Explains the ownership certificates, ownership vouchers, and serial numbers used to establish trusted relationships between Cisco IOS XR routers and their management networks.
Device ownership establishment (DOE) is a process that
-
establishes a device’s first trusted connection with the device management service (network) and vice versa
-
validates the router to the network and the network to the router, and
-
validates third-party application signatures before installation and enables protected operations such as Reimage Protection and customer key-package installation.
Ownership artifacts
Device ownership establishment uses these artifacts:
-
Owner Certificate : The owner certificate (OC) is an X.509 certificate [RFC5280] that identifies an owner, such as an organization. A certificate authority (CA) can sign the OC. The OC contains the owner certificate and all intermediate certificates leading to the pinned-domain-cert (PDC) specified in the OV.
-
Ownership Voucher : The ownership voucher (OV) [RFC8366] securely identifies the owner known to the manufacturer. The device manufacturer signs the OV. The OV verifies that the OC has a chain of trust leading to the trusted PDC included in the OV. Cisco's Manufacturer Authorized Signing Authority (MASA) service issues OVs.
-
Serial Number : The serial number (SN) is typically in the format LLLYYWWSSSS. LLL represents the manufacturing location, YY and WW represent the year and week of manufacture, and SSSS is the unique router code. Find the SN at the bottom of the router or run show platform security device-info location location .
DOE is required to enable or disable Reimage Protection and to install and enable a customer key package for third-party application onboarding.