Describes Gated Shell Access, which restricts supported direct, interactive root shell access on Cisco IOS XR platforms.
A gated shell access is a security feature that
-
controls direct, interactive root-shell access for supported shell commands,
-
requires authorization using a Cisco or customer Consent Token (CT) path before restricting access, and
-
stores the selection in HWTAM Secure Object storage.
Consent Token authorization applies to the shell-access restriction operation. This feature uses a separate Consent Token challenge-response workflow for each shell session.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
Gated shell access |
Release 26.3.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]). Shell access restrictions require Consent Token authorization for direct root shell access initiated through supported shell commands. |
Key features of gated shell access
Lists the key features, benefits, direct CLI commands, scope, state behavior, and command interface for gated shell access on Cisco IOS XR platforms.
How gated shell access works
Describes how restricted shell access invokes the Consent Token workflow and permits a single direct interactive root shell instance on a supported platform.
Restrict shell access using a Cisco-signed Consent Token
Restrict direct interactive root shell access on a supported Cisco IOS XR platform and store the restricted-shell selection in the Gated Shell Access HWTAM Secure Object.
Unrestrict shell access using a Cisco-signed Consent Token
Remove the restricted-shell setting by completing the Consent Token authorization flow and restore the default non-gated root shell behavior.
Restrict shell access using an owner Consent Token
Restrict direct interactive root shell access on a supported Cisco IOS XR platform and store the restricted-shell selection in the Gated Shell Access HWTAM Secure Object.
Unrestrict shell access using an owner Consent Token
Remove the restricted-shell setting by completing the Consent Token authorization flow and restore the default non-gated root shell behavior.
Terminate a pending Consent Token authorization request
Terminates a pending Consent Token authorization request for restrict or unrestrict shell access.
Access a restricted shell
Describes how to access a restricted direct, interactive root shell by completing the Consent Token challenge-response workflow.