Provides key type, authentication, TLS validation, re-enrollment, and trustpoint guidelines for configuring EST.
Review these guidelines and limitations before configuring the EST protocol.
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
Is this content helpful?
Thank you for your feedback. Your response has been recorded.
AI responses are currently only available to logged in users. Log in
Only ask questions about this document. To ask questions about this product as a whole, go to Technical Documentation .
Suggestions
Sorry, we couldn't generate a response for this query.
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
Updated: September 18, 2026
Want to summarize with AI?
Log inProvides key type, authentication, TLS validation, re-enrollment, and trustpoint guidelines for configuring EST.
Review these guidelines and limitations before configuring the EST protocol.
In Cisco IOS XR release 25.1.1, RSA keys are supported for signing the Certificate Signing Request (CSR) during enrollment. ECDSA keys are not supported.
The EST client supports both TLS certificate-based authentication and HTTP-based authentication. Cisco recommends TLS certificate-based authentication according to RFC 7030, although both methods are available.
If client or server certificate validation fails during the TLS handshake, EST enrollment fails. EST does not switch to HTTP authentication when TLS certificate-based client authentication fails.
For re-enrollment, the client always uses the previously issued certificate to establish the TLS connection.
A re-enrollment profile is required when the EST server uses a fixed username and password for re-enrollment but uses a one-time password (OTP) for initial enrollment. This behavior is optional and depends on the EST server configuration.
EST client support requires multiple trustpoints because it enables secure certificate enrollment over TLS for all trustpoints configured on the device. A single trustpoint configuration is insufficient to support this functionality.
Need help?
(Requires a Cisco Service Contract)
The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.