System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Restrict shell access using an owner Consent Token

Want to summarize with AI?

Log in

Restrict direct interactive root shell access on a supported Cisco IOS XR platform and store the restricted-shell selection in the Gated Shell Access HWTAM Secure Object.


Use this task to restrict supported direct, interactive root shell access by using an owner Consent Token.

Procedure

  1. Generate the challenge string on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access restrict challenge owner
    Thu Aug 20 06:06:33.888 UTC
    
    +--------------------------------------+
    Node location: node0_RP0_CPU0
    +--------------------------------------+
    Challenge string:
    <challenge_string>
    

    This produces a challenge string containing the device ID, a nonce, and the requested action.

  2. To generate the response string owner key type , refer to Provisioning customer consent tokens.

  3. Paste the response string provided by the TAC engineer when prompted, to install the signed response on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access restrict response
    Thu Aug 20 06:07:07.090 UTC
    ***************************************************************
    Please enter challenge response string for node location node0_RP0_CPU0
    ***************************************************************
    <response_string>
    Successfully accepted challenge-response for Restrict Shell Access in node0_RP0_CPU0

    The router validates the signature and confirms that the device ID and nonce match its own records. If valid, this restricts the direct shell access.

    Note