Cisco Catalyst Center Administrator Guide, Release 3.3.1

PDF

Cisco Catalyst Center Administrator Guide, Release 3.3.1

Ciphers dashboard

Want to summarize with AI?

Log in

Learn how to manage your organization's cipher posture using the Ciphers dashboard in Cisco Catalyst Center. This topic covers selecting predefined security profiles, creating custom configurations, and monitoring the associated maintenance workflows to ensure secure and compliant communication.


The Ciphers dashboard gives administrators a centralized way to manage TLS and SSH cipher configurations in Cisco Catalyst Center. It brings profile selection, supported algorithm visibility, custom cipher selection, workflow monitoring, error details, and retry into the product interface.

The feature is designed to reduce manual, error-prone configuration steps and help customers align cipher posture with Cisco Recommended, FIPS, Common Criteria, or custom requirements.

What you can do

  • View the current cipher configuration and active profile at a glance.

  • Compare supported algorithms across Cisco Baseline, Cisco Recommended, FIPS, and Common Criteria profiles.

  • Review TLS, SSH, and SFTP algorithms in separate tabs.

  • Search and filter long algorithm lists without scrolling through the entire table.

  • Apply a predefined profile or build a custom cipher configuration from supported algorithms.

  • Track the execution status and history of cipher operations.

  • Inspect propagated error details and retry a failed operation after the underlying issue is corrected.

Profiles

The Ciphers dashboard organizes cipher configuration around profiles. Predefined profiles are read-only and provide a controlled set of algorithms. Custom mode allows administrators to tailor the selected algorithms and TLS version bounds.

Table 1. Predefined profile details
Profile Best suited for Behavior

Cisco Baseline

Deployments that want Cisco baseline defaults.

Read-only profile. Select the profile, review included algorithms and submit the change through the guided workflow.

Cisco Recommended

Deployments that want Cisco-recommended secure defaults.

Read-only profile. Select the profile, review included algorithms and submit the change through the guided workflow.

FIPS

Deployments that require FIPS-aligned cipher posture.

Read-only profile. Select the profile, review included algorithms and submit the change through the guided workflow.

Common Criteria

Deployments that need alignment with Common Criteria expectations.

Read-only profile. The algorithm table updates to show the ciphers associated with the profile.

Custom

Deployments with specific security, interoperability, or policy requirements.

Editable profile. Administrators can select supported algorithms and TLS version bounds before submitting changes.

Figure 1. Cisco Baseline default profile example
Figure 2. Custom profile example

Before you begin

  • Confirm that you have administrative access to System > Settings in Cisco Catalyst Center.

  • Plan a maintenance window. Applying cipher changes will place the system into maintenance mode while the operation runs.

  • Review the impact of cipher changes on managed devices, integrations, clients, and operational tooling.

  • Use predefined profiles when possible. Use Custom only when your policy or interoperability requirements call for a tailored configuration.

Caution

Avoid enabling weak or deprecated algorithms unless your organization has explicitly accepted the risk and documented the exception.

Recommended practices

  • Use Cisco Recommended as the baseline unless compliance or interoperability requirements require another profile.

  • Prefer FIPS or Common Criteria when those compliance postures are required by policy.

  • Reserve Custom mode for documented exceptions or explicit security requirements.

  • Review all TLS, SSH, and SFTP tabs before submitting changes.

  • Schedule changes during a maintenance window and notify stakeholders before submitting.

  • Use View Activities after each change to confirm completion and retain an audit trail.

  • Retry only after the condition that caused the failure has been corrected.

Quick reference

Task Where to go Expected result

View current posture

System > Settings > Trust & Privacy > Ciphers

The active profile is selected, and the included algorithms are shown by category.

Review a predefined profile

Select Cisco Recommended, FIPS, or Common Criteria.

The algorithm table updates to show the ciphers associated with that profile.

Search for an algorithm

Use the Search field in the algorithm table.

The table narrows to matching TLS or SSH algorithms.

Apply a profile

Select profile > Update > Confirm Changes > Submit

A maintenance workflow starts and tracks progress.

Customize ciphers

Select Custom and select algorithms

Selected algorithms and TLS bounds are submitted as a custom configuration.

Review operation history

Click View Activities

Execution status, step history, and details display.

Retry a failure

Open failed operation menu > Retry

The system reruns the prior failed cipher operation after correction.

Glossary

Term Meaning

Cipher profile

A named set of TLS and SSH algorithms used to define the system cipher posture.

TLS

Transport Layer Security, used to protect communication between the controller, managed devices, and other network systems.

SFTP

Algorithms used when the controller accepts SSH connections.

SSH

Algorithms used when the controller acts as an SSH client.

Maintenance workflow

The guided system operation that applies cipher changes and reports.


Manage a cipher configuration

Before you begin

  • Confirm that you have administrative access to System > Settings.

  • Confirm that you planned a maintenance window for cipher changes.

Procedure

  1. Open the Ciphers dashboard.

    1. Go to System > Settings.

    2. Open Trust & Privacy.

    3. Select Ciphers.

    View available profiles, cipher category tabs, search controls, and the supported algorithm table.

  2. Review cipher support.

    • Use the profile selector to view algorithms in each predefined profile.

    • Use the TLS tab for TLS suites and version bounds.

    • Use the SSH Client tab for SSH client algorithms.

    • Use the SSH Server tab for SSH server algorithms.

    • Use Search to find specific algorithms.

  3. Apply a predefined profile (Cisco Recommended, FIPS, or Common Criteria), if needed.

    1. Select the target profile.
    2. Review algorithms in TLS, SSH Client, and SSH Server.
    3. Click Update.
    4. In Confirm Changes, review the summary (profile, TLS bounds, cipher groups), select the acknowledgment checkbox, and click Submit.
  4. Create or update a custom configuration, if needed.

    1. Select Custom in Profiles.
    2. Choose minimum and maximum TLS versions.
    3. In each tab (TLS, SSH Client, SSH Server), select or clear algorithms according to policy and compatibility requirements.
    4. Click Update, review and acknowledge Confirm Changes, then click Submit.
  5. Monitor the operation.

    After submission, Catalyst Center runs a maintenance workflow and displays progress, triggering user, execution ID, start time, and step-by-step status.

    After success, return to Ciphers. The selected profile on page load is the active profile. Use View Activities for execution details.

  6. Troubleshoot and retry failed operations.

    1. Open failure details from the banner or View Activities.
    2. Review execution ID, status, error code, error message, timing, and failed step.
    3. Correct the underlying issue outside the retry workflow.
    4. Return to the failed operation, select Retry, review, and submit.

The system applies the selected cipher profile or custom configuration through the maintenance workflow. Operation history and status are available in View Activities.