Is TACACS+ session data obfuscation weak?
AP 6350 OCSBC 9.1
I see session-id = 0 in all TACACS+ requests generated by the SBC, however rfc8907 states for this field that "This number MUST be generated by a cryptographically strong random number generation method." How does Oracle view this approach to data obfuscation?
Thanks