RFC 9190: EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3
In plain English — editorial summary, not part of the RFC
The Extensible Authentication Protocol (EAP), defined in RFC 3748, provides a standard mechanism for support of multiple authentication methods. This document specifies the use of EAP-TLS with TLS 1.3 while remaining backwards compatible with existing implementations of EAP-TLS. TLS 1.3 provides significantly improved security and privacy, and reduced latency when compared to earlier versions of TLS. EAP-TLS with TLS 1.3 (EAP-TLS 1.3) further improves security and privacy by always providing forward secrecy, never disclosing the peer identity, and by mandating use of revocation checking when compared to EAP-TLS with earlier versions of TLS. This document also provides guidance on authentication, authorization, and resumption for EAP-TLS in general (regardless of the underlying TLS version used). This document updates RFC 5216.
Document record
- Document ID
- RFC9190
- Published
- February 2022
- Authors
- J. Preuß Mattsson; M. Sethi
- Status
- PROPOSED STANDARD
- Stream
- IETF
- Area
- sec
- Pages
- 31
- Also known as
- —
Referenced by
One later RFC formally updates or obsoletes part of this document.
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9191Handling Large Certificates and Long Certificate Chains in TLS-Based EAP MethodsCurrent
February 2022
- RFC 9200Authentication and Authorization for Constrained Environments Using the OAuth 2.0 Framework (ACE-OAuth)Current
August 2022
- RFC 9201Additional OAuth Parameters for Authentication and Authorization for Constrained Environments (ACE)Current
August 2022
- RFC 9202Datagram Transport Layer Security (DTLS) Profile for Authentication and Authorization for Constrained Environments (ACE)Updated
August 2022
- RFC 9203The Object Security for Constrained RESTful Environments (OSCORE) Profile of the Authentication and Authorization for Constrained Environments (ACE) FrameworkCurrent
August 2022
- RFC 9207OAuth 2.0 Authorization Server Issuer IdentificationCurrent
March 2022
- RFC 9216S/MIME Example Keys and CertificatesCurrent
April 2022
- RFC 9162Certificate Transparency Version 2.0Current
December 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?