TLS-Based Extensible Authentication Protocol Types for Use with TLS 1.3
RFC 9427, “TLS-Based Extensible Authentication Protocol Types for Use with TLS 1.3”, is a Proposed Standard document published in June 2023 by A. DeKok. It updates RFC 4851, RFC 5281, RFC 7170. It has since been updated by RFC 9930. The canonical text is published by the RFC Editor.
Abstract
The Extensible Authentication Protocol-TLS (EAP-TLS) (RFC 5216) has been updated for TLS 1.3 in RFC 9190. Many other EAP Types also depend on TLS, such as EAP-Flexible Authentication via Secure Tunneling (EAP-FAST) (RFC 4851), EAP-Tunneled TLS (EAP-TTLS) (RFC 5281), the Tunnel Extensible Authentication Protocol (TEAP) (RFC 7170). It is possible that many vendor-specific EAP methods, such as the Protected Extensible Authentication Protocol (PEAP), depend on TLS as well. This document updates those methods in order to use the new key derivation methods available in TLS 1.3. Additional changes necessitated by TLS 1.3 are also discussed.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9427 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9426 BATched Sparse Coding Scheme for Multi-hop Data Transport
- RFC 9428 Transmission of IPv6 Packets over Near Field Communication
- RFC 9425 JSON Meta Application Protocol for Quotas
- RFC 9424 Indicators of Compromise and Their Role in Attack Defence
- RFC 9430 Extension of the Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments to Transport Layer Security
- RFC 9431 Message Queuing Telemetry Transport and Transport Layer Security Profile of Authentication and Authorization for Constrained Environments Framework
- RFC 9432 DNS Catalog Zones
- RFC 9433 Segment Routing over IPv6 for the Mobile User Plane