Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-night-mode-disabled vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-1 vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-1 vector-sticky-header-enabled" lang="en" dir="ltr"><head>
<meta charset="UTF-8">
<title>Extensible Authentication Protocol</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="canonical" href="https://en.wikipedia.org/wiki/Extensible_Authentication_Protocol"> <link href="./mw/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/skins.vector.styles.css" rel="stylesheet" type="text/css">
<link href="./mw/user.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./mw/site.styles.css">
<link rel="stylesheet" type="text/css" href="./mw/noscript.css">
<link rel="stylesheet" type="text/css" href="./footer.css">
<link rel="stylesheet" type="text/css" href="./vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Extensible_Authentication_Protocol rootpage-Extensible_Authentication_Protocol skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading">
<span id="openzim-page-title" class="mw-page-title-main"><span class="mw-page-title-main">Extensible Authentication Protocol</span></span>
</h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="en" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="en" dir="ltr">
<p><b>Extensible Authentication Protocol</b> (<b>EAP</b>) is an authentication framework frequently used in network and internet connections. It is defined in <style data-mw-deduplicate="TemplateStyles:r1238218222">
/* start https://en.wikipedia.org/ */


.mw-parser-output cite.citation{font-style:inherit;word-wrap:break-word}.mw-parser-output .citation q{quotes:"\"""\"""'""'"}.mw-parser-output .citation:target{background-color:rgba(0,127,255,0.133)}.mw-parser-output .id-lock-free.id-lock-free a{background:url("./mw/Lock-green.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-limited.id-lock-limited a,.mw-parser-output .id-lock-registration.id-lock-registration a{background:url("./mw/Lock-gray-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .id-lock-subscription.id-lock-subscription a{background:url("./mw/Lock-red-alt-2.svg")right 0.1em center/9px no-repeat}.mw-parser-output .cs1-ws-icon a{background:url("./mw/Wikisource-logo.svg")right 0.1em center/12px no-repeat}body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-free a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-limited a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-registration a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .id-lock-subscription a,body:not(.skin-timeless):not(.skin-minerva) .mw-parser-output .cs1-ws-icon a{background-size:contain;padding:0 1em 0 0}.mw-parser-output .cs1-code{color:inherit;background:inherit;border:none;padding:inherit}.mw-parser-output .cs1-hidden-error{display:none;color:var(--color-error,#d33)}.mw-parser-output .cs1-visible-error{color:var(--color-error,#d33)}.mw-parser-output .cs1-maint{display:none;color:#085;margin-left:0.3em}.mw-parser-output .cs1-kern-left{padding-left:0.2em}.mw-parser-output .cs1-kern-right{padding-right:0.2em}.mw-parser-output .citation .mw-selflink{font-weight:inherit}@media screen{.mw-parser-output .cs1-format{font-size:95%}html.skin-theme-clientpref-night .mw-parser-output .cs1-maint{color:#18911f}}@media screen and (prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .cs1-maint{color:#18911f}}


/* end https://en.wikipedia.org/ */
</style><a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc3748">3748</a>, which made <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2284">2284</a> obsolete, and is updated by <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5247">5247</a>.
EAP is an authentication framework for providing the transport and usage of material and parameters generated by EAP methods. There are many methods defined by RFCs, and a number of vendor-specific methods and new proposals exist. EAP is not a <a href="Wire_protocol" title="Wire protocol">wire protocol</a>; instead it only defines the information from the interface and the formats. Each protocol that uses EAP defines a way to encapsulate by the user EAP messages within that protocol's messages.
</p><p>EAP is in wide use. For example, in <a href="IEEE_802.11" title="IEEE 802.11">IEEE 802.11</a> (Wi-Fi) the WPA and WPA2 standards have adopted IEEE 802.1X (with various EAP types) as the canonical authentication mechanism.
</p>
<meta property="mw:PageProp/toc">
<div class="mw-heading mw-heading2"><h2 id="Methods">Methods</h2></div>
<p>EAP is an authentication framework, not a specific authentication mechanism.<sup id="cite_ref-rfc3748_sec1_1-0" class="reference"><a href="#cite_note-rfc3748_sec1-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> It provides some common functions and negotiation of authentication methods called EAP methods. There are currently about 40 different methods defined. Methods defined in <a href="IETF" class="mw-redirect" title="IETF">IETF</a> RFCs include EAP-MD5, EAP-POTP, EAP-GTC, EAP-TLS, EAP-IKEv2, EAP-SIM, EAP-AKA, and EAP-AKA'. Additionally, a number of vendor-specific methods and new proposals exist. Commonly used modern methods capable of operating in wireless networks include EAP-TLS, EAP-SIM, EAP-AKA, <a href="Lightweight_Extensible_Authentication_Protocol" title="Lightweight Extensible Authentication Protocol">LEAP</a> and EAP-TTLS. Requirements for EAP methods used in wireless LAN authentication are described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4017">4017</a>. The list of type and packets codes used in EAP is available from the IANA EAP Registry.<sup id="cite_ref-2" class="reference"><a href="#cite_note-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>
</p><p>The standard also describes the conditions under which the AAA key management requirements described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4962">4962</a> can be satisfied.
