pki enrollment-profile command.

device# show pki enrollment-profile
----------------PKI ENROLLMENT PROFILE ENTRY-----------------
  Enrollment Profile: profile1
  Authentication Command: WINN6C3R0LUDAJ.
  Authentication URL: http://WINN6C3R0LUDAJ.
  Enrollment URL: http://ipfvt-mylab.englab.brocade.com/CertSrv/mscep/mscep.dll
  SCEP password: hellooutthere

The following example shows output for the show pki entity command.

device# show pki entity
----------------PKI ENTITY ENTRY-----------------
  Entity Name: spatha27
    Common Name: Spatha
    Organization Name: SQA
    Organization Unit Name: ICX
    State Name: KA
    Country Name: IN

----------------PKI ENTITY ENTRY-----------------
  Entity Name: ent1
    Common Name: en1
    State Name: KA
    Country Name: IN
    Location: BLR

----------------PKI ENTITY ENTRY-----------------
  Entity Name: entity1
    Common Name: tester1
    Organization Name: BRCD
    Organization Unit Name: FI
    State Name: BC                                                
    Country Name: CA
    Email: user@brocade.com
    Location: BG

The following example shows output for the show pki key command.

device#  show pki key mypubkey  all
----------------PKI PUBLIC KEY ENTRY-----------------
 Public key of generated EC key pair:
  The key label is marcia_ec
  Public-Key: (384 bit)
  pub: 
      04:61:f6:d4:bf:e0:85:8f:2f:70:e3:79:36:d9:22:
      98:ca:3e:6e:10:a3:cd:b9:0a:e9:2d:26:ce:a3:fc:
      96:c5:04:f7:28:6b:fa:fb:e1:36:51:4b:05:05:95:
      da:e7:14:5f:59:68:16:2b:fc:c7:a0:d6:a0:72:85:
      28:dd:54:10:1e:42:51:0d:8e:d7:6b:2f:92:cc:e2:
      ac:f6:f5:89:64:da:54:af:b5:26:e1:f6:a5:25:f2:
      a9:93:3c:9a:b8:93:5b
  ASN1 OID: secp384r1

The following example shows output for the show pki logging-statistics command.

device# show pki logging-statistics
------------------------PKI logging statistics-------------------------------
Type of packet:                     |    TX_PACKETS      |     RX_PACKETS   
------------------------------------|--------------------|------------------
enrollment packets:                 |       0            |          0
authentication packets:             |       1            |          1
revocation check packets:           |       116          |          0
peer certificate download packets:  |       0            |          0
certificate imports through http:   |       0            |          0
Note:enrollment packets can be 2x of actual enrollments depends on server settings

The following example shows output for the show pki trustpoint command.

device# show pki trustpoint  
----------------PKI TRUSTPOINT ENTRY-----------------
  CA: trustRSA
  Key Information:
    The key label is icx_rsa_key
    Public-Key: (2048 bit)
    Modulus:
        00:c5:81:6f:98:aa:f8:e4:a8:2d:d9:f3:d7:d0:e7:
        5e:be:59:4b:4c:d0:c9:aa:a8:53:82:dd:2f:df:09:
        c1:78:c5:38:63:c3:d7:73:47:ed:43:6c:d6:d1:ed:
        99:82:e7:51:c6:03:bc:8e:8f:97:e5:1b:b5:71:a1:
        46:f4:a8:b2:bb:6e:61:54:e2:42:1e:63:f8:79:78:
        6b:bd:d8:63:67:c1:b7:6f:78:cc:9d:16:42:df:81:
        d2:98:24:2b:70:60:10:ec:0e:5c:d9:be:7e:e1:a0:
        27:b8:e0:65:73:99:de:18:59:05:e7:7e:df:f1:1e:
        ac:ab:33:7a:7e:6e:d5:99:85:95:fc:c8:a7:1f:c3:
        d2:43:74:2e:c6:15:80:b6:fc:73:4c:23:30:2a:c1:
        26:d0:84:4c:58:96:0b:4c:1c:f0:87:cf:d3:28:68:
        0a:65:f7:fd:33:cb:92:c7:d5:8d:df:7b:9b:03:92:
        d8:75:03:1c:f6:1b:09:b3:6d:3c:2a:7e:6a:02:10:
        21:5c:46:87:46:73:57:7c:66:8f:a4:bb:a4:6b:ae:
        30:d2:63:a0:44:44:6b:48:e2:ab:8e:fa:d4:d7:f7:
        30:87:c1:11:ac:22:9f:e9:10:52:ee:22:70:c6:f7:
        6b:5b:eb:7f:f3:b3:01:a9:d6:25:10:97:1b:9d:7e:
        50:51
    Exponent: 65537 (0x10001)
  Configured Fingerprint for authentication:
    D8:BC:F5:94:BA:72:9D:F3:34:77:FD:AA:5B:A2:FD:B6:59:A3:00:27
  Enrollment Protocol:SCEP

----------------PKI TRUSTPOINT ENTRY-----------------
  CA: trust1
  Entity Name: entity1
    Common Name: tester1
    Organization Name: BRCD
    Organization Unit Name: FI
    State Name: BC
    Country Name: CA
    Email: user@brocade.com
    Location: BG
  Configured Fingerprint for authentication:
    d2:52:b6:5a:1d:a2:95:3b:f4:e6:05:33:84:05:97:16:75:15:bf:04
  Enrollment Protocol:SCEP
  Enrollment Profile: profile1
History
Release version Command history
08.0.70 This command was introduced.