System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

SSH remote public key authentication using TACACS+

Want to summarize with AI?

Log in

Describes SSH remote public key authentication with TACACS+ integration and explains centralized SSH key management and secure access benefits.


A SSH remote public key authentications using TACACS+ is a feature that

  • enables centralized retrieval and validation of SSH public keys through TACACS+ AAA servers,

  • supports fallback to authorized_keys files based on configuration settings, and

  • provides real-time access control and unified auditing across managed network devices.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

SSH remote public key authentication using TACACS+

Release 26.3.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100], 8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100]); Modular Systems (8800 [LC ASIC: P100]) (select variants only*).

You can centrally manage SSH public keys on IOS XR by enabling devices to retrieve and validate user public keys from TACACS+ servers at login. This feature simplifies key management, streamlines access control, and supports fallback to local keys for continued access if the server is unavailable.


Key features and operational details

When a user attempts SSH login with public key authentication, the device queries the TACACS+ server for the user's authorized public keys. If the server returns keys, the device compares the returned keys and validates the SSH signature locally.

If fallback is enabled in the AAA method list, the device can check the local authorized_keys file when the TACACS+ server is unreachable or when no public key is available for the user. If the TACACS+ server explicitly denies the request, authentication fails and local fallback is not used.

Table 2. Platform and server requirements

Item

Requirement

Description

Platform

Supported platforms

Feature is platform and release dependent

TACACS+ server

SSH public key attribute support

Required for remote authentication and key query handling

Note
  • The TACACS+ server must support SSH public key attributes for this feature to work.

  • Always validate platform, release, and TACACS+ server compatibility before deployment. Centralized SSH key management enhances security, but fallback configuration must be designed to meet operational requirements.


Support and restrictions of SSH remote public key authentication using TACACS+

Provides platform compatibility details, server requirements, configuration restrictions, and compatibility notes for SSH remote public key authentication using TACACS+ on devices.

Table 3. Platform and server compatibility

Requirement

Description

Platform or server

TACACS+ server requirements

Server must support SSH public key attributes

  • Cisco ISE

  • tac_plus_ng

Cisco ISE support

Provides SSH public key attribute services as a TACACS+ server

Cisco ISE

Open-source server usage

Validated only for testing and lab environments

  • tac_plus

  • tac_plus_ng

SSH feature configuration

Requires the ssh server enable remote-pubkey-auth command

Supported platforms

Table 4. Configuration restrictions and compatibility notes

Restriction

Allowed configuration

Behavior

Feature state

Enable the feature with ssh server enable remote-pubkey-auth

Feature is disabled by default

Fallback to local authorized_keys

local must be present in the AAA method list

Local fallback is allowed if configured in AAA

Explicit denial from TACACS+ server

No fallback permitted

Access is denied if the TACACS+ server explicitly denies the request

Unreachable TACACS+ servers

Fallback allowed only if AAA configuration permits

Device uses local authorized_keys if permitted

SSH public key query caching

No caching is supported

Device always queries the server

Note
  • The feature is disabled by default. You must enable it with command ssh server enable remote-pubkey-auth.

  • Fallback to local authorized_keys is permitted only if local is included in the AAA method list.

  • If the TACACS+ server explicitly denies access, fallback to local authentication is not allowed.

  • If all TACACS+ servers are unreachable, fallback to local Key occurs only if the AAA configuration permits it.

  • There is no caching of SSH public key queries. The device queries the configured server for current access control.


How SSH remote public key authentication using TACACS+ servers works

This process begins when a user attempts SSH public key authentication on a device that is configured to use TACACS+ for remote public key lookup. The device retrieves the user's authorized public keys from the TACACS+ server, validates the SSH signature locally, and applies AAA policy to determine whether access is granted.

Summary

The key components involved in the process are:

  • SSH client initiates a connection using the user’s private key to generate a signature for authentication.

  • CiscoSSHd (SSH server) receives SSH login attempts, manages the authentication workflow, and calls the AAA subsystem.

  • The AAA method list determines whether local fallback is allowed.

  • The TACACS+ server stores user public keys and processes requests for SSH key-based authentication, returning authorization or fallback instructions as appropriate.

Workflow

The process involves the following stages:

  1. SSH login starts

    • The user starts an SSH client, enters a username, and initiates login with the public key authentication.

    • The SSH client sends a public key authentication request and signature to the SSH server.

    • The SSH server receives the authentication request, and the session waits for authentication to complete.

    • No access is granted at this stage.

  2. Device queries TACACS+

    • The device checks the AAA method list to determine whether TACACS+ remote public key authentication is enabled.

