%% You should probably cite rfc9887 instead of this I-D. @techreport{ietf-opsawg-tacacs-tls13-24, number = {draft-ietf-opsawg-tacacs-tls13-24}, type = {Internet-Draft}, institution = {Internet Engineering Task Force}, publisher = {Internet Engineering Task Force}, note = {Work in Progress}, url = {https://datatracker.ietf.org/doc/draft-ietf-opsawg-tacacs-tls13/24/}, author = {Thorsten Dahm and John Heasley and dcmgash@cisco.com and Andrej Ota}, title = {{Terminal Access Controller Access-Control System Plus over TLS 1.3 (TACACS+ over TLS)}}, pagetotal = 19, year = 2025, month = jul, day = 9, abstract = {This document specifies the use of Transport Layer Security (TLS) version 1.3 to secure the communication channel between a Terminal Access Controller Access-Control System Plus (TACACS+) client and server. TACACS+ is a protocol used for Authentication, Authorization, and Accounting (AAA) in networked environments. The original TACACS+ protocol, does not mandate the use of encryption or secure transport. This specification defines a profile for using TLS 1.3 with TACACS+, including guidance on authentication, connection establishment, and operational considerations. The goal is to enhance the confidentiality, integrity, and authenticity of TACACS+ traffic, aligning the protocol with modern security best practices. This document updates RFC 8907.}, }