show ip ssl (FIPS)

Displays SSL connection details.
Syntax
show ip ssl [ certificate | client-certificate | device-certificate | profile ]
Parameters
certificate
Displays the SSL certificate details for self-signed certificates.
client-certificate
Displays SSL client certificate details.
device-certificate
Displays SSL details for TPM/non-TPM ICX device certificate.
profile
Displays SSL profile details.
Modes

Privileged EXEC mode (with FIPS enabled)

Global configuration mode (with FIPS enabled)

Examples

The following example displays the output of the show ip ssl command.

device(config)# show ip ssl
Session Protocol Source IP      Source Port  Remote IP      Remote Port
1       TLS_1_2  10.20.157.102  634          10.25.105.201  60892

The following example displays output for the show ip ssl profile command.

device# show ip ssl profile 
SSL Profile Information:
********************************************

Profile Name   : LINUX-END 
Trustpoint Name: TLS-LINUX
Remote Domain  : LINUX-END
********************************************

Profile Name   : LINUX-END-SAN 
Trustpoint Name: TLS-LINUX
Remote Domain  : LINUX-END-SAN
********************************************

Profile Name   : p1 
Trustpoint Name: TLS-LINUX
Remote Domain  : example.com
********************************************

Profile Name   : p2 
Trustpoint Name: TLS-LINUX
Remote Domain  : ruckus.com
********************************************

Profile Name   : p3 
Trustpoint Name: auto
Remote Domain  : gss.example.com
********************************************

Profile Name   : p4 
Trustpoint Name: TLS-LINUX
Remote Domain  : *.example.com
********************************************

Profile Name   : p5 
Trustpoint Name: TLS-LINUX
Remote Domain  : LINUX-SERVER-SAN
********************************************

Profile Name   : p6 
Trustpoint Name: TLS-LINUX
Remote Domain  : LINUX-SERVER-CC
********************************************

The following example displays SSL certificate details.

device(config)# show ip ssl certificate
Trusted Certificates:
 Dynamic:
 Index 0:
  Signature Algorithm: sha256WithRSAEncryption
  Issuer:
   CN: 10.25.105.201
  Validity:
   Not Before: 2014 Aug 22 05:12:45
   Not After : 2017 Aug 21 05:12:45
  Subject:
   CN: 10.25.105.201
  X509v3 extensions:
   X509v3 Subject Alternative Name:
    IP Address: 10.25.105.201
  Signature:
   12:ec:41:d8:01:45:61:ce:cf:7e:80:de:a6:7c:a7:2e:01:7f:
   42:27:22:1d:ac:a2:47:c5:0d:4f:e3:68:24:de:bf:50:40:65:
   25:8c:30:bd:ff:a7:d0:21:73:d2:ba:5e:67:42:1f:bb:97:4a:
   d9:1d:c3:ca:31:c4:59:10:79:d1:42:f4:b6:1a:b0:98:4e:a8:
   ef:e2:a2:98:c3:14:16:63:50:02:a0:18:9c:7a:e3:17:39:0d:
   b7:30:ab:23:9f:63:bd:0f:9e:d8:67:b0:fe:ec:3b:fa:4c:f4:
   3d:34:e2:99:0e:99:24:ec:93:fb:8a:e5:4a:bf:74:d6:ff:91:
   0a:dc:fb:b9:4f:91:5d:d4:f6:77:23:eb:ec:eb:3a:62:08:e1:
   a6:ea:a8:52:b6:39:62:db:29:fa:61:1d:fd:d5:02:31:04:73: 
   50:ad:de:41:54:a5:e2:96:2d:9c:f4:68:b2:68:05:bb:39:47:
   ee:74:89:a2:8c:30:f0:f9:d7:d5:4b:3b:e2:95:6f:82:61:a3:
   c2:79:4c:f2:11:56:f8:2f:cc:fc:2b:4b:cb:3b:54:59:f0:8b:
   5b:70:e1:27:c3:57:25:eb:35:c6:07:ea:6d:0b:34:04:95:81:
   35:e6:64:c6:b8:72:e8:24:18:bd:ca:90:99:74:45:44:85:71:
   9e:7f:13:96:

The following example displays SSL client certificate information.

device(config)# show ip ssl client-certificate  
SSL Client Certificates:
********************************************************* 
Trustpoint Name: TLS-LINUX 
  Signature Algorithm: sha256WithRSAEncryption
  Issuer:
   CN: ROOTCA-CC
  Validity:
   Not Before: 2017 Nov  6 18:24:18
   Not After : 2018 Nov 16 18:24:18
  Subject:
   CN: DUTFIPSCC
  Signature:
   76:24:88:c3:07:f3:37:e0:c7:06:17:a8:39:03:ad:ad:d8:ee:
   f0:76:ac:4f:5b:08:d6:3b:0c:3d:36:b4:1e:ac:cd:b7:76:2b:
   a7:7e:22:94:63:56:5b:88:64:3a:62:a8:80:c7:b4:57:8d:a8:
   51:1c:34:7c:b4:27:d2:92:9f:f2:f8:26:24:de:a6:b9:e5:93:
   ee:08:47:cc:6a:09:03:62:bf:06:2e:14:c0:51:d8:0d:aa:a5:
   4e:b4:1e:91:2c:05:f8:87:a1:48:6c:4c:0b:4e:02:7f:b7:8f:
   6e:1e:a8:9b:00:e0:a8:62:56:5f:25:dd:49:e1:76:42:0f:ea:
   3f:79:43:06:eb:76:53:48:1c:4c:2d:ef:04:f7:1b:96:8d:31:
   3b:ce:d5:33:8f:7c:2e:88:a5:1c:87:ed:c1:99:71:42:c5:62:
   08:46:a4:d7:a3:54:0d:b1:0f:29:5d:1a:fa:9e:02:f1:de:d9:
   89:3a:44:a8:31:0c:85:76:7e:ad:fb:09:6e:af:9c:7f:2e:57:
   27:b1:8a:9c:d3:a6:b1:67:ca:7f:70:26:0b:e2:87:3d:23:ac:
   1c:e8:8f:02:eb:1d:b3:af:0a:ac:81:3b:73:58:8a:79:1f:7e:
   c2:9f:8b:e1:73:dd:fb:76:33:20:84:69:cb:5c:82:cd:4c:8f:
   c1:98:9f:ac:
**********************************************************
History
Release version Command history
08.0.70 This command changes the certificate-client parameter to client-certificate.
09.0.00 The command added the device-certificate option.