ObsoletedPROPOSED STANDARDIETF stream

RFC 2069: An Extension to HTTP : Digest Access Authentication

This RFC has been replaced. Do not implement against it for new work — it was formally obsoleted by RFC 2617.

Current document in this lineage: RFC 7616HTTP Digest Access Authentication; RFC 7617The 'Basic' HTTP Authentication Scheme; RFC 9110HTTP Semantics; RFC 9111HTTP Caching; RFC 9112HTTP/1.1

In plain English — editorial summary, not part of the RFC

The protocol referred to as "HTTP/1.0" includes the specification for a Basic Access Authentication scheme. This scheme is not considered to be a secure method of user authentication, as the user name and password are passed over the network as clear text. A specification for a different authentication scheme is needed to address this severe limitation. This document provides specification for such a scheme, referred to as "Digest Access Authentication". [STANDARDS-TRACK]

Document record

Document ID
RFC2069
Published
January 1997
Authors
J. Franks; P. Hallam-Baker; J. Hostetler; P. Leach; A. Luotonen; E. Sink; L. Stewart
Status
PROPOSED STANDARD
Stream
IETF
Area
app
Pages
18
Also known as
Obsoleted by:
RFC 2617

Topics

Standards lineage

This document is one revision in a chain of 21 RFCs, each formally replacing the one before it.

  1. RFC 2068 (1997)
  2. RFC 2069 (1997)
  3. RFC 2145 (1997)
  4. RFC 2616 (1999)
  5. RFC 2617 (1999)
  6. RFC 2818 (2000)
  7. RFC 7230 (2014)
  8. RFC 7231 (2014)
  9. RFC 7232 (2014)
  10. RFC 7233 (2014)
  11. RFC 7234 (2014)
  12. RFC 7235 (2014)
  13. RFC 7238 (2014)
  14. RFC 7538 (2015)
  15. RFC 7615 (2015)
  16. RFC 7616 (2015)
  17. RFC 7617 (2015)
  18. RFC 7694 (2015)
  19. RFC 9110 (2022)
  20. RFC 9111 (2022)
  21. RFC 9112 (2022)

Read the full history of HTTP/1.1

Referenced by

One later RFC formally updates or obsoletes part of this document.

Related documents

Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.

Also filed under

About this page

The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.

Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.

Data sources · Editorial policy · Report a correction · What is an RFC?

canonical URL: /rfc/2069-an-extension-to-http-digest-access-authentication