certificate

This subcommand lets you do various actions on TLS certificates.

Syntax

(tls-<Index>)# certificate  

Command

Description

Index

Defines the table row index.

alternative-name-add {dns|email|ip-addr|uri}

Defines the Subject Alternative Name (SAN) fields, which can be a DNS, e-mail, IP address or URI.

alternative-name-clear

Deletes all the Subject Alternative Name (SAN) fields.

create-self-signed

Creates a self-signed certificate (by the device) with the current key.

delete

Deletes the certificate.

detail

Displays certificate information.

export

Displays the certificate in the console ("BEGIN CERTIFICATE" to "END CERTIFICATE").

import

Imports a certificate. Type the certificate after the command.

signature-algorithm {sha-1|sha-256|sha-512}

Defines the signature algorithm.

signing-request

Creates a certificate signing request to send to the CA.

status

Displays active status of certificate (e.g., expiration day).

subject {clear|copy|display|field-set}

Operations on the certification subject name.

Command Mode

Privileged User

Example

This example displays information on a TLS certificate:

(config-network)# tls 0
(tls-0)# certificate details
Certificate:
    Data:
        Version: 1 (0x0)
        Serial Number: 0 (0x0)
    Signature Algorithm: sha1WithRSAEncryption
        Issuer: CN=ACL_5967925
        Validity
            Not Before: Jan  5 07:26:31 2010 GMT
            Not After : Dec 31 07:26:31 2029 GMT
        Subject: CN=ACL_5967925
        Subject Public Key Info:
            Public Key Algorithm: rsaEncryption
                Public-Key: (1024 bit)
                Modulus:
                    00:aa:1f:fa:82:5b:2b:2f:26:08:64:96:cb:50:a9:
                    c2:5b:ec:57:66:58:16:aa:17:79:0a:0f:77:5d:dd:
                    15:88:3c:b1:f7:c4:c4:b9:e8:a9:af:88:0f:fa:5e:
                    85:be:1c:34:c1:15:5d:b5:07:93:e2:0d:2f:5e:2f:
                    7e:f3:5c:ee:bf:c5:ac:43:8a:7b:f2:3e:0d:1b:c4:
                    84:2e:07:53:b4:52:af:c8:d0:23:0b:f9:a2:ac:72:
                    2e:f1:65:59:f1:0b:7a:d2:77:cd:e8:c9:5e:81:93:
                    0b:f5:f2:93:85:5e:06:c5:9a:b8:3d:81:d9:b7:e7:
                    4b:44:fe:9e:fd:53:e6:7d:d1
                Exponent: 65537 (0x10001)
    Signature Algorithm: sha1WithRSAEncryption
         3e:f5:97:07:96:e4:36:27:19:8b:e7:7d:5d:04:8c:ba:46:d8:
         d7:31:6c:75:2b:3a:c8:4d:6b:cb:56:d0:29:21:d1:7b:8b:79:
         57:6e:35:71:8e:e6:eb:5d:17:77:ac:b6:ec:20:6d:6a:9b:17:
         9a:28:17:e1:a1:d5:11:7e:a4:95:04:df:15:cb:84:e0:3a:7d:
         bd:15:2c:62:2e:f2:40:2f:00:6d:ba:28:16:fe:bd:87:86:d0:
         4b:a0:c0:a6:06:b8:22:4d:67:ed:af:1d:83:83:ae:92:c4:06:
         f3:e2:e5:8c:17:66:3c:ed:80:f0:96:a3:e0:95:e3:88:9e:61:
         d7:b8