FC-SP uses DHCHAP protocol for authenticating authentication between MDS9000 and other devices could potencially use both tacacs and radius. However, as it tells us all communication between them should be encrypted, only TACACS provides full AAA encryption. https://www.cisco.com/c/en/us/td/docs/switches/datacenter/mds9000/sw/8_x/config/security/cisco _mds9000_security_config_guide_8x/configuring_fcsp_dhchap.html#con_1247118