H3C S3100 Series Command Manual page 1129

Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Parameters
domain-name: Name of the PKI domain, a string of 1 to 15 characters.
Description
Use the display pki crl domain command to display the locally saved CRLs.
Related commands: pki retrieval-crl, pki domain.
Examples
# Display the locally saved CRLs.
<Sysname> display pki crl domain 1
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer:
C=CN
O=abc
OU=soft
CN=A Test Root
Last Update: Jan
Next Update: Jan
CRL extensions:
X509v3 Authority Key Identifier:
keyid:0F71448E E075CAB8 ADDB3A12 0B747387 45D612EC
Revoked Certificates:
Serial Number: 05a234448E...
Revocation Date: Sep 6 12:33:22 2004 GMT
CRL entry extensions:...
Serial Number: 05a278445E...
Revocation Date: Sep 7 12:33:22 2004 GMT
CRL entry extensions:...
Table 1-4 display pki crl domain command output description
Version
Signature Algorithm
Issuer
Last Update
Next Update
CRL extensions
X509v3 Authority Key Identifier
keyid
5 08:44:19 2004 GMT
5 21:42:13 2004 GMT
Field
1-12
Description
Version of the CRLs
Signature algorithm used by the CRLs
CA issuing the CRLs
Last update time
Next update time
Extensions of CRL
CA issuing the CRLs. The certificate version is
X.509v3.
ID of the public key
A CA may have multiple key pairs. This field
indicates the key pair used by the CRL's
signature.

Advertisement

Table of Contents
loading

Table of Contents