![nanog logo](/images/nanog-logo.png)
nanog mailing list archives
Re: TACACS+ server recommendations?
From: Christopher Morrow <morrowc.lists () gmail com>
Date: Thu, 21 Sep 2023 12:26:44 -0400
On Thu, Sep 21, 2023 at 6:56 AM Jim <mysidia () gmail com> wrote: ...
My understanding is a good number of password manager products exists which will handle that, and then the only AAA which network devices need to be concerned about for Authentication and Authorization is Basic password auth, which all equipment supports. And the security problems don't arise so much for using the TACACS+ / Tac_plus service Solely for Accounting (in addition to basic remote syslog).
it's important to recognize that there's not really any protection (practical protection) from MITM if you use a passwd with your ssh connection. A key'd authentication has these protections, as a quirk of the ssh protocol... (or a design feature if you wish) A certificate authenticated session has these same protections.
Current thread:
- TACACS+ server recommendations? Bryan Holloway (Sep 20)
- Re: TACACS+ server recommendations? Mark Tinka (Sep 20)
- Re: TACACS+ server recommendations? Jeff Moore (Sep 20)
- Re: TACACS+ server recommendations? Mark Tinka (Sep 20)
- Re: TACACS+ server recommendations? Mike Lewinski via NANOG (Sep 20)
- Re: TACACS+ server recommendations? Jim (Sep 20)
- Re: TACACS+ server recommendations? Warren Kumari (Sep 20)
- Re: TACACS+ server recommendations? Christopher Morrow (Sep 20)
- Re: TACACS+ server recommendations? Simon Leinen (Sep 21)
- Re: TACACS+ server recommendations? Jim (Sep 21)
- Re: TACACS+ server recommendations? Christopher Morrow (Sep 21)
- RE: TACACS+ server recommendations? Kevin Burke via NANOG (Sep 22)
- Re: TACACS+ server recommendations? Tim Burke (Sep 22)
- Re: TACACS+ server recommendations? Mike Lewinski via NANOG (Sep 22)
- Re: TACACS+ server recommendations? J. Hellenthal via NANOG (Sep 23)
- Re: TACACS+ server recommendations? Alberto Vargas (Sep 23)
- Re: TACACS+ server recommendations? Jeff Moore (Sep 20)
- Re: TACACS+ server recommendations? Mark Tinka (Sep 20)
- Re: TACACS+ server recommendations? Christopher Morrow (Sep 21)
- Re: TACACS+ server recommendations? Bernhard Schmidt (Sep 25)