EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3
RFC 9190, “EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3”, is a Proposed Standard document published in February 2022 by J. Preuß Mattsson, M. Sethi. It updates RFC 5216. It has since been updated by RFC 9965. The canonical text is published by the RFC Editor.
Abstract
The Extensible Authentication Protocol (EAP), defined in RFC 3748, provides a standard mechanism for support of multiple authentication methods. This document specifies the use of EAP-TLS with TLS 1.3 while remaining backwards compatible with existing implementations of EAP-TLS. TLS 1.3 provides significantly improved security and privacy, and reduced latency when compared to earlier versions of TLS. EAP-TLS with TLS 1.3 (EAP-TLS 1.3) further improves security and privacy by always providing forward secrecy, never disclosing the peer identity, and by mandating use of revocation checking when compared to EAP-TLS with earlier versions of TLS. This document also provides guidance on authentication, authorization, and resumption for EAP-TLS in general (regardless of the underlying TLS version used). This document updates RFC 5216.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9190 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9189 GOST Cipher Suites for Transport Layer Security Protocol Version 1.2
- RFC 9191 Handling Large Certificates and Long Certificate Chains in TLS-Based EAP Methods
- RFC 9188 Generic Multi-Access Encapsulation Protocol
- RFC 9192 Network Service Header Fixed-Length Context Header Allocation
- RFC 9187 Sequence Number Extension for Windowed Protocols
- RFC 9193 Sensor Measurement Lists Fields for Indicating Data Value Content-Format
- RFC 9186 Fast Failover in Protocol Independent Multicast - Sparse Mode Using Bidirectional Forwarding Detection for Multipoint Networks
- RFC 9194 A YANG Module for IS-IS Reverse Metric