System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Access a restricted shell

Want to summarize with AI?

Log in

Describes how to access a restricted direct, interactive root shell by completing the Consent Token challenge-response workflow.


Use this task to access a restricted, direct, interactive root shell by completing the Consent Token challenge-response workflow.

This task applies to supported direct, interactive root shell commands, such as bash, run or attach.

Procedure

  1. Restrict shell access by using either a Cisco-signed Consent Token or an Owner Consent Token.

  2. Enter the bash, run or attach command. When prompted, complete the cisco or owner Consent Token challenge-response.

    A valid response permits the requested shell instance.

    Example:

    RP/0/RP0/CPU0:ios# bash
    Thu Aug 20 06:01:15.407 UTC
    Restricted shell access is enabled. Please obtain a consent token to proceed.
    Consent token challenge: <challenge_string>
    Enter challenge response, or Ctrl-C to terminate:
    <response_string>
    Challenge response accepted successfully.