haussli / draft-dahm-opsawg-tacacs-security

IETF draft for new tacacs+ security features
1 stars 1 forks source link

Alan Dekok: existing TACACS+ port can be used for TLS #48

Closed dcmgashcisco closed 2 years ago

dcmgashcisco commented 2 years ago

This is a quick review based on first impressions.

It may be good to have a note that the existing TACACS+ port can be used for TLS, if both ends are configured to require TLS. That means systems can use existing firewall rules, etc. for TACACS+TLS.

haussli commented 2 years ago

Is it really necessary to explain this? S3.1 and S8.2 explain allocation of a new port. But, is there a service that does not allow the ports to be changed?

haussli commented 2 years ago

Noted that other ports could be used in be6a238.