The eap.arpa
RFC 9965, “The eap.arpa”, is a Proposed Standard document published in May 2026 by A. DeKok. It updates RFC 5216, RFC 9140, RFC 9190. The canonical text is published by the RFC Editor.
Abstract
This document defines the eap.arpa. domain for use only in Network Access Identifiers (NAIs) as a way for Extensible Authentication Protocol (EAP) peers to signal to EAP servers that they wish to obtain limited, and unauthenticated, network access. EAP peers signal which kind of access is required via certain predefined identifiers that use the NAI format of RFC 7542. A table of identifiers and meanings is defined, which includes entries for RFC 9140.
This document updates RFCs 5216 and 9190 to define an unauthenticated provisioning method. Those specifications suggest that such a method is possible, but they do not define how it would be done. This document also updates RFC 9140 to deprecate "eap-noob.arpa" and replace it with "@noob.eap.arpa".
What “Proposed Standard” means
An entry-level standards-track specification: stable, peer-reviewed and a solid basis for implementation, though it may still evolve before becoming an Internet Standard.
The canonical text of RFC 9965 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9964 ML-DSA for JSON Object Signing and Encryption and CBOR Object Signing and Encryption
- RFC 9966 Bootstrapped TLS Authentication with Proof of Knowledge
- RFC 9963 Legacy RSASSA-PKCS1-v1_5 Code Points for TLS 1.3
- RFC 9967 System for Cross-Domain Identity Management Profile for Security Event Tokens
- RFC 9962 A Decentralized Locator/ID Separation Protocol Mapping System
- RFC 9968 Report from the IAB Workshop on the Next Era of Network Management Operations
- RFC 9961 MPLS Segment Routing Point-to-Multipoint Policy Ping
- RFC 9969 Report from the IAB Workshop on AI-CONTROL