Cisco Crosswork Network Controller 7.2.x Administration Guide

PDF

Cisco Crosswork Network Controller 7.2.x Administration Guide

Usage of certificate types

Want to summarize with AI?

Log in

Explains the various types of certificates used in Crosswork Network Controller, their roles, properties, and usage for different communication channels.


The following figure shows how Crosswork Network Controller uses certificates for various communication channels.

Figure 1. Certificates in Crosswork Network Controller
Certificate Types and Usage

These certificates are classified into various roles with different properties depending on their use case as shown in the following table.

Table 1. Crosswork internal TLS certificate

Role

Crosswork internal TLS

UI Name

Crosswork-Internal-Communication

Description

  • Generated and provided by Crosswork Network Controller.

  • This trust-chain is available in the UI (including the server and client leaf certificates) and is created by Crosswork Network Controller during initialization. They are used for interprocess communications between Crosswork Network Controller and Crosswork Data Gateway and communication between internal Crosswork Network Controller components.

  • Allows mutual and server authentication.

Server

Crosswork Network Controller

Client

Crosswork Data Gateway

Crosswork Network Controller

Allowed operations

Download

Default expiry

5 years

Allowed expiry

Table 2. Device syslog communication certificate

Role

Device syslog communication

UI Name

Crosswork-Device-Syslog

Description

  • Generated and provided by Crosswork Network Controller.

  • Provides Syslog telemetry communications between devices and Crosswork Data Gateway.

  • Allows server authentication.

Server

Crosswork Data Gateway

Client

Device

Allowed operations

Download

Default expiry

5 years

Allowed expiry

Table 3. ZTP SUDI certificate

Role

ZTP SUDI

UI Name

Crosswork-ZTP-Device-SUDI

Description

  • A public Cisco certificate that is provided as part of Crosswork Network Controller.

  • Provides ZTP protocol communication channel between the ZTP application and device.

  • Allows server authentication.

Server

Crosswork ZTP

Client

Device

Allowed operations

  • Upload

  • Download

Default expiry

100 years

Allowed expiry

31 days to 100 years. The validity period is user-defined.

Table 4. Secure ZTP provisioning certificate

Role

Secure ZTP provisioning

UI Name

Crosswork-ZTP-Owner

Description

  • Generated and provided by Crosswork Network Controller.

  • Forwarded by ZTP to devices and used for second layer of encryption.

Server

Crosswork ZTP

Client

Device

Allowed operations

  • Upload

  • Download

Default expiry

5 years

Allowed expiry

31 days to 30 years. The validity period is user-defined.

Table 5. Crosswork web server certificate

Role

Crosswork web server

UI Name

Crosswork-Web-Cert

Description

  • Generated and provided by Crosswork Network Controller.

  • Provides communication between the user browser and Crosswork Network Controller.

  • Allows server authentication.

Server

Crosswork Web Server

Client

User browser or API client

Allowed operations

  • Upload

  • Download

Default expiry

5 years

Allowed expiry

Default expiry period is 5 years. Users can override this by uploading their own certificate. The allowed period is 31 days to 10 years.

Table 6. Provider gRPC communication certificate

Role

Provider gRPC communication

UI Name

Description

SR-PCE requires gRPC to discover topology and SR-MPLS policies. This certificate enables Transport Layer Security (TLS) and is required when the SR-PCE provider protocol is set to GRPC_SECURE.

Server

Crosswork Network Controller

Client

Clients that want secure connection to the gRPC server (Crosswork Data gateway, Device Group Manager pods, and so on)

Allowed operations

  • Upload

  • Download

Default expiry

Allowed expiry

The validity period is user-defined.

Table 7. Device gNMI/gRPC communication certificate

Role

Device gNMI/gRPC communication

UI Name

Description

Provides GNMI telemetry communications between devices and Crosswork Data Gateway.

Server

Crosswork Data Gateway

Client

Device

Allowed operations

  • Upload

  • Download

Default expiry

100 years

Allowed expiry

31 days to 100 years. The validity period is user-defined.

Table 8. Server syslog communication certificate

Role

Server syslog communication

UI Name

Description

  • Allows syslog events and logs from Crosswork Network Controller to an external Syslog server.

  • Allows server authentication.

Server

External syslog server

Client

Crosswork Network Controller

Allowed operations

  • Upload

    Note

    You can upload multiple certificates associated with different servers.

  • Download

Default expiry

Allowed expiry

31 days to 100 years. The validity period is user-defined.

Table 9. External destination certificate

Role

External destination

UI Name

Description

Exports telemetry data from Crosswork Data Gateway to external destinations (Kafka or gRPC) after performing a mutual-authentication.

Server

External Destinations (Kafka or gRPC)

Client

Crosswork Data Gateway

Allowed operations

  • Upload

    Note

    You can upload one certificate and associate it with one or more external destinations. To upload multiple certificates, configure and select additional destinations.

  • Download

Default expiry

100 years

Allowed expiry

31 days to 100 years. The validity period is user-defined.

Table 10. External destination server auth certificate

Role

External destination server auth

UI Name

Description

Exports telemetry data from Crosswork Data Gateway to external destinations (Kafka or gRPC) after performing a server-based authentication.

Server

External Crosswork Data Gateway Destinations (Kafka or gRPC)

Client

Crosswork Data Gateway

Allowed operations

  • Upload

    Note

    You can upload one certificate and associate it with one or more external destinations. To upload multiple certificates, configure and select additional destinations.

  • Download

Default expiry

100 years

Allowed expiry

31 days to 100 years. The validity period is user-defined.

Table 11. Secure LDAP communication certificate

Role

Secure LDAP communication

UI Name

Description

Crosswork Network Controller uses the trust chain of this certificate to authenticate the secure LDAP server.

Server

Secure LDAP server

Client

Crosswork Network Controller

Allowed operations

  • Upload

    Note

    You can upload multiple certificates associated with different servers.

  • Download

Default expiry

Allowed expiry

31 days to 30 years. The validity period is user-defined.

Table 12. Accedian provider mutual auth certificate

Role

Accedian provider mutual auth

UI Name

Description

Required to add provider connectivity assurance as a provider

Server

Provider

Client

Crosswork Network Controller

Allowed operations

  • Upload

  • Download

Default expiry

Allowed expiry

31 days to 30 years. The validity period is user-defined.

There are two category roles in Crosswork Network Controller:

  • Roles which allow you to upload or download trust chains only.

  • Roles that allow upload or download of both the trust chain and an intermediate certificate and key.