RFC 7029: Extensible Authentication Protocol (EAP) Mutual Cryptographic Binding
In plain English — editorial summary, not part of the RFC
As the Extensible Authentication Protocol (EAP) evolves, EAP peers rely increasingly on information received from the EAP server. EAP extensions such as channel binding or network posture information are often carried in tunnel methods; peers are likely to rely on this information. Cryptographic binding is a facility described in RFC 3748 that protects tunnel methods against man-in-the-middle attacks. However, cryptographic binding focuses on protecting the server rather than the peer. This memo explores attacks possible when the peer is not protected from man-in-the-middle attacks and recommends cryptographic binding based on an Extended Master Session Key, a new form of cryptographic binding that protects both peer and server along with other mitigations.
Document record
- Document ID
- RFC7029
- Published
- October 2013
- Authors
- S. Hartman; M. Wasserman; D. Zhang
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 19
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6813The Network Endpoint Assessment (NEA) Asokan Attack AnalysisCurrent
December 2012
- RFC 6797HTTP Strict Transport Security (HSTS)Current
November 2012
- RFC 7170Tunnel Extensible Authentication Protocol (TEAP) Version 1Obsoleted
May 2014
- RFC 7636Proof Key for Code Exchange by OAuth Public ClientsCurrent
September 2015
- RFC 9458Oblivious HTTPCurrent
January 2024
- RFC 9464Internet Key Exchange Protocol Version 2 (IKEv2) Configuration for Encrypted DNSCurrent
November 2023
- RFC 3620The TUNNEL ProfileUpdated
October 2003
- RFC 6935IPv6 and UDP Checksums for Tunneled PacketsCurrent
April 2013
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?