Explains the PQC key exchange groups that IOS XR uses during 802.1X EAP-TLS negotiation for dynamic MACsec sessions.
A PQC key exchange group is a TLS named group that
-
combines classical and post-quantum cryptography (PQC) algorithms to protect key exchange,
-
is advertised by IOS XR during 802.1X EAP-TLS negotiation, and
-
enables support for hybrid, pure PQC, and classical key exchange methods for dynamic MACsec sessions.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
PQC-enabled MACsec with EAP-TLS |
Release 26.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]) (select variants only*); Centralized Systems (8400 [ASIC: K100]) (select variants only*) Introduces PQC-capable TLS key exchange support to 802.1X EAP-TLS, with default CiscoSSL group advertisement and per-profile group configuration. *This feature is supported on all MACsec-supported IOS XR platforms. |
From IOS XR Release 26.3.1, EAP-TLS advertises CiscoSSL-supported PQC and classical groups by default when no explicit group list is configured. You can configure a colon-separated list on each EAP profile.
The feature supports the 802.1X EAP-TLS supplicant and the Local EAP authenticator. After successful authentication, the EAP-TLS session provides keying material for MACsec key establishment.
Hybrid groups are recommended during migration because they provide classical and PQC key exchange protection.
On platforms that support port control, MACsec EAP does not support the
should-secureMACsec security policy. Dot1x continues to perform port control as part of its default operation, which preventsshould-securefrom functioning with MACsec EAP.