The reset pki all-cert command typically applies to the following scenarios:
If a certificate expires (the validity of a license is generally 10 years) or the key of the certificate is disclosed, run the reset pki all-cert command to delete all certificates and apply for a new certificate.
If you run the pki delete-certificate command to delete a CA certificate or local certificate with a specified file name from the memory, the device searches for the corresponding file in the CF card first. If the file cannot be found in the CF card, it cannot be deleted. In such case, run the reset pki all-cert command to delete all certificates.
Example
# Delete all local certificates and CA certificates from the memory.