System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Unrestrict shell access using an owner Consent Token

Want to summarize with AI?

Log in

Remove the restricted-shell setting by completing the Consent Token authorization flow and restore the default non-gated root shell behavior.


Restore unrestricted root shell access by removing the restricted-shell setting, allowing access to advanced system features when necessary.

Use this task to unrestrict the supported direct, interactive root shell access by using an owner Consent Token.

Before you begin

Ensure that gated shell access is restricted. For more information about restricting shell access by using an owner Consent Token, see Restrict shell access using an owner Consent Token.

Procedure

  1. Generate an unrestrict challenge on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access unrestrict challenge
    Thu Aug 20 06:06:33.888 UTC
    +--------------------------------------+
    Node location: node0_RP0_CPU0
    +--------------------------------------+
    Challenge string:
    <challenge_string>
    
  2. To generate the response string owner key type, refer to Provisioning customer consent tokens.

  3. Paste the response string provided by the TAC engineer when prompted, to install the signed response on the router.

    Example:

    RP/0/RP0/CPU0:ios# platform security shell-access unrestrict response
    Thu Aug 20 06:07:07.090 UTC
    ***************************************************************
    Please enter challenge response string for node location node0_RP0_CPU0
    ***************************************************************
    <response_string>
    Successfully accepted challenge-response for Unrestrict Shell Access in node0_RP0_CPU0

    The router validates the signature and confirms that the device ID and nonce match its own records. If valid, the response removes the restriction on direct shell access.

    Note

    If required, to terminate a pending Consent Token handshake for shell-access restriction, see Terminate a pending Consent Token authorization request.

  4. Verify the shell-access status.

    Example:

    RP/0/RP0/CPU0:ios# show platform security shell-access status
    Thu Aug 20 05:20:01.690 UTC
    Restricted shell access enabled: No