3Com Switch 8800 Family IPsec Module Configuration and Command reference Guide
444 CHAPTER 24: PKI CONFIGURATION COMMANDS
DNS:hyf.3com-3com.com
... ...
Signature Algorithm: md5WithRSAEncryption
A3A5A447 4D08387D ...
display pki crl Syntax
display pki crl domain domain-name
View
Any view
Parameter
domain-name: Name of the domain the certificate to be validated belongs to. It is
configured by using the pki domain command.
Description
Use the display pki crl command to view the locally saved CRL.
Related command: pki retrieval-crl, and pki domain.
Example
# Display a CRL
[SecBlade_VPN] display pki crl domain 1
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer:
C=CN
O=h3c
OU=soft
CN=A Test Root
Last Update: Jan 5 08:44:19 2004 GMT
Next Update: Jan 5 21:42:13 2004 GMT
CRL extensions:
X509v3 CRL Number: 2
X509v3 Authority Key Identifier:
keyid:0F71448E E075CAB8 ADDB3A12 0B747387 45D612EC
Revoked Certificates:
Tabl e 280 Description on the fields of the display pki certificate command
Field Description
Version Version number of the certificate
Serial Number Serial number of the certificate
Signature Algorithm Signature algorithm
Issuer Certificate issuer
Validity Validity period of the certificate
Subject Subject in the certificate request
Subject Public Key Info Public key information of the subject in the certificate
request
X509v3 extensions Extension attributes of the X509v3 certificate
X509v3 CRL Distribution Points Distribution point of X509v3 CRL