Cisco ISR 4000 Family Routers Administrator Guidance
Page
12
of
66
Download the Common Criteria evaluated software image file from Cisco.com onto a
trusted computer system.
Software
images
are
available
from
Cisco.com
at
the
following:
http://www.cisco.com/cisco/software/navigator.html
.
The TOE ships with the correct software images installed, however this may not be the
evaluated version.
Step 8
Once the file is downloaded, copy (via tftp) the downloaded and verified software image
from the trusted system as described in
[3]
.
Once the file has been copied, it is recommended that you read and familiarize yourself with the
Part 2: Configuration Using Setup and Autoinstall -> Overview – Basic Configuration of a Cisco
Networking Device before proceeding with the install
[3]
. You may also want to familiarize
yourself with
[8]
basic commands,
[14]
release notes and
[15]
fundamental Cisco 4000 Series ISR
and IOS concepts before proceeding with the installation and configuration of the TOE.
Step 9
To verify the digital signature prior to installation, the show software authenticity file
command allows you to display software authentication related information that includes image
credential information, key type used for verification, signing information, and other attributes in
the signature envelope, for a specific image file. The command handler will extract the signature
envelope and its fields from the image file and dump the required information
[1]
Loading and
Maintaining
System
Images
->
Digitally
Signed
Cisco
Software.
The show software authenticity file command allows you to display software authentication related
information that includes image credential information, key type used for verification, signing
information, and other attributes in the signature envelope, for a specific image file. The command
handler will extract the signature envelope and its fields from the image file and dump the required
information. To display the software public keys that are in the storage with the key types, use the
show software authenticity keys
command in privileged EXEC mode.
TOE-common-criteria#
show
software
authenticity
file
{
bootflash0:
filename
|
bootflash1:
filename
|
bootflash:
filename
|
nvram:
filename
|
usbflash0:
filename
|
usbflash1:
filename
}
To display information related to software authentication for the current ROM monitor
(ROMMON), monitor library (monlib), and Cisco IOS image used for booting, use the
show
software authenticity running
command in privileged EXEC mode.
Step 10
To install and configure the ISR 4000 Family Router follow the instructions as described
in
[3]
Overview – Basic Configuration of a Cisco Networking Device -> Cisco IOS EX Setup
Mode. Depending on your organization and current network environment, at, Where to Go Next
section, select either ‘Using AutoInstall to Remotely Configure Cisco Networking Device’ or
Using Setup Mode to Configure a Cisco Networking Device’.
Start your ISR 4000 Family Router as described in [
15
] and executing associated commands in
[8]
and
[13]
. Confirm that the TOE
loads the image correctly, completes internal self-checks and
displays the cryptographic export warning on the console.