Mutually Authenticating TLS in the Context of Federations
RFC 9932, “Mutually Authenticating TLS in the Context of Federations”, is an Informational document published in April 2026 by S. Halén, J. Schlyter. The canonical text is published by the RFC Editor.
Abstract
This Informational Independent Submission to the RFC Series describes a means to use TLS 1.3 to perform machine-to-machine mutual authentication within federations. This memo is not a standard. It does not modify the TLS protocol in any way, nor does it require changes to common TLS libraries. TLS is specified and standardized by the IETF's TLS Working Group.
The framework enables interoperable trust management for federated machine-to-machine communication. It introduces a centrally managed trust anchor and a controlled metadata publication process, ensuring that only authorized members are identifiable within the federation. These mechanisms support unambiguous entity identification and reduce the risk of impersonation, promoting secure and policy-aligned interaction across organizational boundaries.
What “Informational” means
Published for the general information of the community. It does not define an IETF standard and carries no standards-track status.
The canonical text of RFC 9932 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9931 Security Considerations for Optimistic Protocol Transitions in HTTP/1.1
- RFC 9930 Tunnel Extensible Authentication Protocol Version 1
- RFC 9934 Privacy-Enhanced Mail File Format for Encrypted ClientHello
- RFC 9929 IGP Unreachable Prefix Announcement
- RFC 9935 Internet X.509 Public Key Infrastructure - Algorithm Identifiers for the Module-Lattice-Based Key-Encapsulation Mechanism
- RFC 9928 DHCPv4 over DHCPv6 with Relay Agent Support
- RFC 9936 Use of ML-KEM in the Cryptographic Message Syntax
- RFC 9927 Fixing the C-Flag in the Extended Address Registration Option