The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

show crypto certificate decode raw pem

Prev Next

Shows the raw openssl x509 output that is decoded from a valid X.509 certificate Privacy Enhanced Email (PEM) string. The command shows information about the PEM-encoded certificate, and errors that are found during the decoding process.

For details about how to configure a CA certificate bundle, refer to the Trellix System Security Guide.

Note

This command is not currently used on the Intelligent Virtual Execution - Server compute node.

Syntax

show crypto certificate decode raw pem ["<pem_string>"]

Parameters

pem_string

(Optional) The PEM-encrypted ASCII string of the certificate that is enclosed with double quotation marks.

Example

The following example shows the raw openssl x509 output that is decoded from a valid X.509 certificate PEM string.

hostname # show crypto certificate decode raw pem
"""-----BEGIN CERTIFICATE-----
MIIFpTCCA42gAwIBAgICEAAwDQYJKoZIhvcNAQELBQAwbTELMAkGA1UEBhMCVVMx
EzARBgNVBAgMCkNhbGlmb3JuaWExFDASBgNVBAoMC0ZpcmVleWUgSW5jMRQwEgYD
...
vURBPtSwN1/pylT/1A6zyIHzrwWBxLUY01ycq3egkfIcGW/85OQJOx2SG4AzvrKR
QIkfy/98EI8f
-----END CERTIFICATE-----"""
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 4096 (0x1000)
    Signature Algorithm: sha256WithRSAEncryption
        Issuer: C=US, ST=California, O=Fireeye Inc, OU=Engineering, CN=Buzz Intermediate CA
        Validity
            Not Before: Oct 27 22:20:09 2016 GMT
            Not After : Nov  6 22:20:09 2017 GMT
    Subject: C=US, ST=California, L=Milpitas, O=Fireeye Inc, OU=Engineering, CN=172.16.216.20
    Subject Public Key Info:
        Public Key Algorithm: rsaEncryption
            Public-Key: (2048 bit)
            Modulus:
                00:d4:49:53:c5:f4:e7:22:cd:86:57:c2:e1:78:f4:
                a4:c1:93:94:aa:35:8c:fa:c1:47:32:10:aa:c3:31:
                ...
                4a:b5
            Exponent: 65537 (0x10001)
    X509v3 extensions:
        X509v3 Basic Constraints:
            CA:FALSE
        Netscape Cert Type:
            SSL Server
        Netscape Comment:
            OpenSSL Generated Server Certificate
        X509v3 Subject Key Identifier:
            94:FF:B7:E7:38:F6:62:3D:7C:2D:DC:1F:AF:D2:C7:DD:C4:96:6B:87
        X509v3 Authority Key Identifier:
        keyid:21:01:9E:EE:8C:D9:0E:A3:61:35:8D:37:03:BB:33:26:4C:79:76:0E
        DirName:/C=US/ST=California/L=Milpitas/O=Fireeye Inc/OU=Engineering/CN=Buzz Root CA
        serial:10:00
        X509v3 Key Usage: critical
            Digital Signature, Key Encipherment
        X509v3 Extended Key Usage:
            TLS Web Server Authentication
        Signature Algorithm: sha256WithRSAEncryption
             a0:b1:d7:fc:0e:ec:a7:f1:4d:81:c6:29:7b:51:7d:44:96:3a:
             88:da:f0:c3:0d:dd:a2:d6:ea:48:58:c2:d2:ef:d1:9d:99:54:
             df:c5:9c:31:6e:bf:13:c3:7c:d6:26:ab:e5:62:88:e2:38:dd:
             ...
             89:1f:cb:ff:7c:10:8f:1f

User role

Admin

Command mode

Enable

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.9.1

  • Network Security: Release 7.9.1

  • Endpoint Security (HX): Release 2.5

  • Intelligent Virtual Execution - Server: Release 7.9.1

  • Email Security — Server: Release 7.9.0