Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments
RFC 9202, “Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments”, is a Proposed Standard document published in August 2022 by S. Gerdes, O. Bergmann, C. Bormann, G. Selander, L. Seitz. It has since been updated by RFC 9430. The canonical text is published by the RFC Editor.
Abstract
This specification defines a profile of the Authentication and Authorization for Constrained Environments (ACE) framework that allows constrained servers to delegate client authentication and authorization. The protocol relies on DTLS version 1.2 or later for communication security between entities in a constrained network using either raw public keys or pre-shared keys. A resource-constrained server can use this protocol to delegate management of authorization information to a trusted host with less-severe limitations regarding processing power and memory.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9202 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9201 Additional OAuth Parameters for Authentication and Authorization for Constrained Environments
- RFC 9203 The Object Security for Constrained RESTful Environments Profile of the Authentication and Authorization for Constrained Environments Framework
- RFC 9200 Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework
- RFC 9204 QPACK: Field Compression for HTTP/3
- RFC 9199 Considerations for Large Authoritative DNS Server Operators
- RFC 9205 Building Protocols with HTTP
- RFC 9198 Advanced Unidirectional Route Assessment
- RFC 9206 Commercial National Security Algorithm Suite Cryptography for Internet Protocol Security