Overview of BSI C5 Cloud Mode
BSI C5 Cloud Mode supports certain information security requirements for cloud computing, referred to as Cloud Computing Compliance Controls Catalog (C5). The requirements were developed by the German Federal Office for Information Security (BSI).
BSI Cloud mode is enabled when an ICX device is managed by a SmartZone controller that is configured for BSI C5 compliance and is using Elliptic Curve Digital Signature Algorithm (ECDSA) for public key certificate validation.
BSI Cloud mode can also be enabled through the CLI to make the switch compliant with BSI C5 requirements for SSH, HTTPs-based image copy, and Web Management.
ECDSA Connections to SmartZone
When the ICX device is placed in a SmartZone switch group with ECDSA enabled, the SmartZone controller onboards the ICX device using the pre-installed device certificates and then sends a controller-signed certificate, along with the other requisite EC keys. Once these items have been received and registered by the ICX device, BSI Cloud mode is automatically enabled on the ICX device from SmartZone.
The ECDSA certificate is stored on the ICX device and is persistent across reboots.
The ECDSA certificate from SmartZone is persistent in BSI cloud mode.
BSI Cloud Mode Changes
When BSI Cloud mode is first enabled, the following changes are triggered on the ICX device.
- All SSH sessions are terminated, and all RSA 2K keys generated by the crypto key gen rsa command are deleted.
- Current SSL sessions for Syslog, RADIUS, and TACACS+ are terminated.
- The crypto key gen rsa command is prevented from generating 2048 RSA keys. Stronger RSA keys can still be generated.
- New logging host, RADIUS, and secure TACACS+ Sessions can be established only using enhanced 3K certificates.
- All RSA 2K client public keys
generated with the
crypto key client generate rsacommand are deleted, and generation of RSA 2K keys is blocked. - An RSA 3K key is generated.
- The client’s public key that was copied to the fast_iron folder is deleted.
- The contents of authorized keys are deleted.
- User certificates and keys with a .pem extension are deleted.
- A locally signed ECDSA certificate is created and is used in BSI cloud mode for applications such as the Web UI, TES, and RESTCONF.
Once these changes are made, the ICX device uses the new ECDSA keys and ECDSA certificate to establish reverse SSH and TLS connections with SmartZone.