Dynamic Authorization Proxying in the Remote Authentication Dial-In User Service Protocol
RFC 8559, “Dynamic Authorization Proxying in the Remote Authentication Dial-In User Service Protocol”, is a Proposed Standard document published in April 2019 by A. DeKok, J. Korhonen. It updates RFC 5176, RFC 5580. The canonical text is published by the RFC Editor.
Abstract
RFC 5176 defines Change-of-Authorization (CoA) and Disconnect Message (DM) behavior for RADIUS. RFC 5176 also suggests that proxying these messages is possible, but it does not provide guidance as to how that is done. This specification updates RFC 5176 to correct that omission for scenarios where networks use realm-based proxying as defined in RFC 7542. This specification also updates RFC 5580 to allow the Operator-Name attribute in CoA-Request and Disconnect-Request packets.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8559 is hosted at rfc-editor.org. Available in TXT,HTML.
- RFC 8558 Transport Protocol Path Signals
- RFC 8560 Seamless Integration of Ethernet VPN with Virtual Private LAN Service and Their Provider Backbone Bridge Equivalents
- RFC 8557 Deterministic Networking Problem Statement
- RFC 8561 A YANG Data Model for Microwave Radio Link
- RFC 8556 Multicast VPN Using Bit Index Explicit Replication
- RFC 8562 Bidirectional Forwarding Detection for Multipoint Networks
- RFC 8555 Automatic Certificate Management Environment
- RFC 8563 Bidirectional Forwarding Detection Multipoint Active Tails