System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Trusted ownership and authorized operations

Want to summarize with AI?

Log in

Explains how ownership certificates, ownership vouchers, customer keys, and consent tokens establish trust and authorize protected router operations.


Trusted ownership and authorized operations are security controls that

  • establish a trusted relationship between a router and its management network

  • validate certificates, vouchers, and third-party software before protected operations, and

  • authorize restricted actions through customer-controlled keys and consent tokens.

Device ownership establishment allows the network to validate the router and the router to validate the network. It also helps validate third-party application signatures before installation.

The ownership voucher identifies the owner known to the manufacturer and carries the pinned-domain certificate used to authenticate later network interactions. Customer key packages add, remove, or revoke keys used by third-party applications and consent-token workflows.

Consent tokens authorize restricted actions only after the requester is authenticated as the legitimate device owner or as an authorized customer-controlled operator.