RFC 9140: Nimble Out-of-Band Authentication for EAP (EAP-NOOB)
In plain English — editorial summary, not part of the RFC
The Extensible Authentication Protocol (EAP) provides support for multiple authentication methods. This document defines the EAP-NOOB authentication method for nimble out-of-band (OOB) authentication and key derivation. The EAP method is intended for bootstrapping all kinds of Internet-of-Things (IoT) devices that have no preconfigured authentication credentials. The method makes use of a user-assisted, one-directional, out-of-band (OOB) message between the peer device and authentication server to authenticate the in-band key exchange. The device must have a nonnetwork input or output interface, such as a display, microphone, speaker, or blinking light, that can send or receive dynamically generated messages of tens of bytes in length.
Document record
- Document ID
- RFC9140
- Published
- December 2021
- Authors
- T. Aura; M. Sethi; A. Peltonen
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 51
- Also known as
- —
- Updated by:
- RFC 9965
Topics
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9244Distributed Denial-of-Service Open Threat Signaling (DOTS) TelemetryCurrent
June 2022
- RFC 9528Ephemeral Diffie-Hellman Over COSE (EDHOC)Current
March 2024
- RFC 9941Secure Shell (SSH) Key Exchange Method Using Hybrid Streamlined NTRU Prime sntrup761 and X25519 with SHA-512: sntrup761x25519-sha512Current
April 2026
- RFC 7925Transport Layer Security (TLS) / Datagram Transport Layer Security (DTLS) Profiles for the Internet of ThingsCurrent
July 2016
- RFC 5489ECDHE_PSK Cipher Suites for Transport Layer Security (TLS)Current
March 2009
- RFC 5487Pre-Shared Key Cipher Suites for TLS with SHA-256/384 and AES Galois Counter ModeUpdated
March 2009
- RFC 5296EAP Extensions for EAP Re-authentication Protocol (ERP)Obsoleted
August 2008
- RFC 5216The EAP-TLS Authentication ProtocolUpdated
March 2008
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?