Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


show security pki crl (View)



Display information about the certificate revocation lists (CRLs) configured on the device.


  • none—Display basic information about all CRLs.

  • brief | detail—(Optional) Display the specified level of output.

  • ca-profile ca-profile-name- (Optional) Display information about only the specified CA profile.

Required Privilege Level


Output Fields

Table 1 lists the output fields for the show security pki crl command. Output fields are listed in the approximate order in which they appear.

Table 1: show security pki crl Output Fields

Field Name

Field Description

CA profile

Name of the configured CA profile.

CRL version

Revision number of the certificate revocation list.

CRL issuer

Authority that issued the digital certificate, including details of the authority organized using the distinguished name format. Possible subfields are:

  • emailAddress—Mail address of the issuing authority.

  • C—Country of origin.

  • ST—State of origin.

  • L—Locality of origin.

  • O—Organization of origin.

  • OU—Department within an organization.

  • CN—Name of the authority.

Effective date

Date and time the certificate revocation list becomes valid.

Next update

Date and time the routing platform will download the latest version of the certificate revocation list.

Revocation List

List of digital certificates that have been revoked before their expiration date. Values are:

  • Serial number—Unique serial number of the digital certificate.

  • Revocation date—Date and time that the digital certificate was revoked.

Sample Output

show security pki crl ca-profile ca2

Sample Output

show security pki crl ca-profile ca2 brief

Sample Output

show security pki crl ca-profile ca2 detail

Release Information

Command modified in Junos OS Release 8.5.