Displaying Information about ICX Digital Certificates

You can use one of the following commands to check for the presence of an SSL certificate on an ICX device and view its contents:

  • show ip ssl certificate - displays the user certificate imported with the copy tftp flash command
  • show ip ssl device-certificate - displays the SSL details for TPM or non-TPM device certificate stored on the ICX device

The following example displays information for a device certificate.

device# show ip ssl device-certificate
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 238779085 (0xe3b7acd)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=fe044db7a0ec05cf9736bfbcc2e186a76da5a13e49b1f12c8717e5c5bf5c32f2, L=10.176.156.30, O=cc:4e:24:8c:67:e8, OU=JLSAWZOIFZMD, CN=ICX
        Validity
            Not Before: Dec  3 22:40:24 2019 GMT
            Not After : Nov 19 22:40:24 2079 GMT
        Subject: C=US, ST=fe044db7a0ec05cf9736bfbcc2e186a76da5a13e49b1f12c8717e5c5bf5c32f2, L=10.176.156.30, O=cc:4e:24:8c:67:e8, OU=JLSAWZOIFZMD, CN=ICX
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (2048 bit)
                Modulus:
                    00:9f:87:35:01:dd:c3:63:52:7b:9d:aa:13:b7:39:
                    a9:0a:12:51:84:6e:57:ed:62:65:b7:79:31:72:35:
                    08:9a:d8:36:8b:f3:c8:76:47:90:5f:88:37:bc:6b:
                    1d:1f:5c:fd:0e:94:2d:7b:3a:54:d0:17:3c:96:d7:
                    be:a5:d8:0a:9c:54:08:08:30:06:84:a3:cb:1c:9f:
                    e0:ab:25:ac:59:02:7e:7b:cd:c2:bf:58:8d:63:09: