RFC 4739 · EXPERIMENTAL · 2006

Multiple Authentication Exchanges in the Internet Key Exchange Protocol

Overview

RFC 4739, “Multiple Authentication Exchanges in the Internet Key Exchange Protocol”, is an Experimental document published in November 2006 by P. Eronen, J. Korhonen. The canonical text is published by the RFC Editor.

Abstract

The Internet Key Exchange (IKEv2) protocol supports several mechanisms for authenticating the parties, including signatures with public-key certificates, shared secrets, and Extensible Authentication Protocol (EAP) methods. Currently, each endpoint uses only one of these mechanisms to authenticate itself. This document specifies an extension to IKEv2 that allows the use of multiple authentication exchanges, using either different mechanisms or the same mechanism. This extension allows, for instance, performing certificate-based authentication of the client host followed by an EAP authentication of the user. When backend authentication servers are used, they can belong to different administrative domains, such as the network access provider and the service provider. This memo defines an Experimental Protocol for the Internet community.

Abstract as published in the RFC, via rfc-editor.org.

What “Experimental” means

Describes a specification that is part of a research or development effort, published so the community can gain experience with it.

Read this RFC

The canonical text of RFC 4739 is hosted at rfc-editor.org. Available in TXT,HTML.

Other RFCs from 2006

Who Is Online

In total there are 66 users online: 0 registered, 59 guests and 7 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: AhrefsBot Baiduspider Bingbot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372