Provides key type, authentication, TLS validation, re-enrollment, and trustpoint guidelines for configuring EST.
Review these guidelines and limitations before configuring the EST protocol.
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
Provides key type, authentication, TLS validation, re-enrollment, and trustpoint guidelines for configuring EST.
Review these guidelines and limitations before configuring the EST protocol.
In Cisco IOS XR release 25.1.1, RSA keys are supported for signing the Certificate Signing Request (CSR) during enrollment. ECDSA keys are not supported.
The EST client supports both TLS certificate-based authentication and HTTP-based authentication. Cisco recommends TLS certificate-based authentication according to RFC 7030, although both methods are available.
If client or server certificate validation fails during the TLS handshake, EST enrollment fails. EST does not switch to HTTP authentication when TLS certificate-based client authentication fails.
For re-enrollment, the client always uses the previously issued certificate to establish the TLS connection.
A re-enrollment profile is required when the EST server uses a fixed username and password for re-enrollment but uses a one-time password (OTP) for initial enrollment. This behavior is optional and depends on the EST server configuration.
EST client support requires multiple trustpoints because it enables secure certificate enrollment over TLS for all trustpoints configured on the device. A single trustpoint configuration is insufficient to support this functionality.