27.03.2013 Views

Cisco Broadband Cable Command Reference Guide

Cisco Broadband Cable Command Reference Guide

Cisco Broadband Cable Command Reference Guide

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 2 <strong>Cisco</strong> <strong>Cable</strong> Modem Termination System <strong>Command</strong>s<br />

cable privacy<br />

Syntax Description<br />

OL-1581-05<br />

<strong>Cisco</strong> <strong>Broadband</strong> <strong>Cable</strong> <strong>Command</strong> <strong>Reference</strong> <strong>Guide</strong><br />

cable privacy<br />

To enable and configure BPI/BPI+ encryption, use the cable privacy command in cable interface<br />

configuration mode. To disable privacy or to remove a particular configuration, use the no form of this<br />

command.<br />

cable privacy [40-bit-des | accept-self-signed-certificate | authenticate-modem |<br />

authorize-multicast | mandatory | oaep-support | dsx-support]<br />

no cable privacy [40-bit-des | accept-self-signed-certificate | authenticate-modem |<br />

authorize-multicast | mandatory | oaep-support | dsx-support]<br />

Defaults BPI is disabled. When enabled, 56-bit DES encryption is enabled by default, and self-signed<br />

manufacturer certificates are not allowed.<br />

<strong>Command</strong> Modes Interface configuration (cable interface only)<br />

<strong>Command</strong> History<br />

40-bit-des (Optional) Uses 40-bit DES encryption.<br />

Note <strong>Cisco</strong> discourages the use of 40-bit DES encryption because<br />

it is not as secure as the other available methods of<br />

encryption.<br />

accept-self-signed-certificate (Optional) Allows cable modems to register using self-signed<br />

manufacturer certificates, as opposed to a manufacturer certificate<br />

that is chained to the DOCSIS root certificate.<br />

authenticate-modem (Optional) Uses AAA protocols in conjunction with BPI to<br />

authenticate all CMs.<br />

authorize-multicast (Optional) Uses AAA protocols with BPI to authorize all multicast<br />

stream (IGMP) join requests.<br />

dsx-support (Optional) Enables encryption for dynamic services SIDs.<br />

mandatory (Optional) Requires baseline privacy for all CMs.<br />

oaep-support (Optional) Enables Optimal Asymmetric Encryption Padding<br />

(OAEP) BPI+ encryption.<br />

Release Modification<br />

12.1 T This command was introduced.<br />

12.1(4)CX,<br />

Added the dsx-support and oaep-support keywords as part of support for<br />

12.2(1)XF1,<br />

12.2(4)BC1<br />

BPI+ encryption.<br />

12.2(11)BC1 Changed the accept-self-signed-certificate option from a global<br />

configuration option to a cable interface option.<br />

Usage <strong>Guide</strong>lines This command is applicable only on images that support BPI or BPI+ encryption.<br />

2-115

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!