</p>
<div class="mw-heading mw-heading3"><h3 id="Lightweight_Extensible_Authentication_Protocol_(LEAP)">Lightweight Extensible Authentication Protocol (LEAP)</h3></div>
<style data-mw-deduplicate="TemplateStyles:r1236090951">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hatnote{font-style:italic}.mw-parser-output div.hatnote{padding-left:1.6em;margin-bottom:0.5em}.mw-parser-output .hatnote i{font-style:normal}.mw-parser-output .hatnote+link+.hatnote{margin-top:-0.5em}@media print{body.ns-0 .mw-parser-output .hatnote{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Lightweight_Extensible_Authentication_Protocol" title="Lightweight Extensible Authentication Protocol">Lightweight Extensible Authentication Protocol</a></div>
<p>The <a href="Lightweight_Extensible_Authentication_Protocol" title="Lightweight Extensible Authentication Protocol">Lightweight Extensible Authentication Protocol</a> (LEAP) method was developed by <a href="Cisco_Systems" class="mw-redirect" title="Cisco Systems">Cisco Systems</a> prior to the <a href="IEEE" class="mw-redirect" title="IEEE">IEEE</a> ratification of the <a href="802.11i" class="mw-redirect" title="802.11i">802.11i</a> security standard.<sup id="cite_ref-3" class="reference"><a href="#cite_note-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup> Cisco distributed the protocol through the CCX (Cisco Certified Extensions) as part of getting 802.1X and dynamic <a href="Wired_Equivalent_Privacy" title="Wired Equivalent Privacy">WEP</a> adoption into the industry in the absence of a standard. There is no native support for LEAP in any <a href="Windows_operating_system" class="mw-redirect" title="Windows operating system">Windows operating system</a>, but it is widely supported by third-party client software most commonly included with WLAN (wireless LAN) devices. <a href="Lightweight_Extensible_Authentication_Protocol" title="Lightweight Extensible Authentication Protocol">LEAP</a> support for Microsoft Windows 7 and Microsoft Windows Vista can be added by downloading a client add in from Cisco that provides support for both LEAP and EAP-FAST. Due to the wide adoption of LEAP in the networking industry many other WLAN vendors claim support for LEAP.
</p><p>LEAP uses a modified version of <a href="MS-CHAP" title="MS-CHAP">MS-CHAP</a>, an <a href="Authentication" title="Authentication">authentication</a> protocol in which user credentials are not strongly protected and easily compromised; an exploit tool called ASLEAP was released in early 2004 by Joshua Wright.<sup id="cite_ref-4" class="reference"><a href="#cite_note-4"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> Cisco recommends that customers who absolutely must use LEAP do so only with sufficiently complex passwords, though complex passwords are difficult to administer and enforce. Cisco's current recommendation is to use newer and stronger EAP protocols such as EAP-FAST, <a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">PEAP</a>, or EAP-TLS.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Transport_Layer_Security_(EAP-TLS)">EAP Transport Layer Security (EAP-TLS)</h3></div>
<p>EAP Transport Layer Security (EAP-TLS), defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5216">5216</a>, is an IETF <a href="Open_standard" title="Open standard">open standard</a> that uses the <a href="Transport_Layer_Security" title="Transport Layer Security">Transport Layer Security</a> (TLS) protocol, and is well-supported among wireless vendors. EAP-TLS is the original, standard wireless LAN EAP authentication protocol.
</p><p>EAP-TLS is still considered one of the most secure EAP standards available, although TLS provides strong security only as long as the user understands potential warnings about false credentials, and is universally supported by all manufacturers of wireless LAN hardware and software. Until April 2005, EAP-TLS was the only EAP type vendors needed to certify for a WPA or WPA2 logo.<sup id="cite_ref-5" class="reference"><a href="#cite_note-5"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> There are client and server implementations of EAP-TLS in 3Com, Apple, <a href="Avaya" title="Avaya">Avaya</a>, Brocade Communications, Cisco, Enterasys Networks, Fortinet, Foundry, Hirschmann, HP, Juniper, Microsoft, and open source operating systems. EAP-<span lang="Vi" dir="ltr">TLS</span> is natively supported in Mac OS X 10.3 and above, <a href="Wpa_supplicant" title="Wpa supplicant">wpa_supplicant</a>, Windows 2000 SP4, Windows XP and above, Windows Mobile 2003 and above, Windows CE 4.2, and Apple's iOS mobile operating system.
</p><p>Unlike most TLS implementations of <a href="HTTPS" title="HTTPS">HTTPS</a>, such as on the <a href="World_Wide_Web" title="World Wide Web">World Wide Web</a>, the majority of implementations of EAP-TLS require mutual authentication using client-side <a href="X.509" title="X.509">X.509</a> certificates without giving the option to disable the requirement, even though the standard does not mandate their use.<sup id="cite_ref-opensecurewireless_6-0" class="reference"><a href="#cite_note-opensecurewireless-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-rfc5216s211_7-0" class="reference"><a href="#cite_note-rfc5216s211-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> Some have identified this as having the potential to dramatically reduce adoption of EAP-TLS and prevent "open" but encrypted access points.<sup id="cite_ref-opensecurewireless_6-1" class="reference"><a href="#cite_note-opensecurewireless-6"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-rfc5216s211_7-1" class="reference"><a href="#cite_note-rfc5216s211-7"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup> On 22 August 2012 <a href="Hostapd" title="Hostapd">hostapd</a> (and wpa_supplicant) added support in its <a href="Git_(software)" class="mw-redirect" title="Git (software)">Git</a> repository for an UNAUTH-TLS vendor-specific EAP type (using the hostapd/wpa_supplicant project <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5612">5612</a> Private Enterprise Number),<sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup> and on 25 February 2014 added support for the WFA-UNAUTH-TLS vendor-specific EAP type (using the <a href="Wi-Fi_Alliance" title="Wi-Fi Alliance">Wi-Fi Alliance</a> Private Enterprise Number),<sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-10" class="reference"><a href="#cite_note-10"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup> which only do server authentication. This would allow for situations much like HTTPS, where a wireless hotspot allows free access and does not authenticate station clients but station clients wish to use encryption (<a href="IEEE_802.11i-2004" title="IEEE 802.11i-2004">IEEE 802.11i-2004</a> i.e. <a href="WPA2" class="mw-redirect" title="WPA2">WPA2</a>) and potentially authenticate the wireless hotspot. There have also been proposals to use <a href="IEEE_802.11u" title="IEEE 802.11u">IEEE 802.11u</a> for access points to signal that they allow EAP-TLS using only server-side authentication, using the standard EAP-TLS IETF type instead of a vendor-specific EAP type.<sup id="cite_ref-11" class="reference"><a href="#cite_note-11"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>
</p><p>The requirement for a client-side certificate, however unpopular it may be, is what gives EAP-TLS its authentication strength and illustrates the classic convenience vs. security trade-off. With a client-side certificate, a compromised password is not enough to break into EAP-TLS enabled systems because the intruder still needs to have the client-side certificate; indeed, a password is not even needed, as it is only used to encrypt the client-side certificate for storage. The highest security available is when the "private keys" of client-side certificate are housed in <a href="Smart_card" title="Smart card">smart cards</a>.<sup id="cite_ref-12" class="reference"><a href="#cite_note-12"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup> This is because there is no way to steal a client-side certificate's corresponding private key from a smart card without stealing the card itself. It is more likely that the physical theft of a smart card would be noticed (and the smart card immediately revoked) than a (typical) password theft would be noticed. In addition, the private key on a smart card is typically encrypted using a PIN that only the owner of the smart card knows, minimizing its utility for a thief even before the card has been reported stolen and revoked.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP-MD5">EAP-MD5</h3></div>
<p>EAP-MD5 was the only IETF Standards Track based EAP method when it was first defined in the original RFC for EAP, <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2284">2284</a>. It offers minimal security; the <a href="MD5" title="MD5">MD5</a> <a href="Hash_function" title="Hash function">hash function</a> is vulnerable to <a href="Dictionary_attack" title="Dictionary attack">dictionary attacks</a>, and does not support key generation, which makes it unsuitable for use with dynamic WEP, or WPA/WPA2 enterprise. EAP-MD5 differs from other EAP methods in that it only provides authentication of the EAP peer to the EAP server but not mutual authentication. By not providing EAP server authentication, this EAP method is vulnerable to man-in-the-middle attacks.<sup id="cite_ref-13" class="reference"><a href="#cite_note-13"><span class="cite-bracket">[</span>13<span class="cite-bracket">]</span></a></sup> EAP-MD5 support was first included in <a href="Windows_2000" title="Windows 2000">Windows 2000</a> and deprecated in <a href="Windows_Vista" title="Windows Vista">Windows Vista</a>.<sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>14<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Protected_One-Time_Password_(EAP-POTP)">EAP Protected One-Time Password (EAP-POTP)</h3></div>
<p>EAP Protected One-Time Password (EAP-POTP), which is described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4793">4793</a>, is an EAP method developed by RSA Laboratories that uses one-time password (OTP) tokens, such as a handheld hardware device or a hardware or software module running on a personal computer, to generate authentication keys. EAP-POTP can be used to provide unilateral or mutual authentication and key material in protocols that use EAP.
