Specifies a global value for the secret key used to communicate with the TACACS+ servers configured on an appliance.
Important
The key you configure on the appliance must match the key that was configured on the TACACS+ servers.
Note
For security, you can use this command without the
key stringparameter to be prompted to enter and confirm the key, with the entries masked with*characters.This key is not used to communicate with a specific TACACS+ server if another key is configured using the
tacacs-server host <ip address> key <key string>command.
Syntax
tacacs-server key [<key string>]
no tacacs-server key
Parameters
no
Use the no form of this command to remove the global key from the appliance configuration.
key string
Specify the key string.
Examples
The following example sets the global secret key.
hostname (config) # tacacs-server key 789101
The following example sets the global secret key with masked characters.
hostname (config) # tacacs-server key Key: ****** Confirm: ******
The following example removes the global secret key.
hostname (config) # no tacacs-server key
User role
Admin
Command mode
Config
Supported appliances
This command is supported on the following appliances running the specified releases or later:
Malware Analysis: Before release 6.4
Central Management System: Before release 6.4
Email Security — Server: Before release 6.4
File Protect: Before release 6.4
Endpoint Security (HX): Release 2.5
Network Security: Before release 6.4