System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

TLS RFC 5289 compliance for security template

Want to summarize with AI?

Log in

Describes how security-template compliance with RFC 5289 supports Common Criteria mode, newer cipher suites, and stronger Elliptic Curve Cryptography (ECC) algorithms.


TLS RFC 5289 compliance for a security template is a security feature that

  • supports Common Criteria (CC) mode

  • specifies new cipher suites, and

  • provides stronger Elliptic Curve Cryptography (ECC) algorithms.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

TLS RFC 5289 compliance for security template framework

Release 25.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100], 8010 [ASIC: A100]); Centralized Systems (8600 [ASIC: Q200]); Modular Systems (8800 [LC ASIC: Q100, Q200, P100])

The security template framework is based on RFC 5289, which specifies new cipher suites for the Transport Layer Security (TLS) protocol.

This feature supports Common Criteria (CC) mode which is an enhanced security mode that enforces stricter compliance-focused behavior. It enhances TLS security by introducing stronger Elliptic Curve Cryptography (ECC) algorithms.

The security template framework for TLS-enabled applications uses RFC 5289 compliance. RFC 5289 moves away from HMAC-SHA1 and uses SHA-256 and SHA-384 for message authentication codes. For more information about the security template framework, see Security template framework for TLS applications.