</p><p>The EAP-POTP method provides two-factor user authentication, meaning that a user needs both physical access to a token and knowledge of a <a href="Personal_identification_number" title="Personal identification number">personal identification number</a> (PIN) to perform authentication.<sup id="cite_ref-15" class="reference"><a href="#cite_note-15"><span class="cite-bracket">[</span>15<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Pre-Shared_Key_(EAP-PSK)">EAP Pre-Shared Key (EAP-PSK)</h3></div>
<p><sup id="cite_ref-rfc3748_sec1_1-1" class="reference"><a href="#cite_note-rfc3748_sec1-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup> EAP Pre-shared key (EAP-PSK), defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4764">4764</a>, is an EAP method for mutual authentication and session key derivation using a <a href="Pre-shared_key" title="Pre-shared key">pre-shared key</a> (PSK). It provides a protected communication channel, when mutual authentication is successful, for both parties to communicate and is designed for authentication over insecure networks such as IEEE 802.11.
</p><p>EAP-PSK is documented in an experimental RFC that provides a lightweight and extensible EAP method that does not require any public-key cryptography. The EAP method protocol exchange is done in a minimum of four messages.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Password_(EAP-PWD)">EAP Password (EAP-PWD)</h3></div>
<p>EAP Password (EAP-PWD), defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5931">5931</a>, is an EAP method which uses a shared password for authentication. The password may be a low-entropy one and may be drawn from some set of possible passwords, like a dictionary, which is available to an attacker. The underlying key exchange is resistant to active attack, passive attack, and dictionary attack.
</p><p>EAP-PWD is in the base of Android 4.0 (ICS). It is in FreeRADIUS<sup id="cite_ref-16" class="reference"><a href="#cite_note-16"><span class="cite-bracket">[</span>16<span class="cite-bracket">]</span></a></sup> and Radiator<sup id="cite_ref-17" class="reference"><a href="#cite_note-17"><span class="cite-bracket">[</span>17<span class="cite-bracket">]</span></a></sup> RADIUS servers, and it is in hostapd and wpa_supplicant.<sup id="cite_ref-18" class="reference"><a href="#cite_note-18"><span class="cite-bracket">[</span>18<span class="cite-bracket">]</span></a></sup>
</p><p>
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Tunneled_Transport_Layer_Security_(EAP-TTLS)">EAP Tunneled Transport Layer Security (EAP-TTLS)</h3></div>
<div role="note" class="hatnote navigation-not-searchable">"TTLS" redirects here. For the children's song, see <a href="Twinkle%2C_Twinkle%2C_Little_Star" title="Twinkle, Twinkle, Little Star">Twinkle, Twinkle, Little Star</a>.</div>
<p>EAP Tunneled Transport Layer Security (EAP-TTLS) is an EAP protocol that extends <a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a>. It was co-developed by <a href="Funk_Software" title="Funk Software">Funk Software</a> and <a href="Certicom" class="mw-redirect" title="Certicom">Certicom</a> and is widely supported across platforms. Microsoft did not incorporate native support for the EAP-TTLS protocol in <a href="Windows_XP" title="Windows XP">Windows XP</a>, <a href="Windows_Vista" title="Windows Vista">Vista</a>, or <a href="Windows_7" title="Windows 7">7</a>. Supporting TTLS on these platforms requires third-party Encryption Control Protocol (ECP) certified software. <a href="Microsoft_Windows" title="Microsoft Windows">Microsoft Windows</a> started EAP-TTLS support with <a href="Windows_8" title="Windows 8">Windows 8</a>,<sup id="cite_ref-19" class="reference"><a href="#cite_note-19"><span class="cite-bracket">[</span>19<span class="cite-bracket">]</span></a></sup> support for EAP-TTLS<sup id="cite_ref-20" class="reference"><a href="#cite_note-20"><span class="cite-bracket">[</span>20<span class="cite-bracket">]</span></a></sup> appeared in Windows Phone <a href="Windows_Phone_8.1" title="Windows Phone 8.1">version 8.1</a>.<sup id="cite_ref-21" class="reference"><a href="#cite_note-21"><span class="cite-bracket">[</span>21<span class="cite-bracket">]</span></a></sup>
</p><p>The client can, but does not have to be authenticated via a <a href="Certificate_authority" title="Certificate authority">CA</a>-signed <a href="Public_key_infrastructure" title="Public key infrastructure">PKI</a> certificate to the server. This greatly simplifies the setup procedure since a certificate is not needed on every client.
