TACACS+ over TLS Overview

Understand how TACACS+ over TLS encapsulates AAA exchanges in a TLS 1.3 connection to secure management-plane credentials, using certificate-based server authentication and optional mutual TLS for client authentication

TACACS+ over TLS encapsulates TACACS+ AAA (authentication, authorization, and accounting) in a TLS 1.3 protected connection to secure management-plane credential and policy exchanges. TLS provides confidentiality and integrity and uses certificate-based authentication to validate the TACACS+ server identity. Optionally, you can configure mutual TLS (mTLS) so the server also authenticates the client by using a client certificate during the TLS handshake.

You configure TLS settings per TACACS+ server and per TACACS+ accounting destination by binding each entry to a trusted certificate authority (CA) group for server-certificate validation. After the TLS session is established, TACACS+ behavior and authorization semantics are the same as TACACS+ over TCP, including the same mutual-exclusion rules for command/configuration allow or deny parameters and their regular expression variants. You can configure multiple servers and use standard AAA ordering and failover, including mixed TLS and TCP server lists and fallback to other authentication methods such as RADIUS or local authentication. You can reach TACACS+ servers over IPv4 or IPv6 from the routing instance you select.

Benefits of TACACS+ over TLS (TLS 1.3) for AAA

  • Protects TACACS+ AAA traffic from eavesdropping and tampering by encrypting traffic and applying integrity checks.

  • Reduces exposure of administrator credentials and authorization decisions by using TLS instead of legacy TACACS+ obfuscation.

  • Helps prevent connections to untrusted AAA endpoints by validating the TACACS+ server identity with X.509 certificates chained to a configured trusted CA.

  • Supports deployments that require two-way identity verification by enabling mTLS so the server can authenticate the client before accepting AAA requests.

  • Preserves resiliency during AAA outages by supporting multiple servers and predictable ordering and failover when a server is unreachable or fails TLS validation.

How TACACS+ over TLS works

When you enable TACACS+ over TLS for a TACACS+ server entry, the AAA client establishes a TLS 1.3 session and sends TACACS+ exchanges through the encrypted channel. The TLS handshake controls AAA reachability. If the client cannot negotiate TLS or cannot validate the server certificate, it does not send TACACS+ requests to that server, and AAA proceeds based on the configured authentication order.

Server certificate validation uses the trusted CA group you configure for the server entry. With mTLS, the client also presents a local certificate identity during the handshake. Public key infrastructure (PKI) conditions such as an expired certificate, an untrusted issuer, or an incomplete certificate chain can cause the handshake to fail and trigger failover to the next configured server or method.

After TLS is established, TACACS+ request and response handling is the same as TACACS+ over TCP. If a TLS-enabled server is unreachable or fails TLS establishment, the client tries the next TACACS+ server in the configured list (which can include a mix of TLS and non-TLS entries) and then other methods such as RADIUS or local authentication, as dictated by your authentication order. The routing instance you select determines which interfaces and routing table the device uses to reach the TACACS+ server.

Key configuration points

To enable TACACS+ over TLS for authentication, attach TLS settings to the TACACS+ server definition so the client uses the correct CA trust and, optionally, the correct client identity:

  • set system tacplus-server server-ip tls trusted-ca-group trusted-ca-group

  • set system tacplus-server server-ip tls mutual-authentication certificate-id certificate-id

To enable TACACS+ over TLS for accounting, apply the same TLS bindings under the TACACS+ accounting destination so accounting records use the TLS protected channel:

  • set system accounting destination tacplus server server-ip tls trusted-ca-group trusted-ca-group

  • set system accounting destination tacplus server server-ip tls mutual-authentication certificate-id certificate-id

If you mix TACACS+ over TLS and TACACS+ over TCP entries, define the server list order intentionally. The client attempts servers in the configured order and advances on TLS negotiation or certificate validation failure based on your AAA configuration.