New and Changed Feature Information

This table summarizes the new and changed feature information for the System Security Configuration Guide for Cisco NCS 5500 Series Routers, and tells you where they are documented.

System Security Features Added or Modified in IOS XR Release 26.x.x

Feature Description Changed in Release Where Documented

Upgrade CURL libraries for HTTP client

This feature was introduced.

Release 26.3.1

Upgrade CURL libraries for HTTP client

Gated shell access

This feature was introduced.

Release 26.3.1

Gated shell access

SSH client strict host key check

This feature was introduced.

Release 26.3.1

SSH client strict host key checks

IPSec for management traffic

This feature was introduced.

Release 26.3.1

IPSec for management traffic

PQC-enabled MACsec with EAP-TLS

This feature was introduced.

Release 26.3.1

PQC key exchange groups for EAP-TLS

uRPF strict mode

This feature was introduced.

Release 26.2.1

uRPF strict mode with external TCAM

FIDO2 authentication for SSH

This feature was introduced.

Release 26.2.1

FIDO2 authentication for SSH

SSH key strength: 3072 bits by default

This feature was introduced.

Release 26.1.1

Automatic generation of SSH host-key pairs