</p><p>After the server is securely authenticated to the client via its CA certificate and optionally the client to the server, the server can then use the established secure connection ("tunnel") to authenticate the client. It can use an existing and widely deployed authentication protocol and infrastructure, incorporating legacy password mechanisms and authentication databases, while the secure tunnel provides protection from <a href="Eavesdropping" title="Eavesdropping">eavesdropping</a> and <a href="Man-in-the-middle_attack" title="Man-in-the-middle attack">man-in-the-middle attack</a>. Note that the user's name is never transmitted in unencrypted clear text, improving privacy.
</p><p>Two distinct versions of EAP-TTLS exist: original EAP-TTLS (a.k.a. EAP-TTLSv0) and EAP-TTLSv1. EAP-TTLSv0 is described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5281">5281</a>, EAP-TTLSv1 is available as an Internet draft.<sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>22<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Internet_Key_Exchange_v._2_(EAP-IKEv2)">EAP Internet Key Exchange v. 2 (EAP-IKEv2)</h3></div>
<p>EAP Internet Key Exchange v. 2 (EAP-IKEv2) is an EAP method based on the <a href="Internet_Key_Exchange" title="Internet Key Exchange">Internet Key Exchange</a> protocol version 2 (IKEv2). It provides mutual authentication and session key establishment between an EAP peer and an EAP server. It supports authentication techniques that are based on the following types of credentials:
</p>
<dl><dt>Asymmetric key pairs</dt>
<dd>Public/private key pairs where the public key is embedded into a <a href="Digital_certificate" class="mw-redirect" title="Digital certificate">digital certificate</a>, and the corresponding <a href="Private_key" class="mw-redirect" title="Private key">private key</a> is known only to a single party.</dd>
<dt>Passwords</dt>
<dd>Low-<a href="Information_entropy" class="mw-redirect" title="Information entropy">entropy</a> bit strings that are known to both the server and the peer.</dd>
<dt>Symmetric keys</dt>
<dd>High-entropy bit strings that are known to both the server and the peer.</dd></dl>
<p>It is possible to use a different authentication <a href="Credential" title="Credential">credential</a> (and thereby technique) in each direction. For example, the EAP server authenticates itself using public/private key pair and the EAP peer using symmetric key. However, not all of the nine theoretical combinations are expected in practice. Specifically, the standard <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5106">5106</a> lists four use cases: The server authenticating with an asymmetric key pair while the client uses any of the three methods; and that both sides use a symmetric key.
</p><p>EAP-IKEv2 is described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5106">5106</a>, and a <a rel="nofollow" class="external text" href="http://eap-ikev2.sourceforge.net">prototype implementation</a> exists.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Flexible_Authentication_via_Secure_Tunneling_(EAP-FAST)">EAP Flexible Authentication via Secure Tunneling (EAP-FAST)</h3></div>
<p>Flexible Authentication via Secure Tunneling (EAP-FAST; <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4851">4851</a>) is a protocol proposal by <a href="Cisco_Systems" class="mw-redirect" title="Cisco Systems">Cisco Systems</a> as a replacement for <a href="Lightweight_Extensible_Authentication_Protocol" title="Lightweight Extensible Authentication Protocol">LEAP</a>.<sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>23<span class="cite-bracket">]</span></a></sup> The protocol was designed to address the weaknesses of LEAP while preserving the "lightweight" implementation. Use of server certificates is optional in EAP-FAST. EAP-FAST uses a Protected Access Credential (PAC) to establish a TLS tunnel in which client credentials are verified.
