2053
display pki crl domain
Syntax display pki crl domain domain-name
View Any view
Parameter domain-name: Name of the PKI domain, a string of 1 to 15 characters.
Description Use the
display pki crl domain command to display the locally saved CRLs.
Related command: pki retrieval-crl domain and pki domain.
Example # Display the locally saved CRLs.
<Sysname> display pki crl domain 1
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer:
C=CN
O=abc
OU=soft
CN=A Test Root
Last Update: Jan 5 08: 44: 19 2004 GMT
Next Update: Jan 5 21: 42: 13 2004 GMT
CRL extensions:
X509v3 Authority Key Identifier:
keyid:0F71448E E075CAB8 ADDB3A12 0B747387 45D612EC
Revoked Certificates:
Serial Number: 05a234448E...
Revocation Date: Sep 6 12:33:22 2004 GMT
CRL entry extensions:...
Serial Number: 05a234448E...
Revocation Date: Sep 6 12:33:22 2004 GMT
CRL entry extensions:...
Table 534 Description on the fields of display pki certificate attribute-group
Field Description
attribute group name Name of the certificate attribute group
attribute number Number of the attribute rules
subject-name Name of the certificate subject
dn Domain of the entity
ctn Indicates the contain operations
abc Value of attribute 1
issuer-name Name of the certificate issuer
fqdn FQDN of the entity
nctn Indicates the not-contain operations
app Value of attribute 2