Provides the security concepts and operational references for establishing device ownership, obtaining ownership vouchers, provisioning third-party key packages, and authorizing privileged router operations.
Use this chapter to establish trusted ownership and prepare the certificates, vouchers, keys, and consent tokens required for authorized router operations.
This chapter covers these security topics:
-
Trusted ownership and authorized operations introduces the shared security model.
-
Device ownership explains ownership artifacts, establishment, clearing, and security profiles.
-
Cisco MASA service describes ownership-voucher creation and MASA interactions.
-
Third-party key packages explains package versions and key provisioning.
-
Consent tokens explains authorization for restricted actions.
Trusted ownership and authorized operations
Explains how ownership certificates, ownership vouchers, customer keys, and consent tokens establish trust and authorize protected router operations.
Device ownership
Explains the ownership certificates, ownership vouchers, and serial numbers used to establish trusted relationships between Cisco IOS XR routers and their management networks.
Cisco MASA service
Explains how the Cisco Manufacturer Authorized Signing Authority service creates ownership vouchers, supports router authentication, and provides web, REST, and gRPC interactions.
How routers are provisioned using ownership vouchers
Describes how Cisco, the customer, the ZTP server, and the device exchange ownership artifacts during secure router provisioning.
Third-party key packages
Explains how signed key packages onboard owner keys, customer consent tokens, and owner RPM keys on Cisco IOS XR routers.
Consent tokens
Explains how Cisco-signed and customer-signed consent tokens authorize restricted router actions through time-limited, device-specific, single-use challenge-response workflows.