</p><p>EAP-FAST has three phases:<sup id="cite_ref-24" class="reference"><a href="#cite_note-24"><span class="cite-bracket">[</span>24<span class="cite-bracket">]</span></a></sup>
</p>
<table class="wikitable">

<tbody><tr>
<th>Phase</th>
<th>Function</th>
<th>Description</th>
<th>Purpose
</th></tr>
<tr>
<td>0</td>
<td>In-band provisioning—provide the peer with a shared secret to be used in secure phase 1 conversation</td>
<td>Uses Authenticated Diffie-Hellman Protocol (ADHP). This phase is independent of other phases; hence, any other scheme (in-band or out-of-band) can be used in the future.</td>
<td>Eliminate the requirement in the client to establish a master secret every time a client requires network access
</td></tr>
<tr>
<td>1</td>
<td>Tunnel establishment</td>
<td>Authenticates using the PAC and establishes a tunnel key</td>
<td>Key establishment to provide confidentiality and integrity during the authentication process in phase 2
</td></tr>
<tr>
<td>2</td>
<td>Authentication</td>
<td>Authenticates the peer</td>
<td>Multiple tunneled, secure authentication mechanisms (credentials exchanged)
</td></tr></tbody></table>
<p>When automatic PAC provisioning is enabled, EAP-FAST has a vulnerability where an attacker can intercept the PAC and use that to compromise user credentials. This vulnerability is mitigated by manual PAC provisioning or by using server certificates for the PAC provisioning phase.
</p><p>It is worth noting that the PAC file is issued on a per-user basis. This is a requirement in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4851">4851</a> sec 7.4.4 so if a new user logs on the network from a device, a new PAC file must be provisioned first. This is one reason why it is difficult not to run EAP-FAST in insecure anonymous provisioning mode. The alternative is to use device passwords instead, but then the device is validated on the network not the user.
</p><p>EAP-FAST can be used without PAC files, falling back to normal TLS.
</p><p>EAP-FAST is natively supported in Apple OS X 10.4.8 and newer. <a href="Cisco" title="Cisco">Cisco</a> supplies an EAP-FAST module<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>25<span class="cite-bracket">]</span></a></sup> for <a href="Windows_Vista" title="Windows Vista">Windows Vista</a><sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>26<span class="cite-bracket">]</span></a></sup> and later operating systems which have an extensible EAPHost architecture for new authentication methods and supplicants.<sup id="cite_ref-27" class="reference"><a href="#cite_note-27"><span class="cite-bracket">[</span>27<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="Tunnel_Extensible_Authentication_Protocol_(TEAP)">Tunnel Extensible Authentication Protocol (TEAP)</h3></div>
<p>Tunnel Extensible Authentication Protocol (TEAP; <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc7170">7170</a>) is a tunnel-based EAP method that enables secure communication between a peer and a server by using the Transport Layer Security (TLS) protocol to establish a mutually authenticated tunnel. Within the tunnel, TLV (Type-Length-Value) objects are used to convey authentication-related data between the EAP peer and the EAP server.
</p><p>In addition to peer authentication, TEAP allows the peer to ask the server for a certificate by sending a request in <a href="Certificate_signing_request" title="Certificate signing request">PKCS#10</a> format. After receiving the certificate request and authenticating the peer, the server can provision a certificate to the peer in PKCS#7 format (<a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2325">2325</a>). The server can also distribute trusted root certificates to the peer in PKCS#7 format (<a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2325">2325</a>). Both operations are enclosed into the corresponding TLVs and happen securely within the already established TLS tunnel.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Subscriber_Identity_Module_(EAP-SIM)">EAP Subscriber Identity Module (EAP-SIM)</h3></div>
<p>EAP <a href="Subscriber_Identity_Module" class="mw-redirect" title="Subscriber Identity Module">Subscriber Identity Module</a> (EAP-SIM) is used for authentication and session key distribution using the subscriber identity module (SIM) from the Global System for Mobile Communications (<a href="GSM" title="GSM">GSM</a>).
</p><p>GSM cellular networks use a subscriber identity module card to carry out user authentication. EAP-SIM use a SIM authentication algorithm between the client and an <a href="AAA_protocol" class="mw-redirect" title="AAA protocol">Authentication, Authorization and Accounting (AAA)</a> server providing mutual authentication between the client and the network.
</p><p>In EAP-SIM the communication between the SIM card and the Authentication Centre (AuC) replaces the need for a pre-established password between the client and the AAA server.
</p><p>The A3/A8 algorithms are being run a few times, with different 128 bit challenges, so there will be more 64 bit Kc-s which will be combined/mixed to create stronger keys (Kc-s won't be used directly). The lack of mutual authentication in GSM has also been overcome.
