CurrentPROPOSED STANDARDIETF stream

RFC 9887: Terminal Access Controller Access-Control System Plus (TACACS+) over TLS 1.3

In plain English — editorial summary, not part of the RFC

This document specifies the use of Transport Layer Security (TLS) version 1.3 to secure the communication channel between a Terminal Access Controller Access-Control System Plus (TACACS+) client and server. TACACS+ is a protocol used for Authentication, Authorization, and Accounting (AAA) in networked environments. The original TACACS+ protocol does not mandate the use of encryption or secure transport. This specification defines a profile for using TLS 1.3 with TACACS+, including guidance on authentication, connection establishment, and operational considerations. The goal is to enhance the confidentiality, integrity, and authenticity of TACACS+ traffic, aligning the protocol with modern security best practices. This document updates RFC 8907.

Document record

Document ID
RFC9887
Published
December 2025
Authors
T. Dahm; J. Heasley; D.C. Medway Gash; A. Ota
Status
PROPOSED STANDARD
Stream
IETF
Area
ops
Pages
15
Also known as
Updates:
RFC 8907

Topics

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/9887-terminal-access-controller-access-control-system-plus-tacacs-over-tls-1-3