Third-Party Token-Based Authentication and Authorization for Session Initiation Protocol
RFC 8898, “Third-Party Token-Based Authentication and Authorization for Session Initiation Protocol”, is a Proposed Standard document published in September 2020 by R. Shekh-Yusef, C. Holmberg, V. Pascual. It updates RFC 3261. The canonical text is published by the RFC Editor.
Abstract
This document defines the "Bearer" authentication scheme for the Session Initiation Protocol (SIP) and a mechanism by which user authentication and SIP registration authorization is delegated to a third party, using the OAuth 2.0 framework and OpenID Connect Core 1.0. This document updates RFC 3261 to provide guidance on how a SIP User Agent Client (UAC) responds to a SIP 401/407 response that contains multiple WWW-Authenticate/Proxy-Authenticate header fields.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 8898 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 8897 Requirements for Resource Public Key Infrastructure Relying Parties
- RFC 8899 Packetization Layer Path MTU Discovery for Datagram Transports
- RFC 8896 Application-Layer Traffic Optimization Cost Calendar
- RFC 8900 IP Fragmentation Considered Fragile
- RFC 8895 Application-Layer Traffic Optimization Incremental Updates Using Server-Sent Events
- RFC 8901 Multi-Signer DNSSEC Models
- RFC 8894 Simple Certificate Enrolment Protocol
- RFC 8902 TLS Authentication Using Intelligent Transport System Certificates