show pki

Displays information on PKI, including information on certificates and other options.
Syntax
show pki { certificates { local | trustpoint } | counters | crls | enrollment-profile | entity | key | logging-statistics | trustpoint }
Parameters
certificates
Displays PKI certificates.
counters
Displays PKI counters.
crls
Displays the PKI certification revocation list if there is one.
enrollment-profile
Displays PKI enrollment profile.
entity
Displays PKI entity.
key
Displays router public keys.
logging-statistics
Displays PKI logging statistics.
trustpoint
Displays PKI trustpoint information.
Modes

User EXEC mode

Is the command available in other modes? What are they?

Examples

The following example shows output for the show pki certificates local command.

device# show pki certificates local 
----------------PKI LOCAL CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4100 (0x1004)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
        Validity
            Not Before: Feb 23 16:19:43 2018 GMT
            Not After : Feb 21 16:19:43 2028 GMT
        Subject: CN=ICX RSA, ST=KA, C=IN, O=NEBU, OU=Ruckus Arris

The following example shows output for the show pki certificates trustpoint command.

device# show pki certificates trustpoint 
----------------PKI TRUSTPOINT CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number:
            e2:11:82:3f:37:c2:6f:c0
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
        Validity
            Not Before: Feb 23 05:38:11 2018 GMT
            Not After : Feb 23 05:38:11 2023 GMT
        Subject: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA

The following example shows output for the show pki counters command.

device# show pki counters
------------PKI-COUNTERS----------
PKI Sessions Started: 3701
PKI Sessions Ended: 3701
PKI Sessions Active: 0
Successful Validations: 35
Failed Validations: 3855
Bypassed Validations: 0
Pending Validations: 5
CRLs checked: 0
CRL - fetch attempts: 0
CRL - failed attempts: 0

The following example shows output for the show pki enrollment-profile command.

device# show pki enrollment-profile
----------------PKI ENROLLMENT PROFILE ENTRY-----------------
  Enrollment Profile: profile1
  Authentication Command: WINN6C3R0LUDAJ.
  Authentication URL: http://WINN6C3R0LUDAJ.
  Enrollment URL: http://ipfvt-mylab.englab.brocade.com/CertSrv/mscep/mscep.dll
  SCEP password: hellooutthere

The following example shows output for the show pki entity command.

device# show pki entity
----------------PKI ENTITY ENTRY-----------------
  Entity Name: spatha27
    Common Name: Spatha
    Organization Name: SQA
    Organization Unit Name: ICX
    State Name: KA
    Country Name: IN

----------------PKI ENTITY ENTRY-----------------
  Entity Name: ent1
    Common Name: en1
    State Name: KA
    Country Name: IN
    Location: BLR

----------------PKI ENTITY ENTRY-----------------
  Entity Name: entity1
    Common Name: tester1
    Organization Name: BRCD
    Organization Unit Name: FI
    State Name: BC                                                
    Country Name: CA
    Email: user@brocade.com
    Location: BG

The following example shows output for the show pki key command.

device#  show pki key mypubkey  all
----------------PKI PUBLIC KEY ENTRY-----------------
 Public key of generated EC key pair:
  The key label is marcia_ec
  Public-Key: (384 bit)
  pub: 
      04:61:f6:d4:bf:e0:85:8f:2f:70:e3:79:36:d9:22:
      98:ca:3e:6e:10:a3:cd:b9:0a:e9:2d:26:ce:a3:fc:
      96:c5:04:f7:28:6b:fa:fb:e1:36:51:4b:05:05:95:
      da:e7:14:5f:59:68:16:2b:fc:c7:a0:d6:a0:72:85:
      28:dd:54:10:1e:42:51:0d:8e:d7:6b:2f:92:cc:e2:
      ac:f6:f5:89:64:da:54:af:b5:26:e1:f6:a5:25:f2:
      a9:93:3c:9a:b8:93:5b
  ASN1 OID: secp384r1

The following example shows output for the show pki logging-statistics command.

device# show pki logging-statistics
------------------------PKI logging statistics-------------------------------
Type of packet:                     |    TX_PACKETS      |     RX_PACKETS   
------------------------------------|--------------------|------------------
enrollment packets:                 |       0            |          0
authentication packets:             |       1            |          1
revocation check packets:           |       116          |          0
peer certificate download packets:  |       0            |          0
certificate imports through http:   |       0            |          0
Note:enrollment packets can be 2x of actual enrollments depends on server settings

The following example shows output for the show pki trustpoint command.

device# show pki trustpoint  
----------------PKI TRUSTPOINT ENTRY-----------------
  CA: trustRSA
  Key Information:
    The key label is icx_rsa_key
    Public-Key: (2048 bit)
    Modulus:
        00:c5:81:6f:98:aa:f8:e4:a8:2d:d9:f3:d7:d0:e7:
        5e:be:59:4b:4c:d0:c9:aa:a8:53:82:dd:2f:df:09:
        c1:78:c5:38:63:c3:d7:73:47:ed:43:6c:d6:d1:ed:
        99:82:e7:51:c6:03:bc:8e:8f:97:e5:1b:b5:71:a1:
        46:f4:a8:b2:bb:6e:61:54:e2:42:1e:63:f8:79:78:
        6b:bd:d8:63:67:c1:b7:6f:78:cc:9d:16:42:df:81:
        d2:98:24:2b:70:60:10:ec:0e:5c:d9:be:7e:e1:a0:
        27:b8:e0:65:73:99:de:18:59:05:e7:7e:df:f1:1e:
        ac:ab:33:7a:7e:6e:d5:99:85:95:fc:c8:a7:1f:c3:
        d2:43:74:2e:c6:15:80:b6:fc:73:4c:23:30:2a:c1:
        26:d0:84:4c:58:96:0b:4c:1c:f0:87:cf:d3:28:68:
        0a:65:f7:fd:33:cb:92:c7:d5:8d:df:7b:9b:03:92:
        d8:75:03:1c:f6:1b:09:b3:6d:3c:2a:7e:6a:02:10:
        21:5c:46:87:46:73:57:7c:66:8f:a4:bb:a4:6b:ae:
        30:d2:63:a0:44:44:6b:48:e2:ab:8e:fa:d4:d7:f7:
        30:87:c1:11:ac:22:9f:e9:10:52:ee:22:70:c6:f7:
        6b:5b:eb:7f:f3:b3:01:a9:d6:25:10:97:1b:9d:7e:
        50:51
    Exponent: 65537 (0x10001)
  Configured Fingerprint for authentication:
    D8:BC:F5:94:BA:72:9D:F3:34:77:FD:AA:5B:A2:FD:B6:59:A3:00:27
  Enrollment Protocol:SCEP

----------------PKI TRUSTPOINT ENTRY-----------------
  CA: trust1
  Entity Name: entity1
    Common Name: tester1
    Organization Name: BRCD
    Organization Unit Name: FI
    State Name: BC
    Country Name: CA
    Email: user@brocade.com
    Location: BG
  Configured Fingerprint for authentication:
    d2:52:b6:5a:1d:a2:95:3b:f4:e6:05:33:84:05:97:16:75:15:bf:04
  Enrollment Protocol:SCEP
  Enrollment Profile: profile1
History
Release version Command history
08.0.70 This command was introduced.