show crypto pki ta-profile

Syntax

show crypto pki ta-profile [<TA-NAME>]

Description

Shows a list of all configured TA profiles, or detailed information for a specific profile.

Command context

Manager (#)

Parameters

<TA-NAME>
Specify the name of a TA profile. Range: 1 to 32 alphanumeric characters (excluding ").

Authority

Administrators

Examples

Showing a list of all configured TA profiles:

switch# show crypto pki ta-profile

Profile Name                     TA Certificate     Revocation Check
-------------------------------- ------------------ ---------------- 
BASE_CA                          Installed,valid    disabled 
BASE02_CA                        Installed,expired  disabled 
root-cert                        Installed,valid    OCSP  
ROOT-A_CA                        Not Installed      OCSP

Showing detailed information for TA profile root-cert:

switch# show crypto pki ta-profile root-cert

  TA Profile Name         : root-cert
  Revocation Check        : OCSP
    OSCP Primary URL      : http://ocsp1.domain.com
    OCSP Secondary URL    : Not Configured
    OCSP Disable-nonce    : false
    OCSP Enforcement Level: strict
    OCSP VRF              : mgmt
  TA Certificate: Installed and valid
    Version: 3 (0x2)
    Serial Number:
       74:e6:6d:22:3f:52:cc:94:43:41:ab:66:a8:8d:47:b1
    Signature Algorithm: sha1withRSAEncryption
    Issuer: OU=DeviceTrust, OU=Operations, O=Site, C=US,
            CN=Site Trusted Computing Root CA 1.0
    Validity
       Not Before: Sep 14 03:12:06 2007 GMT
       Not After : Sep 14 03:21:14 2032 GMT
    Subject: OU=DeviceTrust, OU=Operations, O=Site, C=US,
             CN=Site Trusted Computing Root CA 1.0
    Subject Public Key Info:
       Public Key Algorithm: rsaEncryption
          RSA Public Key: (2048 bit)
          Modulus (2048 bit):
              30:0d:06:09:2a:86:48:86:f7:0d:01:01:01:05:33:
              03:82:01:0f:00:30:82:01:3a:02:82:01:01:00:ac:
              3d:60:3a:2e:ca:a4:34:db:5c:3b:6b:07:df:73:62:
              ...
              20:c8:df:63:14:5a:e8:d3:ea:83:d8:47:a3:b5:2e:
              bb:64:51:f0:be:13:b6:91:e4:32:45:58:5e:1f:0d:
              af:36:94:01:43:06:de:0a:44:64:ae:51:f4:bd:b1:
              02:03:01:00:01
          Exponent: 65537 (0x10001)
    X509v3 extensions:
       X509v3 Key Usage:
          Digital Signature, Certificate Signing, CRL Signing
       X509v3 Basic Constraints:
          CA:TRUE, pathlen:4
       X509v3 Subject Key Identifier:
          eb:d7:ec:db:8a:cb:f2:51:d5:06:e1:42:7b:39:a7:d0:1e:31:6e:bf

    Signature Algorithm: sha1withRSAEncryption
       1c:90:f3:a4:f0:0d:e2:e3:e9:ae:01:e1:7d:a7:13:e2:cc:0b:
       17:31:26:92:a2:5d:1d:19:60:54:03:13:9b:e1:73:6c:e4:b3:
       01:4f:4e:ae:61:bd:ae:b6:12:d3:ab:08:ae:8c:47:92:d7:0d:
       ...
       ca:cf:11:78:55:6d:06:49:fa:d4:8d:f3:ef:7f:79:38:35:5d:
       16:5a:57:7f:a8:dc:b0:f8:a2:04:0d:17:0b:bb:58:32:30:e0:
       2d:a8:37:a2