bsicloud enable

Enables BSI cloud mode on the ICX device.
Syntax
bsicloud enable
no bsicloud enable
Command Default

By default, BSI Cloud mode is not enabled.

Modes

Global configuration mode

Usage Guidelines

BSI Cloud mode is enabled when a secure ECDSA connection has been established with a SmartZone device or using this command.

When ECDSA encryption is enabled on the SmartZone controller for the switch group the ICX device belongs to, as soon as the ICX device has exchanged elliptic curve cryptography (ECC) keys and received valid certificates from SmartZone, bsicloud enable is automatically configured.

When the bsicloud enable command is configured, the system performs actions to ensure that RSA keys with a size less than 3000, non-compliant ssh key exchange algorithms, host-key algorithm, encryption algorithms, and weaker TLS cipher suites are disabled. However, you can still change the SSH configuration using CLI commands.

The following actions are performed:

  • All existing inbound and outbound SSH sessions are terminated.
  • All RSA 2K keys generated with the crypto key gen rsa command are deleted, and generation of additional RSA 2K keys is blocked.
  • RSA 3K keys are generated.
  • All copies of SSH client public keys are deleted.
  • Current SSL sessions for Syslog, RADIUS, and TACACS+ are terminated.
  • Existing user certificates and keys are deleted.
  • A locally signed ECDSA certificate is created and is used as the NGINX server certificate for Web UI and RESTCONF, replacing the preinstalled RUCKUS-signed device certificate.
  • The NGINX service is stopped and restarted.
  • For reverse SSH and TLS authentication, ICX devices and SmartZone use new ECDSA keys and certificates.

The no form of the command resets the ICX device to default mode.

Examples

The following example enables BSI Cloud mode.

device# configure terminal
device(config)# bsicloud enable
History
Release version Command history
10.0.10c This command was introduced.