    • If TACACS+ remote public key authentication enabled, the AAA subsystem sends an SSH key query to the TACACS+ server to retrieve the user's authorized public keys.

    • Only the username is sent. The user's public key and signature are not sent to the TACACS+ server.

  3. TACACS+ returns key information

    • The TACACS+ server receives the query, looks up the user's authorized public keys, and forms a response.

    • If public keys are found, the server returns them to the device.

    • If no public key is found, or if the server cannot complete the request, the response can lead to local fallback if the AAA method list allows it.

    • If the server explicitly denies the request, authentication fails and local fallback is not attempted.

  4. Device verifies the signature

    • CiscoSSHd compares the user’s provided key and signature against the public keys returned by the TACACS+ server.

    • If a valid match and signature are found, authentication is allowed and the SSH session is established.

    • If there is no match or a "no public key" response, fallback logic may activate based on the AAA method list.

    • If the server explicitly denies access, no fallback occurs and authentication is denied immediately.

    This stage provides both centralized policy enforcement and local cryptographic verification.

    If authentication fails here and fallback is not permitted, the session is terminated.

  5. Device checks local keys if fallback is allowed

    • If the AAA method list allows local fallback, the device checks the local authorized_keys file when TACACS+ does not provide a usable key result, such as when no public key is found or the server is unreachable.

    • If a matching local key is found and the signature is valid, authentication succeeds.

    • If no matching local key is found, authentication fails.

    • If the TACACS+ server explicitly denies access, no fallback occurs and access is denied immediately.

Result

SSH access is granted only if authentication succeeds through TACACS+ or, when permitted, through the local authorized_keys file. SSH access is denied if authentication fails or if the TACACS+ server explicitly denies the request.

What’s next

To troubleshoot authentication, use show tacacs counters and show tacacs trace commands. Adjust the AAA method list to manage fallback or enforce stricter authentication policies as required.


Configure SSH remote public key authentication using TACACS+

This task configures centralized SSH remote public key authentication on the devices using TACACS+ as the external AAA method.

SSH remote public key authentication with TACACS+ allows the device to retrieve user public keys from an external AAA server during SSH login and validate signatures locally. If configured in the AAA method list, the device can fall back to local authentication when TACACS+ is unavailable.

Before you begin

  • Ensure that the device can reach an operational TACACS+ server for authentication requests.

  • Verify that user accounts on the TACACS+ server include SSH public key attributes in the supported format.

  • Confirm that SSH server is enabled and operational on the device.

Follow these steps to configure SSH remote public key authentication using TACACS+.

Procedure

  1. Enter global configuration mode.

    Example:

    configure terminal

    Use this mode to apply configuration changes to the device. All subsequent commands are entered in configuration mode.

    You are now in global configuration mode.

  2. Enable SSH remote public key authentication with TACACS+.

    Example:

    ssh server enable remote-pubkey-auth

    This command enables the device to retrieve user SSH public keys from a TACACS+ server for SSH login authentication. The device validates SSH signatures locally.

    Tip

    Only new SSH login attempts will use the remote public key feature.

  3. Configure the AAA method list to use TACACS+ for SSH authentication, with local fallback if required.

    Example:

    aaa authentication login default group tacacs+ local

    This line makes TACACS+ the default method for SSH authentication and falls back to local credentials (including local authorized keys) if all TACACS+ servers fail or are unreachable. If local is omitted, local fallback is not available.

    Tip
    You can define custom method lists for specific lines or groups as needed.

    AAA method list for SSH authentication is configured with TACACS+ as primary and local fallback as required.

  4. Define the TACACS+ server group and add the server entries.

    Example:

    tacacs-server host 10.10.10.10
     key 0 <TACACS_SHARED_SECRET>
    !
    aaa group server tacacs+ TACXRGRP
     server 10.10.10.10
    !

    Configure each TACACS+ server with address and shared secret, then create a group for redundancy. Reference the group in the AAA method list if required. For more information about configuring TACACS+ server groups, see Configure TACACS+ Server Groups.

    Repeat the server configuration for each TACACS+ server you use.

  5. Commit the configuration to apply changes.

    Example:

    commit

    This saves and activates all changes, including enabling SSH remote public key authentication and configuring AAA and TACACS+ server properties.

    • Check configuration for errors before committing.

    Configuration is saved, activating remote SSH public key authentication with TACACS+.

New SSH authentication attempts use user public keys retrieved from the configured TACACS+ server, aligning access control and audits with centralized AAA policy. Local key authentication occurs only if fallback is defined in the AAA method list.