TACACS+
TACACS and TACACS+ (Terminal Access Controller Access-Control System Plus)
Within this page
TACACS+ RFCs (6)
RFC 9950: A YANG Data Model for Terminal Access Controller Access-Control System Plus (TACACS+)
Proposed Standard- M. Boucadair
- B. Wu
- March 2026
- IETF publication
- Operations and Management Area
Abstract
This document defines a Terminal Access Controller Access-Control
System Plus (TACACS+) client YANG module that augments the System
Management data model, defined in RFC 7317, to allow devices to make
use of TACACS+ servers for centralized Authentication, Authorization,
and Accounting (AAA). Specifically, the TACACS+ YANG module can be
used to manage TACACS+ over TLS.
This document obsoletes RFC 9105.
Abstract
This document defines a Terminal Access Controller Access-Control
System Plus (TACACS+) client YANG module that augments the System
Management data model, defined in RFC 7317, to allow devices to make
use of TACACS+ servers for centralized Authentication, Authorization,
and Accounting (AAA). Specifically, the TACACS+ YANG module can be
used to manage TACACS+ over TLS.
This document obsoletes RFC 9105.
RFC 9887: Terminal Access Controller Access-Control System Plus (TACACS+) over TLS 1.3
Proposed Standard- T. Dahm
- J. Heasley
- D.C. Medway Gash
- A. Ota
- December 2025
- IETF publication
- Operations and Management Area
Abstract
This document specifies the use of Transport Layer Security (TLS) version 1.3 to secure the communication channel between a Terminal Access Controller Access-Control System Plus (TACACS+) client and server. TACACS+ is a protocol used for Authentication, Authorization, and Accounting (AAA) in networked environments. The original TACACS+ protocol does not mandate the use of encryption or secure transport. This specification defines a profile for using TLS 1.3 with TACACS+, including guidance on authentication, connection establishment, and operational considerations. The goal is to enhance the confidentiality, integrity, and authenticity of TACACS+ traffic, aligning the protocol with modern security best practices.
This document updates RFC 8907.
Abstract
This document specifies the use of Transport Layer Security (TLS) version 1.3 to secure the communication channel between a Terminal Access Controller Access-Control System Plus (TACACS+) client and server. TACACS+ is a protocol used for Authentication, Authorization, and Accounting (AAA) in networked environments. The original TACACS+ protocol does not mandate the use of encryption or secure transport. This specification defines a profile for using TLS 1.3 with TACACS+, including guidance on authentication, connection establishment, and operational considerations. The goal is to enhance the confidentiality, integrity, and authenticity of TACACS+ traffic, aligning the protocol with modern security best practices.
This document updates RFC 8907.
RFC 9105: A YANG Data Model for Terminal Access Controller Access-Control System Plus (TACACS+)
Proposed Standard- B. Wu
- G. Zheng
- M. Wang
- August 2021
- IETF publication
- Operations and Management Area
Abstract
This document defines a Terminal Access Controller Access-Control System Plus (TACACS+) client YANG module that augments the System Management data model, defined in RFC 7317, to allow devices to make use of TACACS+ servers for centralized Authentication, Authorization, and Accounting (AAA). Though being a standard module, this module does not endorse the security mechanisms of the TACACS+ protocol (RFC 8907), and TACACS+ be used within a secure deployment.
The YANG module in this document conforms to the Network Management Datastore Architecture (NMDA) defined in RFC 8342.
Obsoleted by RFC 9950
Abstract
This document defines a Terminal Access Controller Access-Control System Plus (TACACS+) client YANG module that augments the System Management data model, defined in RFC 7317, to allow devices to make use of TACACS+ servers for centralized Authentication, Authorization, and Accounting (AAA). Though being a standard module, this module does not endorse the security mechanisms of the TACACS+ protocol (RFC 8907), and TACACS+ be used within a secure deployment.
The YANG module in this document conforms to the Network Management Datastore Architecture (NMDA) defined in RFC 8342.
RFC 8907: The Terminal Access Controller Access-Control System Plus (TACACS+) Protocol
Informational- T. Dahm
- A. Ota
- D.C. Medway Gash
- D. Carrel
- L. Grant
- September 2020
- IETF publication
- Operations and Management Area
Abstract
This document describes the Terminal Access Controller Access-Control System Plus (TACACS+) protocol, which is widely deployed today to provide Device Administration for routers, network access servers, and other networked computing devices via one or more centralized servers.
Abstract
This document describes the Terminal Access Controller Access-Control System Plus (TACACS+) protocol, which is widely deployed today to provide Device Administration for routers, network access servers, and other networked computing devices via one or more centralized servers.
RFC 1492: An Access Control Protocol, Sometimes Called TACACS
Informational- C. Finseth
- July 1993
- Legacy publication
Abstract
This RFC documents the extended TACACS protocol use by the Cisco Systems terminal servers. This same protocol is used by the University of Minnesota's distributed authentication system. This memo provides information for the Internet community. It does not specify an Internet standard.
Abstract
This RFC documents the extended TACACS protocol use by the Cisco Systems terminal servers. This same protocol is used by the University of Minnesota's distributed authentication system. This memo provides information for the Internet community. It does not specify an Internet standard.
RFC 927: TACACS user identification Telnet option
Proposed Standard- B.A. Anderson
- December 1984
- Legacy publication
Abstract
The following is the description of a TELNET option designed to facilitate double login avoidance. It is intended primarily for TAC connections to target hosts on behalf of TAC users, but it can be used between any two consenting hosts. For example, all hosts at one site (e.g., BBN) can use this option to avoid double login when TELNETing to one another. This RFC suggests a proposed protocol for the ARPA-Internet community, and requests discussion and suggestions for improvements.
Abstract
The following is the description of a TELNET option designed to facilitate double login avoidance. It is intended primarily for TAC connections to target hosts on behalf of TAC users, but it can be used between any two consenting hosts. For example, all hosts at one site (e.g., BBN) can use this option to avoid double login when TELNETing to one another. This RFC suggests a proposed protocol for the ARPA-Internet community, and requests discussion and suggestions for improvements.
Subscribe to TACACS+
Get notified when:
- RFC changes to status, obsoleted by, updates, updated by, or subseries.
- New RFC added to this subject or below
- The subject was merged into another.