</p><p>EAP-SIM is described in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4186">4186</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Authentication_and_Key_Agreement_(EAP-AKA)">EAP Authentication and Key Agreement (EAP-AKA)</h3></div>
<p>Extensible Authentication Protocol Method for <a href="Universal_Mobile_Telecommunications_System" class="mw-redirect" title="Universal Mobile Telecommunications System">Universal Mobile Telecommunications System</a> (UMTS) Authentication and Key Agreement (EAP-AKA), is an EAP mechanism for authentication and session key distribution using the UMTS Subscriber Identity Module (<a href="Universal_Subscriber_Identity_Module" class="mw-redirect" title="Universal Subscriber Identity Module">USIM</a>). EAP-AKA is defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc4187">4187</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Authentication_and_Key_Agreement_prime_(EAP-AKA')">EAP Authentication and Key Agreement <a href="Prime_(symbol)#Use_in_mathematics,_statistics,_and_science" title="Prime (symbol)">prime</a> (EAP-AKA')</h3></div>
<p>The EAP-AKA' variant of EAP-AKA, defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5448">5448</a>, and is used for non-3GPP access to a <a href="3GPP" title="3GPP">3GPP</a> core network. For example, via <a href="Evolution-Data_Optimized" title="Evolution-Data Optimized">EVDO</a>, <a href="WiFi" class="mw-redirect" title="WiFi">WiFi</a>, or <a href="WiMax" class="mw-redirect" title="WiMax">WiMax</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Generic_Token_Card_(EAP-GTC)">EAP Generic Token Card (EAP-GTC)</h3></div>
<p>EAP Generic Token Card, or EAP-GTC, is an EAP method created by Cisco as an alternative to PEAPv0/EAP-MSCHAPv2 and defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2284">2284</a> and <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc3748">3748</a>. EAP-GTC carries a text challenge from the authentication server, and a reply generated by a <a href="Security_token" title="Security token">security token</a>. The PEAP-GTC authentication mechanism allows generic authentication to a number of databases such as <a href="Novell_Directory_Service" class="mw-redirect" title="Novell Directory Service">Novell Directory Service</a> (NDS) and <a href="Lightweight_Directory_Access_Protocol" title="Lightweight Directory Access Protocol">Lightweight Directory Access Protocol</a> (LDAP), as well as the use of a <a href="One-time_password" title="One-time password">one-time password</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="EAP_Encrypted_Key_Exchange_(EAP-EKE)">EAP Encrypted Key Exchange (EAP-EKE)</h3></div>
<p>EAP with the <a href="Encrypted_key_exchange" title="Encrypted key exchange">encrypted key exchange</a>, or EAP-EKE, is one of the few EAP methods that provide secure mutual authentication using short passwords and no need for <a href="Public_key_certificate" title="Public key certificate">public key certificates</a>. It is a three-round exchange, based on the <a href="Diffie%E2%80%93Hellman_key_exchange" title="Diffie–Hellman key exchange">Diffie-Hellman</a> variant of the well-known EKE protocol.
</p><p>EAP-EKE is specified in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc6124">6124</a>.
</p>
<div class="mw-heading mw-heading3"><h3 id="Nimble_out-of-band_authentication_for_EAP_(EAP-NOOB)">Nimble out-of-band authentication for EAP (EAP-NOOB)</h3></div>
<p>Nimble out-of-band authentication for EAP<sup id="cite_ref-28" class="reference"><a href="#cite_note-28"><span class="cite-bracket">[</span>28<span class="cite-bracket">]</span></a></sup> (EAP-NOOB) is a generic bootstrapping solution for devices which have no pre-configured authentication credentials and which are not yet registered on any server. It is especially useful for Internet-of-Things (IoT) gadgets and toys that come with no information about any owner, network or server. Authentication for this EAP method is based on a user-assisted out-of-band (OOB) channel between the server and peer. EAP-NOOB supports many types of OOB channels such as QR codes, NFC tags, audio etc. and unlike other EAP methods, the protocol security has been verified by formal modeling of the specification with <a href="ProVerif" title="ProVerif">ProVerif</a> and <a href="MCRL2" title="MCRL2">MCRL2</a> tools.<sup id="cite_ref-29" class="reference"><a href="#cite_note-29"><span class="cite-bracket">[</span>29<span class="cite-bracket">]</span></a></sup>
</p><p>EAP-NOOB performs an Ephemeral Elliptic Curve Diffie-Hellman (ECDHE) over the in-band EAP channel. The user then confirms this exchange by transferring the OOB message. Users can transfer the OOB message from the peer to the server, when for example, the device is a smart TV that can show a QR code. Alternatively, users can transfer the OOB message from the server to the peer, when for example, the device being bootstrapped is a camera that can only read a QR code.
