Introduces the key features and concepts of Crosswork Trust Insights and public-key systems, outlining their roles in securing network infrastructure, and detailing configuration, management, and verification procedures for effective deployment.
Cisco IOS XR Software provides a framework to securely enroll devices and share system integrity information with Cisco Crosswork Trust Insights, a cloud-based SaaS solution that tracks trust posture and validates network hardware and software integrity.
For more details, see:
Summary
The key components involved in the process are:
-
Cisco IOS XR platform: Generates key pairs and trust roots for secure communication.
-
Trust Inspector service: Manages device enrollment and receives required credentials for integration.
-
Crosswork collector: Collects signed-data dossiers from IOS XR instances and forwards them for validation.
-
Crosswork cloud service: Validates signed-data, ensuring trust posture and certificate authority interoperability.
Integrating Cisco IOS XR and Crosswork Trust Insights helps ensure certificate authority interoperability between network hardware and cloud services by enabling secure enrollment and signed-data sharing.
Workflow
These stages describe integrating Cisco IOS XR and Crosswork Trust Insights.
-
The Cisco IOS XR platform generates a new key pair and trust root using IOS XR commands.
-
The user logs into Trust Inspector, initiates the enrollment workflow, and provides the device’s management IP, credentials, and certificate root.
-
Trust Inspector configures the Crosswork collector to log in to the router and pull integration data.
-
The Crosswork collector begins periodic polling and generates signed-information dossiers from each IOS XR instance.
-
The collector forwards signed-envelope data to the Crosswork cloud service for validation.
-
The cloud service validates the signed-envelope against the enrolled certificate or trust chain.
Result
The integration achieves certificate authority interoperability, allowing network devices and cloud services to securely verify system integrity and trust posture.