RFC 9154 · PROPOSED STANDARD · 2021

Extensible Provisioning Protocol Secure Authorization Information for Transfer

Overview

RFC 9154, “Extensible Provisioning Protocol Secure Authorization Information for Transfer”, is a Proposed Standard document published in December 2021 by J. Gould, R. Wilhelm. The canonical text is published by the RFC Editor.

Abstract

The Extensible Provisioning Protocol (EPP) (RFC 5730) defines the use of authorization information to authorize a transfer of an EPP object, such as a domain name, between clients that are referred to as "registrars". Object-specific, password-based authorization information (see RFCs 5731 and 5733) is commonly used but raises issues related to the security, complexity, storage, and lifetime of authentication information. This document defines an operational practice, using the EPP RFCs, that leverages the use of strong random authorization information values that are short lived, not stored by the client, and stored by the server using a cryptographic hash that provides for secure authorization information that can safely be used for object transfers.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9154 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Other RFCs from 2021

Who Is Online

In total there are 63 users online: 0 registered, 58 guests and 5 bots.

Most users ever online was 1,226 on 13 Jun 2026, 3:56 am.

Bots: Applebot Googlebot Other Bot Other Spider SemrushBot

Users active in the past 15 minutes. Total registered members: 354