Extensible Authentication Protocol Authentication Using Only a Password
RFC 5931, “Extensible Authentication Protocol Authentication Using Only a Password”, is an Informational document published in August 2010 by D. Harkins, G. Zorn. It has since been updated by RFC 8146. The canonical text is published by the RFC Editor.
Abstract
This memo describes an Extensible Authentication Protocol (EAP) method, EAP-pwd, which uses a shared password for authentication. The password may be a low-entropy one and may be drawn from some set of possible passwords, like a dictionary, which is available to an attacker. The underlying key exchange is resistant to active attack, passive attack, and dictionary attack. This document is not an Internet Standards Track specification; it is published for informational purposes.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 5931 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 5930 Using Advanced Encryption Standard Counter Mode with the Internet Key Exchange version 02 Protocol
- RFC 5932 Camellia Cipher Suites for TLS
- RFC 5929 Channel Bindings for TLS
- RFC 5933 Use of GOST Signature Algorithms in DNSKEY and RRSIG Resource Records for DNSSEC
- RFC 5928 Traversal Using Relays around NAT Resolution Mechanism
- RFC 5934 Trust Anchor Management Protocol
- RFC 5927 ICMP Attacks against TCP
- RFC 5935 Expressing SNMP SMI Datatypes in XML Schema Definition Language