RFC 7833: A RADIUS Attribute, Binding, Profiles, Name Identifier Format, and Confirmation Methods for the Security Assertion Markup Language (SAML)
In plain English — editorial summary, not part of the RFC
This document describes the use of the Security Assertion Markup Language (SAML) with RADIUS in the context of the Application Bridging for Federated Access Beyond web (ABFAB) architecture. It defines two RADIUS attributes, a SAML binding, a SAML name identifier format, two SAML profiles, and two SAML confirmation methods. The RADIUS attributes permit encapsulation of SAML Assertions and protocol messages within RADIUS, allowing SAML entities to communicate using the binding. The two profiles describe the application of this binding for ABFAB authentication and assertion Query/Request, enabling a Relying Party to request authentication of, or assertions for, users or machines (clients). These clients may be named using a Network Access Identifier (NAI) name identifier format. Finally, the subject confirmation methods allow requests and queries to be issued for a previously authenticated user or machine without needing to explicitly identify them as the subject. The use of the artifacts defined in this document is not exclusive to ABFAB. They can be applied in any Authentication, Authorization, and Accounting (AAA) scenario, such as network access control.
Document record
- Document ID
- RFC7833
- Published
- May 2016
- Authors
- J. Howlett; S. Hartman; A. Perez-Mendez
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 32
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 7831Application Bridging for Federated Access Beyond Web (ABFAB) ArchitectureCurrent
May 2016
- RFC 7832Application Bridging for Federated Access Beyond Web (ABFAB) Use CasesCurrent
May 2016
- RFC 7593The eduroam Architecture for Network RoamingCurrent
September 2015
- RFC 7585Dynamic Peer Discovery for RADIUS/TLS and RADIUS/DTLS Based on the Network Access Identifier (NAI)Current
October 2015
- RFC 7057Update to the Extensible Authentication Protocol (EAP) Applicability Statement for Application Bridging for Federated Access Beyond Web (ABFAB)Current
December 2013
- RFC 6911RADIUS Attributes for IPv6 Access NetworksCurrent
April 2013
- RFC 6614Transport Layer Security (TLS) Encryption for RADIUSUpdated
May 2012
- RFC 8658RADIUS Attributes for Softwire Mechanisms Based on Address plus Port (A+P)Current
November 2019
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?