RADIUS/1.1: Leveraging Application-Layer Protocol Negotiation to Remove MD5
RFC 9765, “RADIUS/1.1: Leveraging Application-Layer Protocol Negotiation to Remove MD5”, is an Experimental document published in April 2025 by A. DeKok. It updates RFC 2865, RFC 2866, RFC 5176, RFC 6613, RFC 6614, RFC 7360. The canonical text is published by the RFC Editor.
Abstract
This document defines Application-Layer Protocol Negotiation (ALPN) extensions for use with RADIUS/TLS and RADIUS/DTLS. These extensions permit the negotiation of an application protocol variant of RADIUS called "RADIUS/1.1". No changes are made to RADIUS/UDP or RADIUS/TCP. The extensions allow the negotiation of a transport profile where the RADIUS shared secret is no longer used, and all MD5-based packet authentication and attribute obfuscation methods are removed.
This document updates RFCs 2865, 2866, 5176, 6613, 6614, and 7360.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 9765 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9764 Bidirectional Forwarding Detection Encapsulated in Large Packets
- RFC 9766 Extensions for Weak Cache Consistency in NFSv4.2's Flexible File Layout
- RFC 9763 Related Certificates for Use in Multiple Authentications within a Protocol
- RFC 9767 Grant Negotiation and Authorization Protocol Resource Server Connections
- RFC 9762 Using Router Advertisements to Signal the Availability of DHCPv6 Prefix Delegation to Clients
- RFC 9761 Manufacturer Usage Description for TLS and DTLS Profiles for Internet of Things Devices
- RFC 9769 NTP Interleaved Modes
- RFC 9760 Enterprise Profile for the Precision Time Protocol with Mixed Multicast and Unicast Messages