Displaying PKI Information

Display PKI information including, certificates, CA status, certificate evocation lists, PKI counters, public keys, and current enrollment profiles, and PKI entities.

Enter the show pki trustpoint command to display information on configured trustpoints.

device# show pki trustpoint
----------------PKI TRUSTPOINT ENTRY-----------------
CA: trustRSA
Key Information:
The key label is icx_rsa_key
Public-Key: (2048 bit)
Modulus:
00:c5:81:6f:98:aa:f8:e4:a8:2d:d9:f3:d7:d0:e7:
5e:be:59:4b:4c:d0:c9:aa:a8:53:82:dd:2f:df:09:
c1:78:c5:38:63:c3:d7:73:47:ed:43:6c:d6:d1:ed:
99:82:e7:51:c6:03:bc:8e:8f:97:e5:1b:b5:71:a1:
46:f4:a8:b2:bb:6e:61:54:e2:42:1e:63:f8:79:78:
6b:bd:d8:63:67:c1:b7:6f:78:cc:9d:16:42:df:81:
d2:98:24:2b:70:60:10:ec:0e:5c:d9:be:7e:e1:a0:
27:b8:e0:65:73:99:de:18:59:05:e7:7e:df:f1:1e:
ac:ab:33:7a:7e:6e:d5:99:85:95:fc:c8:a7:1f:c3:
d2:43:74:2e:c6:15:80:b6:fc:73:4c:23:30:2a:c1:
26:d0:84:4c:58:96:0b:4c:1c:f0:87:cf:d3:28:68:
0a:65:f7:fd:33:cb:92:c7:d5:8d:df:7b:9b:03:92:
d8:75:03:1c:f6:1b:09:b3:6d:3c:2a:7e:6a:02:10:
21:5c:46:87:46:73:57:7c:66:8f:a4:bb:a4:6b:ae:
30:d2:63:a0:44:44:6b:48:e2:ab:8e:fa:d4:d7:f7:
30:87:c1:11:ac:22:9f:e9:10:52:ee:22:70:c6:f7:
6b:5b:eb:7f:f3:b3:01:a9:d6:25:10:97:1b:9d:7e:
50:51
Exponent: 65537 (0x10001)
Configured Fingerprint for authentication:
D8:BC:F5:94:BA:72:9D:F3:34:77:FD:AA:5B:A2:FD:B6:59:A3:00:27
Enrollment Protocol:SCEP
----------------PKI TRUSTPOINT ENTRY-----------------
CA: trust1
Entity Name: entity1
Common Name: tester1
Organization Name: BRCD
Organization Unit Name: FI
State Name: BC
Country Name: CA
Email: user@brocade.com
Location: BG
Configured Fingerprint for authentication:
d2:52:b6:5a:1d:a2:95:3b:f4:e6:05:33:84:05:97:16:75:15:bf:04
Enrollment Protocol:SCEP
Enrollment Profile: profile1

Enter the show pki certificates trustpoint command to display information on trustpoints and related certificates.

device# show pki certificates trustpoint
----------------PKI TRUSTPOINT CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
Data:
Version: 3 (0x2)
Serial Number:
e2:11:82:3f:37:c2:6f:c0
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
Validity
Not Before: Feb 23 05:38:11 2018 GMT
Not After : Feb 23 05:38:11 2023 GMT
Subject: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA

Enter the show pki certificates local command to display information about local certificates.

device# show pki certificates local
----------------PKI LOCAL CERTIFICATE ENTRY-----------------
CA: trustRSA
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 4100 (0x1004)
Signature Algorithm: sha256WithRSAEncryption
Issuer: C=IN, ST=KA, L=Bangalore, O=Ruckus Arris, OU=NEBU, CN=ROOT RSA
Validity
Not Before: Feb 23 16:19:43 2018 GMT
Not After : Feb 21 16:19:43 2028 GMT
Subject: CN=ICX RSA, ST=KA, C=IN, O=NEBU, OU=Ruckus Arris

Enter the show pki crls command followed by a trustpoint name to display the current certificate revocation lists on the specified trustpoint (trust1 in the following example).

device(config)# show pki crls trust1

Enter the show pki counters command to display the current PKI counters.

device# show pki counters
------------PKI-COUNTERS----------
PKI Sessions Started: 3701
PKI Sessions Ended: 3701
PKI Sessions Active: 0
Successful Validations: 35
Failed Validations: 3855
Bypassed Validations: 0
Pending Validations: 5
CRLs checked: 0
CRL - fetch attempts: 0
CRL - failed attempts: 0

Enter the show pki key mypubkey all command to display information about the current public keys on the router. You can choose to display only generated keys, manually imported keys, or all keys.

device# show pki key mypubkey all
----------------PKI PUBLIC KEY ENTRY-----------------
Public key of generated EC key pair:
The key label is marcia_ec
Public-Key: (384 bit)
pub:
04:61:f6:d4:bf:e0:85:8f:2f:70:e3:79:36:d9:22:
98:ca:3e:6e:10:a3:cd:b9:0a:e9:2d:26:ce:a3:fc:
96:c5:04:f7:28:6b:fa:fb:e1:36:51:4b:05:05:95:
da:e7:14:5f:59:68:16:2b:fc:c7:a0:d6:a0:72:85:
28:dd:54:10:1e:42:51:0d:8e:d7:6b:2f:92:cc:e2:
ac:f6:f5:89:64:da:54:af:b5:26:e1:f6:a5:25:f2:
a9:93:3c:9a:b8:93:5b
ASN1 OID: secp384r1

Enter the show pki enrollment-profile command followed by the profile name to display information about the specified enrollment profile.

device# show pki enrollment-profile profile1
----------------PKI ENROLLMENT PROFILE ENTRY-----------------
Enrollment Profile: profile1
Authentication Command: WINN6C3R0LUDAJ.
Authentication URL: http://WINN6C3R0LUDAJ.
Enrollment URL: http://ipfvt-mylab.englab.brocade.com/CertSrv/mscep/mscep.dll
SCEP password: hellooutthere

Enter the show pki entity command to display information on configured PKI entities.

device# show pki entity
----------------PKI ENTITY ENTRY-----------------
Entity Name: spatha27
Common Name: Spatha
Organization Name: SQA
Organization Unit Name: ICX
State Name: KA
Country Name: IN
----------------PKI ENTITY ENTRY-----------------
Entity Name: ent1
Common Name: en1
State Name: KA
Country Name: IN
Location: BLR
----------------PKI ENTITY ENTRY-----------------
Entity Name: entity1
Common Name: tester1
Organization Name: BRCD
Organization Unit Name: FI
State Name: BC
Country Name: CA
Email: user@brocade.com
Location: BG