Message Queuing Telemetry Transport and Transport Layer Security Profile of Authentication and Authorization for Constrained Environments Framework
RFC 9431, “Message Queuing Telemetry Transport and Transport Layer Security Profile of Authentication and Authorization for Constrained Environments Framework”, is a Proposed Standard document published in July 2023 by C. Sengul, A. Kirby. The canonical text is published by the RFC Editor.
Abstract
This document specifies a profile for the Authentication and Authorization for Constrained Environments (ACE) framework to enable authorization in a publish-subscribe messaging system based on Message Queuing Telemetry Transport (MQTT). Proof-of-Possession keys, bound to OAuth 2.0 access tokens, are used to authenticate and authorize MQTT Clients. The protocol relies on TLS for confidentiality and MQTT server (Broker) authentication.
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9431 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9430 Extension of the Datagram Transport Layer Security Profile for Authentication and Authorization for Constrained Environments to Transport Layer Security
- RFC 9432 DNS Catalog Zones
- RFC 9433 Segment Routing over IPv6 for the Mobile User Plane
- RFC 9428 Transmission of IPv6 Packets over Near Field Communication
- RFC 9434 Drone Remote Identification Protocol Architecture
- RFC 9427 TLS-Based Extensible Authentication Protocol Types for Use with TLS 1.3
- RFC 9435 Considerations for Assigning a New Recommended Differentiated Services Code Point
- RFC 9426 BATched Sparse Coding Scheme for Multi-hop Data Transport