Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0
RFC 5281, “Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0”, is an Informational document published in August 2008 by P. Funk, S. Blake-Wilson. It has since been updated by RFC 8996, RFC 9427. The canonical text is published by the RFC Editor.
Abstract
EAP-TTLS is an EAP (Extensible Authentication Protocol) method that encapsulates a TLS (Transport Layer Security) session, consisting of a handshake phase and a data phase. During the handshake phase, the server is authenticated to the client (or client and server are mutually authenticated) using standard TLS procedures, and keying material is generated in order to create a cryptographically secure tunnel for information exchange in the subsequent data phase. During the data phase, the client is authenticated to the server (or client and server are mutually authenticated) using an arbitrary authentication mechanism encapsulated within the secure tunnel. The encapsulated authentication mechanism may itself be EAP, or it may be another authentication protocol such as PAP, CHAP, MS-CHAP, or MS-CHAP-V2. Thus, EAP-TTLS allows legacy password-based authentication protocols to be used against existing authentication databases, while protecting the security of these legacy protocols against eavesdropping, man-in-the-middle, and other attacks. The data phase may also be used for additional, arbitrary data exchange. This memo provides information for the Internet community.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5281 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5280 Internet X.509 Public Key Infrastructure Certificate and Certificate Revocation List Profile
- RFC 5282 Using Authenticated Encryption Algorithms with the Encrypted Payload of the Internet Key Exchange version 2 Protocol
- RFC 5279 A Uniform Resource Name Namespace for the 3rd Generation Partnership Project
- RFC 5283 LDP Extension for Inter-Area Label Switched Paths
- RFC 5278 IANA Registration of Enumservices for Voice and Video Messaging
- RFC 5284 User-Defined Errors for RSVP
- RFC 5277 NETCONF Event Notifications
- RFC 5285 A General Mechanism for RTP Header Extensions