Explains how to send system log messages securely over Transport Layer Security (TLS), configure TLS security templates, and apply RFC 5289-compliant cryptographic controls on Cisco 8000 Series Routers.
Use this chapter to implement secure logging over TLS and to centralize TLS and certificate policies for supported applications.
The chapter covers these areas:
-
Secure logging over TLS, including handshake behavior, restrictions, configuration, and verification
-
Security templates for reusable certificate, TLS, and compliance policies
-
RFC 5289 compliance for security templates
System logging over Transport Layer Security (TLS)
Describes how Cisco 8000 Series Routers use Transport Layer Security (TLS) to send system log messages to a remote syslog server over a trusted channel.
Security template framework for TLS applications
Describes reusable security templates that centralize certificate authentication, Transport Layer Security (TLS) controls, and compliance settings for multiple Cisco IOS XR applications.
TLS RFC 5289 compliance for security template
Describes how security-template compliance with RFC 5289 supports Common Criteria mode, newer cipher suites, and stronger Elliptic Curve Cryptography (ECC) algorithms.