230
Description
Use the display pki crl domain command to display the locally saved CRLs.
Related commands: pki retrieval-crl and pki domain.
Examples
# Display the locally saved CRLs.
<Sysname> display pki crl domain 1
Certificate Revocation List (CRL):
Version 2 (0x1)
Signature Algorithm: sha1WithRSAEncryption
Issuer:
C=CN
O=abc
OU=soft
CN=A Test Root
Last Update: Jan 5 08:44:19 2004 GMT
Next Update: Jan 5 21:42:13 2004 GMT
CRL extensions:
X509v3 Authority Key Identifier:
keyid:0F71448E E075CAB8 ADDB3A12 0B747387 45D612EC
Revoked Certificates:
Serial Number: 05a234448E…
Revocation Date: Sep 6 12:33:22 2004 GMT
CRL entry extensions:…
Serial Number: 05a278445E…
Revocation Date: Sep 7 12:33:22 2004 GMT
CRL entry extensions:…
Table 33 Output description
Signature algorithm used by the CRLs
X509v3 Authority Key Identifier
CA issuing the CRLs. The certificate version is X.509
v3.
ID of the public key
A CA might have multiple key pairs. This field
indicates the key pair used by the CRL’s signature.
Serial number of the revoked certificate
Revocation date of the certificate