bsicloud enable
By default, BSI Cloud mode is not enabled.
Global configuration mode
BSI Cloud mode is enabled when a secure ECDSA connection has been established with a SmartZone device or using this command.
When ECDSA encryption is enabled on
the SmartZone controller for the switch group the ICX device belongs to, as soon as
the ICX device has exchanged elliptic curve cryptography (ECC) keys and received
valid certificates from SmartZone, bsicloud enable is
automatically configured.
When the bsicloud enable command
is configured, the system performs actions to ensure that RSA keys with a size less
than 3000, non-compliant ssh key exchange algorithms, host-key algorithm, encryption
algorithms, and weaker TLS cipher suites are disabled. However, you can still change
the SSH configuration using CLI commands.
The following actions are performed:
- All existing inbound and outbound SSH sessions are terminated.
- All RSA 2K keys generated
with the
crypto key gen rsacommand are deleted, and generation of additional RSA 2K keys is blocked. - RSA 3K keys are generated.
- All copies of SSH client public keys are deleted.
- Current SSL sessions for Syslog, RADIUS, and TACACS+ are terminated.
- Existing user certificates and keys are deleted.
- A locally signed ECDSA certificate is created and is used as the NGINX server certificate for Web UI and RESTCONF, replacing the preinstalled RUCKUS-signed device certificate.
- The NGINX service is stopped and restarted.
- For reverse SSH and TLS authentication, ICX devices and SmartZone use new ECDSA keys and certificates.
The no form of the command resets the ICX device to default mode.
| Release version | Command history |
|---|---|
| 10.0.10c | This command was introduced. |