Describes SSH remote public key authentication with TACACS+ integration and explains centralized SSH key management and secure access benefits.
A SSH remote public key authentications using TACACS+ is a feature that
-
enables centralized retrieval and validation of SSH public keys through TACACS+ AAA servers,
-
supports fallback to
authorized_keysfiles based on configuration settings, and -
provides real-time access control and unified auditing across managed network devices.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
SSH remote public key authentication using TACACS+ |
Release 26.3.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100], 8200 [ASIC: Q100, Q200, P100], 8700 [ASIC: P100, K100]); Modular Systems (8800 [LC ASIC: P100]) (select variants only*). You can centrally manage SSH public keys on IOS XR by enabling devices to retrieve and validate user public keys from TACACS+ servers at login. This feature simplifies key management, streamlines access control, and supports fallback to local keys for continued access if the server is unavailable. |