show ip ssl (FIPS)
Displays SSL connection details.
Parameters
Modes
Privileged EXEC mode (with FIPS enabled)
Global configuration mode (with FIPS enabled)
Examples
The following example displays the output of the
show ip ssl command.
device(config)# show ip ssl Session Protocol Source IP Source Port Remote IP Remote Port 1 TLS_1_2 10.20.157.102 634 10.25.105.201 60892
The following example displays output for the
show ip ssl profile command.
device# show ip ssl profile SSL Profile Information: ******************************************** Profile Name : LINUX-END Trustpoint Name: TLS-LINUX Remote Domain : LINUX-END ******************************************** Profile Name : LINUX-END-SAN Trustpoint Name: TLS-LINUX Remote Domain : LINUX-END-SAN ******************************************** Profile Name : p1 Trustpoint Name: TLS-LINUX Remote Domain : example.com ******************************************** Profile Name : p2 Trustpoint Name: TLS-LINUX Remote Domain : ruckus.com ******************************************** Profile Name : p3 Trustpoint Name: auto Remote Domain : gss.example.com ******************************************** Profile Name : p4 Trustpoint Name: TLS-LINUX Remote Domain : *.example.com ******************************************** Profile Name : p5 Trustpoint Name: TLS-LINUX Remote Domain : LINUX-SERVER-SAN ******************************************** Profile Name : p6 Trustpoint Name: TLS-LINUX Remote Domain : LINUX-SERVER-CC ********************************************
The following example displays SSL certificate details.
device(config)# show ip ssl certificate
Trusted Certificates:
Dynamic:
Index 0:
Signature Algorithm: sha256WithRSAEncryption
Issuer:
CN: 10.25.105.201
Validity:
Not Before: 2014 Aug 22 05:12:45
Not After : 2017 Aug 21 05:12:45
Subject:
CN: 10.25.105.201
X509v3 extensions:
X509v3 Subject Alternative Name:
IP Address: 10.25.105.201
Signature:
12:ec:41:d8:01:45:61:ce:cf:7e:80:de:a6:7c:a7:2e:01:7f:
42:27:22:1d:ac:a2:47:c5:0d:4f:e3:68:24:de:bf:50:40:65:
25:8c:30:bd:ff:a7:d0:21:73:d2:ba:5e:67:42:1f:bb:97:4a:
d9:1d:c3:ca:31:c4:59:10:79:d1:42:f4:b6:1a:b0:98:4e:a8:
ef:e2:a2:98:c3:14:16:63:50:02:a0:18:9c:7a:e3:17:39:0d:
b7:30:ab:23:9f:63:bd:0f:9e:d8:67:b0:fe:ec:3b:fa:4c:f4:
3d:34:e2:99:0e:99:24:ec:93:fb:8a:e5:4a:bf:74:d6:ff:91:
0a:dc:fb:b9:4f:91:5d:d4:f6:77:23:eb:ec:eb:3a:62:08:e1:
a6:ea:a8:52:b6:39:62:db:29:fa:61:1d:fd:d5:02:31:04:73:
50:ad:de:41:54:a5:e2:96:2d:9c:f4:68:b2:68:05:bb:39:47:
ee:74:89:a2:8c:30:f0:f9:d7:d5:4b:3b:e2:95:6f:82:61:a3:
c2:79:4c:f2:11:56:f8:2f:cc:fc:2b:4b:cb:3b:54:59:f0:8b:
5b:70:e1:27:c3:57:25:eb:35:c6:07:ea:6d:0b:34:04:95:81:
35:e6:64:c6:b8:72:e8:24:18:bd:ca:90:99:74:45:44:85:71:
9e:7f:13:96:
The following example displays SSL client certificate information.
device(config)# show ip ssl client-certificate SSL Client Certificates: ********************************************************* Trustpoint Name: TLS-LINUX Signature Algorithm: sha256WithRSAEncryption Issuer: CN: ROOTCA-CC Validity: Not Before: 2017 Nov 6 18:24:18 Not After : 2018 Nov 16 18:24:18 Subject: CN: DUTFIPSCC Signature: 76:24:88:c3:07:f3:37:e0:c7:06:17:a8:39:03:ad:ad:d8:ee: f0:76:ac:4f:5b:08:d6:3b:0c:3d:36:b4:1e:ac:cd:b7:76:2b: a7:7e:22:94:63:56:5b:88:64:3a:62:a8:80:c7:b4:57:8d:a8: 51:1c:34:7c:b4:27:d2:92:9f:f2:f8:26:24:de:a6:b9:e5:93: ee:08:47:cc:6a:09:03:62:bf:06:2e:14:c0:51:d8:0d:aa:a5: 4e:b4:1e:91:2c:05:f8:87:a1:48:6c:4c:0b:4e:02:7f:b7:8f: 6e:1e:a8:9b:00:e0:a8:62:56:5f:25:dd:49:e1:76:42:0f:ea: 3f:79:43:06:eb:76:53:48:1c:4c:2d:ef:04:f7:1b:96:8d:31: 3b:ce:d5:33:8f:7c:2e:88:a5:1c:87:ed:c1:99:71:42:c5:62: 08:46:a4:d7:a3:54:0d:b1:0f:29:5d:1a:fa:9e:02:f1:de:d9: 89:3a:44:a8:31:0c:85:76:7e:ad:fb:09:6e:af:9c:7f:2e:57: 27:b1:8a:9c:d3:a6:b1:67:ca:7f:70:26:0b:e2:87:3d:23:ac: 1c:e8:8f:02:eb:1d:b3:af:0a:ac:81:3b:73:58:8a:79:1f:7e: c2:9f:8b:e1:73:dd:fb:76:33:20:84:69:cb:5c:82:cd:4c:8f: c1:98:9f:ac: **********************************************************
History
| Release version | Command history |
|---|---|
| 08.0.70 | This command changes the certificate-client parameter to client-certificate. |
| 09.0.00 | The command added the device-certificate option. |