RFC 7831: Application Bridging for Federated Access Beyond Web (ABFAB) Architecture
In plain English — editorial summary, not part of the RFC
Over the last decade, a substantial amount of work has occurred in the space of federated access management. Most of this effort has focused on two use cases: network access and web-based access. However, the solutions to these use cases that have been proposed and deployed tend to have few building blocks in common. This memo describes an architecture that makes use of extensions to the commonly used security mechanisms for both federated and non-federated access management, including the Remote Authentication Dial-In User Service (RADIUS), the Generic Security Service Application Program Interface (GSS-API), the Extensible Authentication Protocol (EAP), and the Security Assertion Markup Language (SAML). The architecture addresses the problem of federated access management to primarily non-web-based services, in a manner that will scale to large numbers of Identity Providers, Relying Parties, and federations.
Document record
- Document ID
- RFC7831
- Published
- May 2016
- Authors
- J. Howlett; S. Hartman; H. Tschofenig; J. Schaad
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 46
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7832Application Bridging for Federated Access Beyond Web (ABFAB) Use CasesCurrent
May 2016
- RFC 7833A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for the Security Assertion Markup Language (SAML)Current
May 2016
- RFC 7593The eduroam Architecture for Network RoamingCurrent
September 2015
- RFC 7585Dynamic Peer Discovery for RADIUS/TLS and RADIUS/DTLS Based on the Network Access Identifier (NAI)Current
October 2015
- RFC 7057Update to the Extensible Authentication Protocol (EAP) Applicability Statement for Application Bridging for Federated Access Beyond Web (ABFAB)Current
December 2013
- RFC 6911RADIUS Attributes for IPv6 Access NetworksCurrent
April 2013
- RFC 6614Transport Layer Security (TLS) Encryption for RADIUSUpdated
May 2012
- RFC 8658RADIUS Attributes for Softwire Mechanisms Based on Address plus Port (A+P)Current
November 2019
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?