7
IPsec VPN
145
The
SEG
uses
the
certificate
version
that
is
in
the
cache
if
it
is
there.
If
there
has
been
a
change
to
a
certificate
either
locally
of
remotely,
the
cache
may
need
to
be
updated.
The
contents
of
the
cache
can
be
examined
using
only
‐
cert
option
on
its
own.
Some
example
output
is
given
below:
Device:/>
ike
‐
cert
IKEv2
Certificates
#
Subject
‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐
1
C=SE,
O=Clavister,
OU=R&D,
CN=TTG
2
C=SE,
O=Clavister,
OU=R&D,
CN=TTG2
3
C=SE,
O=Clavister,
OU=R&D,
CN=GGSN
4
DC=local,
DC=devlab,
CN=labsrv
The
abbreviations
found
in
this
output
have
the
following
meanings
for
each
cached
certificate:
•
C
–
ISO3166
two
character
country
code.
•
ST
–
State
or
province.
•
L
–
Locality.
Usually
a
city.
•
O
–
Organization.
Usually
a
company
name.
•
OU
–
The
organization
unit.
Typically,
the
certificate
type.
•
CN
–
The
common
name.
Typically
a
product
name.
•
DC
–
The
domain
component.
The
‐
verbose
option
with
the
‐
cert
option
can
provide
more
detailed
information
about
the
cache
contents:
Device:/>
ike
‐
cert
‐
verbose
IKEv2
Certificates
#
Subject
Issuer
Valid
From
Valid
To
Status
‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐
1
C=SE,
DC=local,
2011
‐
05
‐
09
2012
‐
05
‐
09
Valid
O=Clavister,
DC=lab,
06:37:00
06:47:00
OU=R&D,
CN=TTG
CN=labsrv
2
C=SE,
DC=local,
2011
‐
06
‐
28
2012
‐
06
‐
28
Valid
O=Clavister,
DC=lab,
08:34:49
08:44:49
OU=R&D,
CN=TTG2
CN=labsrv
3
C=SE,
DC=local,
2010
‐
07
‐
28
2011
‐
07
‐
28
Valid
O=Clavister,
DC=lab,
07:55:33
08:05:33
OU=R&D,
CN=GGSN
CN=labsrv
4
DC=local,
DC=local,
2007
‐
10
‐
11
2012
‐
10
‐
11
Valid
DC=lab,
DC=lab,
10:09:29
10:17:17
CN=labsrv
CN=labsrv