Explains how signed key packages onboard owner keys, customer consent tokens, and owner RPM keys on Cisco IOS XR routers.
Key packages are Cryptographic Message Syntax (CMS [RFC5652]) objects that are digitally signed with the private keys of the customer's Ownership Certificate (OC) and can
-
add one or more keys to the router
-
delete one or more keys from the router, and
-
revoke one or more keys from the router.
Key packages are required for onboarding owner keys, customer consent tokens, and owner RPMs. A key package provides a secure mechanism to install owner or third-party public keys (GPG or X.509) on the router.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Key package enhancements |
Release 26.1.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC:Q200]) ; Modular Systems (8800 [LC ASIC: Q100, Q200, P100]) This feature introduces you to the version 3 key package. With the version 3 key package, you can create, validate, sign a key package before the key package is provisioned on the router. Unlike the reserved customer consent token name, CUS-CT, used in version 1 and version 2 key packages, you can now use any name for the customer consent token that you include in the key package. However, to enable the customer consent token workflow, execute the consent-token customer command after the key package installation. |