System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

EST protocol configuration guidelines and limitations

Want to summarize with AI?

Log in

Provides key type, authentication, TLS validation, re-enrollment, and trustpoint guidelines for configuring EST.


Review these guidelines and limitations before configuring the EST protocol.


Supported key types

In Cisco IOS XR release 25.1.1, RSA keys are supported for signing the Certificate Signing Request (CSR) during enrollment. ECDSA keys are not supported.


Client authentication methods

The EST client supports both TLS certificate-based authentication and HTTP-based authentication. Cisco recommends TLS certificate-based authentication according to RFC 7030, although both methods are available.


TLS validation and authentication requirements

If client or server certificate validation fails during the TLS handshake, EST enrollment fails. EST does not switch to HTTP authentication when TLS certificate-based client authentication fails.


EST re-enrollment

For re-enrollment, the client always uses the previously issued certificate to establish the TLS connection.

A re-enrollment profile is required when the EST server uses a fixed username and password for re-enrollment but uses a one-time password (OTP) for initial enrollment. This behavior is optional and depends on the EST server configuration.


EST client support for multiple trustpoints

EST client support requires multiple trustpoints because it enables secure certificate enrollment over TLS for all trustpoints configured on the device. A single trustpoint configuration is insufficient to support this functionality.