Acme Packet (MOSC)

MOSC Banner

Is TACACS+ session data obfuscation weak?

AP 6350 OCSBC 9.1

I see session-id = 0 in all TACACS+ requests generated by the SBC, however rfc8907 states for this field that "This number MUST be generated by a cryptographically strong random number generation method." How does Oracle view this approach to data obfuscation?


Thanks

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center