System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Restrict shell access using a Cisco-signed Consent Token

Want to summarize with AI?

Log in

Restrict direct interactive root shell access on a supported Cisco IOS XR platform and store the restricted-shell selection in the Gated Shell Access HWTAM Secure Object.


Use this task to restrict supported direct, interactive root shell access by using a Cisco-signed Consent Token.

Procedure

  1. Generate the challenge string on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access restrict challenge cisco
    Thu Aug 20 06:06:33.888 UTC
    
    +--------------------------------------+
    Node location: node0_RP0_CPU0
    +--------------------------------------+
    Challenge string:
    <challenge_string>
    

    This produces a challenge string containing the device ID, a nonce, and the requested action.

  2. Submit the challenge string to a Cisco TAC engineer. Cisco verifies that the requester is the legitimate device owner and is authorized to perform the requested action. If verified, the TAC engineer provides a signed response string.

  3. Paste the response string provided by the TAC engineer when prompted, to install the signed response on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access restrict response
    Thu Aug 20 06:07:07.090 UTC
    ***************************************************************
    Please enter challenge response string for node location node0_RP0_CPU0
    ***************************************************************
    <response_string>
    Successfully accepted challenge-response for Restrict Shell Access in node0_RP0_CPU0

    Example:

    The router validates the signature and confirms that the device ID and nonce match its own records. If valid, this restricts the direct shell access.

    Note