Explains automatic PKI certificate renewal and auto-enroll behavior for Cisco IOS XR trustpoint certificates.
Automatic PKI certificate renewal is a Cisco IOS XR capability that
-
enables a router to request a new PKI certificate before the current certificate expires
-
eliminates the need for manual replacement of certificates, and
-
helps avoid interruptions to encrypted communications such as MACsec session flaps due to certificate expiry.
-
Public key infrastructure (PKI) controls the digital certificates used to authenticate a router and protect sensitive information flowing through a network.
-
PKI certificates can have a short validity period and otherwise require manual replacement before expiration.
Feature history
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Automatic renewal of Public Key Infrastructure (PKI) certificate |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
Automatic renewal of Public Key Infrastructure (PKI) certificate |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100])(select variants only*) *This feature is supported on:
|
|
Automatic renewal of Public Key Infrastructure (PKI) certificate |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
Automatic renewal of Public Key Infrastructure (PKI) certificate |
Release 7.5.3 |
You can now enable the router to renew the PKI certificate from the Certificate Authority (CA) by configuring the percentage of the certificate validity, after which the router requests a new certificate from the CA, and the CA authorizes it before certification expiration. This feature eliminates the previously needed manual efforts of certification renewal and avoids interruptions such as MACsec session flaps due to certificate expiry and so on. This feature introduces the following commands: |
Additional reference information
-
The auto-enroll setting defines the certificate-validity percentage after which the router requests a new certificate from the certification authority (CA).
-
PKI encrypts and decrypts data using a public key and a private key pair that it generates. A PKI digital certificate authenticates the identity of a router.
-
You can configure a timeline for PKI certificate renewal by specifying the percentage of certificate validity after which the router requests a new certificate from the CA server. This timeline for automatic PKI certificate renewal is called auto-enroll.