RFC 4169 · INFORMATIONAL · 2005

Hypertext Transfer Protocol Digest Authentication Using Authentication and Key Agreement Version-2

Overview

RFC 4169, “Hypertext Transfer Protocol Digest Authentication Using Authentication and Key Agreement Version-2”, is an Informational document published in November 2005 by V. Torvinen, J. Arkko, M. Naslund. The canonical text is published by the RFC Editor.

Abstract

HTTP Digest, as specified in RFC 2617, is known to be vulnerable to man-in-the-middle attacks if the client fails to authenticate the server in TLS, or if the same passwords are used for authentication in some other context without TLS. This is a general problem that exists not just with HTTP Digest, but also with other IETF protocols that use tunneled authentication. This document specifies version 2 of the HTTP Digest AKA algorithm (RFC 3310). This algorithm can be implemented in a way that it is resistant to the man-in-the-middle attack. This memo provides information for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Informational” means

Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.

Read this RFC

The canonical text of RFC 4169 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2005

Who Is Online

In total there are 57 users online: 0 registered, 50 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372