A PKI alert notification is a certificate authority interoperability component that
-
provides timely alerts when certificates used by Cisco IOS XR applications are nearing expiry
-
supports certificate-based authentication and trust for routers, and
-
enhances operational awareness by notifying administrators through syslog and SNMP traps, ensuring seamless service continuity.
-
PKI traps retrieve certificate information from devices in the network and send SNMP traps at regular intervals to the network management system, based on thresholds configured on the device.
-
An SNMP trap (certificate expiry notification) is sent to the SNMP server at intervals starting from 60 days to one week before the certificate end date.
Additional reference information
Certificates are essential for authenticating routers in Cisco IOS XR deployments. If a certificate expires, it becomes invalid and can disrupt services such as Crosswork Trust Insights, Internet Key Exchange version 2 (IKEv2), dot1x, and others. PKI alert notifications ensure administrators are informed of impending certificate expiry, reducing risk to critical network functions.
Alert notifications are sent in the following modes and intervals:
-
First notification: Sent 60 days before certificate expiry; warning mode.
-
Repeated notifications: Sent every week until one week before expiry; warning mode.
-
Last notification: Sent every day within the final week before expiry; alert mode.
The notifications include the following information:
Sample syslog message
%SECURITY-CEPKI-1-CERT_EXPIRING_ALERT : Certificate expiring WITHIN A WEEK.
Trustpoint Name= check, Certificate Type= ID, Serial Number= 02:EC,
Issuer Name= CN=cacert,OU=SPBU,O=CSCO,L=BGL,ST=KA,C=IN, Subject name= CN=cisco.com,
Time Left= 1 days, 23 hours, 59 minutes, 41 seconds
Notification Intervals and Modes
| Interval |
Description |
Notification Mode |
| First notification |
Sent 60 days before certificate expiry |
Warning |
| Repeated notifications |
Sent weekly until one week before expiry |
Warning |
| Last notification |
Sent daily within the final week before expiry |
Alert |
PKI credentials expiry alerts
PKI alert notifications are not sent for:
-
Secure Unique Device Identifier (SUDI) certificates
-
Certificates in a trustpool (trustpools have their own expiry alerts mechanism)
-
Trustpoint clones
-
Certificate authority (CA) certificates without an associated router certificate
-
Certificates with key usage keys