RFC 9191: Handling Large Certificates and Long Certificate Chains in TLS-Based EAP Methods
In plain English — editorial summary, not part of the RFC
The Extensible Authentication Protocol (EAP), defined in RFC 3748, provides a standard mechanism for support of multiple authentication methods. EAP-TLS and other TLS-based EAP methods are widely deployed and used for network access authentication. Large certificates and long certificate chains combined with authenticators that drop an EAP session after only 40 - 50 round trips is a major deployment problem. This document looks at this problem in detail and describes the potential solutions available.
Document record
- Document ID
- RFC9191
- Published
- February 2022
- Authors
- M. Sethi; J. Preuß Mattsson; S. Turner
- Status
- INFORMATIONAL
- Stream
- IETF
- Area
- sec
- Pages
- 12
- Also known as
- —
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 9295Clarifications for Ed25519, Ed448, X25519, and X448 Algorithm IdentifiersCurrent
September 2022
- RFC 9048Improved Extensible Authentication Protocol Method for 3GPP Mobile Network Authentication and Key Agreement (EAP-AKA')Updated
October 2021
- RFC 9336X.509 Certificate General-Purpose Extended Key Usage (EKU) for Document SigningCurrent
December 2022
- RFC 9399Internet X.509 Public Key Infrastructure: Logotypes in X.509 CertificatesCurrent
May 2023
- RFC 8940Extensible Authentication Protocol (EAP) Session-Id Derivation for EAP Subscriber Identity Module (EAP-SIM), EAP Authentication and Key Agreement (EAP-AKA), and Protected EAP (PEAP)Current
October 2020
- RFC 8813Clarifications for Elliptic Curve Cryptography Subject Public Key InformationCurrent
August 2020
- RFC 9678Forward Secrecy Extension to the Improved Extensible Authentication Protocol Method for Authentication and Key Agreement (EAP-AKA' FS)Current
March 2025
- RFC 9734X.509 Certificate Extended Key Usage (EKU) for Instant Messaging URIsCurrent
February 2025
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?