System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Gated shell access

Describes Gated Shell Access, which restricts supported direct, interactive root shell access on Cisco IOS XR platforms.


A gated shell access is a security feature that

  • controls direct, interactive root-shell access for supported shell commands,

  • requires authorization using a Cisco or customer Consent Token (CT) path before restricting access, and

  • stores the selection in HWTAM Secure Object storage.

Consent Token authorization applies to the shell-access restriction operation. This feature uses a separate Consent Token challenge-response workflow for each shell session.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

Gated shell access

Release 26.3.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100]).

Shell access restrictions require Consent Token authorization for direct root shell access initiated through supported shell commands.