Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

PDF

Cisco Catalyst 9800 Series Wireless Controller Software Configuration Guide, Cisco IOS XE 26.1.x

Common criteria

Want to summarize with AI?

Log in

Details Common Criteria, offering configuration procedures, verification steps, and guidelines for operating in CC mode to achieve and maintain relevant security certification requirements.


A Common Criteria certificate is a security assurance certification that

  • provides independent verification that IT products meet specified security requirements,

  • twenty-four countries worldwide officially recognize this certification,

  • and this scheme uses defined protection profiles for requirements, tests, and evaluation methodologies.

Common Criteria protection profiles and further information

Common Criteria (CC) is a global testing standard. It verifies whether a device provides the security functionalities claimed by product developers. The standard establishes requirements, tests, and an evaluation methodology to ensure that IT products comply with recognized security standards.

The Target of Evaluation (ToE) is the product or system under evaluation. It must conform to protection profiles under the Common Criteria scheme. The applicable protection profiles are:

  • Collaborative Protection Profile for Network Devices (NDcPP) version 2 dated 2017-05-05,

  • Wireless Local Area Network (WLAN) Access Systems Extended Package version 1 dated 2015-05-29.

The CC certificate’s recognition by twenty-four countries ensures that vendors can demonstrate compliance with internationally accepted security requirements.

For more information about CC, refer to the Cisco Common Criteria documentation.


Configure the common criteria (CLI)

Enable common criteria mode for enhanced security compliance on your wireless controller.

Procedure

1.

Enter global configuration mode.

Example:

Device# configure terminal
2.

Configure the common criteria mode for the controller.

Example:

Device(config)# wireless wlancc
Note

Reboot the controller after enabling the common criteria mode.

3.

Configure the cipher suite supported by DTLS.

Example:

Device(config)# ap dtls-cipher ciphersuite
Note

Reboot the controller to activate the selected cipher suite.

4.

Configure DTLS version 1.0 or 1.2.

Example:

Device(config)# ap dtls-version dtls_1_0 dtls_1_2
Note

Save the configuration and reload the controller for the changes to take effect.

5.

Exit the configuration mode and enter the privileged EXEC mode.

Example:

Device(config)# end

The controller operates in common criteria mode with the chosen DTLS cipher suite and protocol version. The changes take effect after you reboot the controller.


Verify CC configuration

Use the this show command to display the wireless certification configurations:


Device# show wireless certification config
Wireless Certification Configurations

WLANCC                                    : Configured
AP DTLS Cipher Suite                      : DHE-RSA-AES128-SHA
                                            DHE-RSA-AES256-SHA
                                            DHE-RSA-AES256-SHA256
                                            ECDHE-ECDSA-AES128-GCM-SHA256
                                            ECDHE-ECDSA-AES256-GCM-SHA384
AP DTLS Version                           : DTLS v1.2

Check points for CC mode operation

This topic describes the key check points and considerations for CC mode operation on Cisco Catalyst 9800 Series Wireless Controllers.

Check points for CC mode operation

You need to be aware of these for CC mode operation:

Table 1. Check points for CC mode operation

Features

Description

Link encryption

Data link encryption is not supported for C91xx wireless mobility express platform.

Link encryption

For non-C91xx wireless mobility express platfoms - Enabling Data link encryption (using ECDHE keypair) would make AP flap continually.

LDAP

Secure LDAP does not support strong ciphers and is not part of CC certification.

Mobility

Mobility between Cisco Catalyst 9800 Series Wireless controllers is possible with LSC as wireless management trustpoint (having RSA based keys).

Mobility

Mobility between AireOS WLC and Cisco Catalyst 9800 Series Wireless controllers is supported (using SUDI and MIC certificates for wireless management trustpoint).

Mobility

Mobility between AireOS WLC and Cisco Catalyst 9800 Series Wireless controllers is not supported (if using LSC certficates for wireless management trustpoint).

CC mode

The show wireless certification config command displays the configured values for WLANCC, or AP-dtls-ciphersuite, or AP-dtls-version, and needs reload after re-configuring these parameters.

CC mode

The AES128-SHA option is not supported for AP-dtls-ciphersuite when Cisco Catalyst 9800 Series Wireless Controller is operating in CC mode.

CC mode

The AES128-SHA option is supported for AP-dtls-ciphersuite when Cisco Catalyst 9800 Series Wireless Controller is operating in FIPS mode.

CC mode

If you want your Cisco Catalyst 9800 Series Wireless Controller to operate in CC mode (you need to enable both FIPS mode and CC mode).

LSC

To secure communication between Cisco Catalyst 9800 Series Wireless Controller and LSC server, you need to deploy ESTCA as LSC server (which uses TLS to secure related communication).

LSC

Cisco Catalyst 9800 Series Wireless Controllers do not support HTTPS to secure its communication with the LSC server.

LSC

During LSC provisioning, APs generate EC based keys only when related Cisco Catalyst 9800 Series Wireless Controller is operating in CC mode.

LSC

During LSC provisioning, APs generate RSA based keys when related Cisco Catalyst 9800 Series Wireless Controller is operating in FIPS mode.

LSC

During LSC provisioning, APs generate RSA based keys when related Cisco Catalyst 9800 Series Wireless Controlle is operating in non-FIPS or non-CC mode.

Password Obfuscation

You can use the following commands for password obfuscation:

  • key config-key password-encrypt

  • service password-encryption

  • password encryption aes

  • passwd key obfuscate

CC mode

APs reload immediately, if you change the wlancc status.

FIPS mode

APs do not reload immediately, if you change the FIPS status.

Cisco 1562 AP

To assist Cisco 1562 APs join the Cisco Catalyst 9800 Series wireless controller, you need to have the ethernet MAC of the AP in the username list.

AP serial number authorization

Serial number authorization is possible only when Cisco Catalyst 9800 Series wireless controller is in FIPS and CC mode, and with LSC based trustpoints/certficates only (not with SUDI trustpoint).

Display

FIPS suitability displays Suitable only if the controller is in CC mode and LSC certificate is compatible. Both wireless management and Certs CN should match the hostname of the controller and length of RSA Key (> 2048) (or) EC keys being used.

RADSEC

RSA key size must contain a minimum of 2048 bits (of certificate under RADSEC) when operating in FIPS or CC mode, else RADSEC fails.