Cisco UTD OAuth 2.0 Device Authorization
In previous releases of Cisco IOS XE, UTD in Autonomous Mode utilized customer Cisco.com (CCO) credentials (username and password)
to authenticate against legacy SSO services (cloudsso.cisco.com) for automated software and signature package downloads from Cisco Automated Software Distribution (ASD) APIs (api.cisco.com/software/).
Starting with this release, authentication migrates to Okta (id.cisco.com) using an OAuth 2.0 Device Authorization Flow. Individual CCO usernames and passwords are replaced by a cryptographic refresh-token.
Key architecture and benefits
-
No Cleartext Credentials: Routers no longer store user account passwords. The refresh-token is securely encrypted in the Cisco IOS XE Configuration Database (CDB) using Cisco Type 6 encryption.
-
Single Network-Wide Authorization: The administrator performs the browser-based authorization workflow only once on any single router hosting UTD. The resulting refresh-token can be deployed across all autonomous routers in the customer domain.
-
Rolling 90-Day Token Validity: The generated refresh-token has a 90-day validity window. Each time an automated periodic signature update (daily, weekly, or monthly) is performed, the token is automatically refreshed, extending its lifetime by another 90 days.
Device authorization flow
The device authorization workflow operates in the following sequence:
-
The administrator issues the utd threat-inspection signature update generate refresh-token command on the router.
-
The router contacts the Okta authorization server (
id.cisco.com) using embedded client credentials and receives a Device Code, a User Code, and a Verification URI (For example,https://id.cisco.com/activate?user_code=HSPCDPRQ). -
The administrator opens the verification URI in a standard web browser, logs in using a generic Cisco account (non-cisco.com email address), and approves the device authorization request. The device code remains valid for 10 minutes (600 seconds).
-
The administrator executes the generation command again on the router CLI. The router exchanges the authorized device code for a durable refresh-token.
-
The administrator configures the refresh-token under the threat-inspection configuration mode on all target autonomous routers.
Deprecation notice
Note |
Configuring CCO credentials using the legacy signature update server cisco username <username> password <password> syntax is deprecated. Entering or executing legacy credential commands generates a system logging (syslog) warning alerting the administrator to migrate to Okta refresh-tokens. |
Feedback