Guestshell as an SD-WAN Onboarding Certificate Workaround

Guestshell on a Cisco IOS XE-based cEdge device offers a workaround for handling certificates during SD-WAN onboarding, particularly when the automatic process is not possible or direct communication with a Certificate Authority (CA) is unavailable. With Guestshell, users can generate certificate signing requests (CSRs), store certificates locally, and manually transfer them. Although Guestshell cannot function as a CA itself, requiring certificates to be signed externally before they can be installed, it provides increased flexibility in managing certificates under such constraints.

https://networklessons.com/cisco/cisco-sd-wan/cisco-sd-wan-cedge-onboarding