Explains Ed25519 public-key signature support in Cisco IOS XR certificate-based trust, covering source behavior, constraints, and operational details for certification authority interoperability.
A Ed25519 public-key signature is a cryptographic algorithm that
-
uses elliptic curve cryptography to provide enhanced security and faster performance compared to other signature algorithms
-
enables certificate-based trust and interoperability with certificate authorities in Cisco IOS XR deployments, and
-
allows integration with Cisco Crosswork Trust Insights through key generation and management on 64-bit platforms.
Ed25519 keys can be generated with an empty label or predefined labels, such as system-root-key and system-enroll-key . When an empty label is used, the system assigns a default label. Predefined labels facilitate integration with Cisco Crosswork Trust Insights.
Feature history
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Support for Ed25519 Public-Key Signature System |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100])(select variants only*) *This feature is supported on the Cisco 8712-MOD-M routers. |
|
Support for Ed25519 Public-Key Signature System |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100])(select variants only*); Modular Systems (8800 [LC ASIC: P100])(select variants only*) *This feature is supported on:
|
|
Support for Ed25519 Public-Key Signature System |
Release 7.3.1 |
This feature allows you to generate and securely store crypto key pair for the Ed25519 public-key signature algorithm on Cisco IOS XR 64-bit platforms. This signature system provides fast signing, fast key generation, fool proof session keys, collision resilience, and small signatures. The feature also facilitates integration of Cisco IOS XR with Cisco Crosswork Trust Insights. Commands introduced for this feature are: Commands modified for this feature are: |