RFC 9427 · PROPOSED STANDARD · 2023

TLS-Based Extensible Authentication Protocol Types for Use with TLS 1.3

Overview

RFC 9427, “TLS-Based Extensible Authentication Protocol Types for Use with TLS 1.3”, is a Proposed Standard document published in June 2023 by A. DeKok. It updates RFC 4851, RFC 5281, RFC 7170. It has since been updated by RFC 9930. The canonical text is published by the RFC Editor.

Abstract

The Extensible Authentication Protocol-TLS (EAP-TLS) (RFC 5216) has been updated for TLS 1.3 in RFC 9190. Many other EAP Types also depend on TLS, such as EAP-Flexible Authentication via Secure Tunneling (EAP-FAST) (RFC 4851), EAP-Tunneled TLS (EAP-TTLS) (RFC 5281), the Tunnel Extensible Authentication Protocol (TEAP) (RFC 7170). It is possible that many vendor-specific EAP methods, such as the Protected Extensible Authentication Protocol (PEAP), depend on TLS as well. This document updates those methods in order to use the new key derivation methods available in TLS 1.3. Additional changes necessitated by TLS 1.3 are also discussed.

Abstract as published in the RFC, via rfc-editor.org.

What “Proposed Standard” means

An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.

Read this RFC

The canonical text of RFC 9427 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.

Relationships to other RFCs
This RFC updates
RFC 4851 RFC 5281 RFC 7170
Updated by
RFC 9930
Other RFCs from 2023

Who Is Online

In total there are 94 users online: 0 registered, 86 guests and 8 bots.

Most users ever online was 5,555 on 17 Jul 2026, 3:23 am.

Bots: Applebot Baiduspider Bingbot Googlebot Other Bot Other Crawler PetalBot SemrushBot

Users active in the past 15 minutes. Total registered members: 372