to do Tacacs+ TLS Based Device Administration, need to deploy certificates to devices in PKCS format.
- How we can use DNAC to push the certificate file ?
- Is there a way I can use a common cert for all Devices for TLS 1.3 Tacacs purpose
- How to make it efficient so that these device certs can be uploaded in bulk when expiration is close to the date is it possible to deploy the Device cert from DNAC to individual device ? If we can use DNAC to push certificates than it would be much easier to import ca signed certs to devices.
Here is the doc link for Tacacs+ TLS based Device Administration.
https://www.cisco.com/c/en/us/support/docs/security-vpn/terminal-access-controller-access-control-system-tacacs-/225097-configure-tacacs-over-tls-1-3-on-an.html