Session Traversal Utilities for NAT Extension for Third-Party Authorization
RFC 7635, “Session Traversal Utilities for NAT Extension for Third-Party Authorization”, is a Proposed Standard document published in August 2015 by T. Reddy, P. Patil, R. Ravindranath, J. Uberti. The canonical text is published by the RFC Editor.
Abstract
This document proposes the use of OAuth 2.0 to obtain and validate ephemeral tokens that can be used for Session Traversal Utilities for NAT (STUN) authentication. The usage of ephemeral tokens ensures that access to a STUN server can be controlled even if the tokens are compromised.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 7635 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 7634 ChaCha20, Poly1305, and Their Use in the Internet Key Exchange Protocol and IPsec
- RFC 7636 Proof Key for Code Exchange by OAuth Public Clients
- RFC 7633 X.509v3 Transport Layer Security Feature Extension
- RFC 7637 NVGRE: Network Virtualization Using Generic Routing Encapsulation
- RFC 7632 Endpoint Security Posture Assessment: Enterprise Use Cases
- RFC 7638 JSON Web Key Thumbprint
- RFC 7631 TLV Naming in the Mobile Ad Hoc Network Generalized Packet/Message Format
- RFC 7639 The ALPN HTTP Header Field