Consent Token; Restrictions For Consent Token; Information About Consent Token - Cisco Catalyst 9400 System Management Configuration Manual

Cisco ios xe bengaluru 17.4.x
Hide thumbs Also See for Catalyst 9400:
Table of Contents

Advertisement

Consent Token

Restrictions for Consent Token

• Consent Token is enabled by default and cannot be disabled.
• After the challenge has been sent from the device, the response needs to be entered within 30 minutes.
• A single response is valid only for one time for a corresponding challenge.
• The maximum authorization timeout for root-shell access is seven days.
• After a switchover event, all the existing Consent Token based authorizations would be treated as expired.
• Only Cisco authorized personnel have access to Consent Token response generation on Cisco's challenge
• In System Shell access scenario, exiting the shell does not terminate authorization until the authorization

Information About Consent Token

Consent Token is a security feature that is used to authenticate the network administrator of an organization
to access system shell with mutual consent from the network administrator and Cisco Technical Assistance
Centre (Cisco TAC).
In some debugging scenarios, the Cisco TAC engineer may have to collect certain debug information or
perform live debug on a production system. In such cases, the Cisco TAC engineer will ask you (the network
Restrictions for Consent Token, on page 385
Information About Consent Token, on page 385
Consent Token Authorization Process for System Shell Access, on page 386
Feature History for Consent Token, on page 387
If it is not entered, the challenge expires and a new challenge must be requested.
You must then restart a fresh authentication sequence for service access.
signing server.
timeout occurs or the shell authorization is explicitly terminated by the consent token terminate
authorization command.
We recommend that you force terminate System Shell authorization by explicitly issuing the Consent
Token terminate command once the purpose of System Shell access is complete.
System Management Configuration Guide, Cisco IOS XE Bengaluru 17.4.x (Catalyst 9400 Switches)
18
C H A P T E R
385

Advertisement

Table of Contents
loading

Table of Contents