System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Unrestrict shell access using a Cisco-signed Consent Token

Want to summarize with AI?

Log in

Remove the restricted-shell setting by completing the Consent Token authorization flow and restore the default non-gated root shell behavior.


Use this task to unrestrict the supported direct, interactive root shell access by using a Cisco-signed Consent Token.

Before you begin

Ensure that gated shell access is restricted. For more information about restricting shell access by using a Cisco-signed Consent Token, see Restrict shell access using a Cisco-signed Consent Token.

Procedure

  1. Generate an unrestrict challenge on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access unrestrict challenge
    Thu Aug 20 06:06:33.888 UTC
    
    +--------------------------------------+
    Node location: node0_RP0_CPU0
    +--------------------------------------+
    Challenge string:
    <challenge_string>
    
  2. Submit the challenge string to a Cisco TAC engineer. Cisco verifies that the requester is the legitimate device owner and is authorized to perform the requested action. If verified, the TAC engineer provides a signed response string.

  3. Paste the response string provided by the TAC engineer when prompted, to install the signed response on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access unrestrict response
    Thu Aug 20 06:07:07.090 UTC
    ***************************************************************
    Please enter challenge response string for node location node0_RP0_CPU0
    ***************************************************************
    <response_string>
    Successfully accepted challenge-response for Unrestrict Shell Access in node0_RP0_CPU0

    The router validates the signature and confirms that the device ID and nonce match its own records. If valid, the response removes the restriction on direct shell access.

    Note

    If required, to terminate a pending Consent Token handshake for shell-access restriction, see Terminate a pending Consent Token authorization request.

  4. Verify the shell-access status.

    Example:

    RP/0/RP0/CPU0:ios# show platform security shell-access status
    Thu Aug 20 05:20:01.690 UTC
    Restricted shell access enabled: No