</p>
<div class="mw-heading mw-heading2"><h2 id="Encapsulation">Encapsulation</h2></div>
<p>EAP is not a wire protocol; instead it only defines message formats. Each protocol that uses EAP defines a way to <a href="Encapsulation_(networking)" title="Encapsulation (networking)">encapsulate</a> EAP messages within that protocol's messages.<sup id="cite_ref-30" class="reference"><a href="#cite_note-30"><span class="cite-bracket">[</span>30<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-31" class="reference"><a href="#cite_note-31"><span class="cite-bracket">[</span>31<span class="cite-bracket">]</span></a></sup>
</p>
<div class="mw-heading mw-heading3"><h3 id="IEEE_802.1X">IEEE 802.1X</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="IEEE_802.1X" title="IEEE 802.1X">IEEE 802.1X</a></div>
<p>The encapsulation of EAP over <a href="IEEE_802" title="IEEE 802">IEEE 802</a> is defined in <a href="IEEE_802.1X" title="IEEE 802.1X">IEEE 802.1X</a> and known as "EAP over LANs" or EAPOL.<sup id="cite_ref-32" class="reference"><a href="#cite_note-32"><span class="cite-bracket">[</span>32<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-33" class="reference"><a href="#cite_note-33"><span class="cite-bracket">[</span>33<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-34" class="reference"><a href="#cite_note-34"><span class="cite-bracket">[</span>34<span class="cite-bracket">]</span></a></sup> EAPOL was originally designed for <a href="IEEE_802.3" title="IEEE 802.3">IEEE 802.3</a> Ethernet in 802.1X-2001, but was clarified to suit other IEEE 802 LAN technologies such as <a href="IEEE_802.11" title="IEEE 802.11">IEEE 802.11</a> wireless and <a href="Fiber_Distributed_Data_Interface" title="Fiber Distributed Data Interface">Fiber Distributed Data Interface</a> (ANSI X3T9.5/X3T12, adopted as ISO 9314) in 802.1X-2004.<sup id="cite_ref-35" class="reference"><a href="#cite_note-35"><span class="cite-bracket">[</span>35<span class="cite-bracket">]</span></a></sup> The EAPOL protocol was also modified for use with <a href="IEEE_802.1AE" title="IEEE 802.1AE">IEEE 802.1AE</a> (MACsec) and <a href="IEEE_802.1#802.1AR" title="IEEE 802.1">IEEE 802.1AR</a> (Initial Device Identity, IDevID) in 802.1X-2010.<sup id="cite_ref-36" class="reference"><a href="#cite_note-36"><span class="cite-bracket">[</span>36<span class="cite-bracket">]</span></a></sup>
</p><p>When EAP is invoked by an 802.1X enabled <a href="Network_Access_Server" class="mw-redirect" title="Network Access Server">Network Access Server</a> (NAS) device such as an <a href="IEEE_802.11i-2004" title="IEEE 802.11i-2004">IEEE 802.11i-2004</a> Wireless Access Point (WAP), modern EAP methods can provide a secure authentication mechanism and negotiate a secure private key (Pair-wise Master Key, PMK) between the client and NAS which can then be used for a wireless encryption session utilizing <a href="Temporal_Key_Integrity_Protocol" title="Temporal Key Integrity Protocol">TKIP</a> or <a href="CCMP_(cryptography)" title="CCMP (cryptography)">CCMP</a> (based on <a href="Advanced_Encryption_Standard" title="Advanced Encryption Standard">AES</a>) encryption.
</p>
<div class="mw-heading mw-heading3"><h3 id="PEAP">PEAP</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">Protected Extensible Authentication Protocol</a></div>
<p>The <a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">Protected Extensible Authentication Protocol</a>, also known as Protected EAP or simply PEAP, is a protocol that encapsulates EAP within a potentially encrypted and authenticated <a href="Transport_Layer_Security" title="Transport Layer Security">Transport Layer Security</a> (TLS) <a href="Tunneling_protocol" title="Tunneling protocol">tunnel</a>.<sup id="cite_ref-37" class="reference"><a href="#cite_note-37"><span class="cite-bracket">[</span>37<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-peapv2-10_abstract_38-0" class="reference"><a href="#cite_note-peapv2-10_abstract-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-39" class="reference"><a href="#cite_note-39"><span class="cite-bracket">[</span>39<span class="cite-bracket">]</span></a></sup> The purpose was to correct deficiencies in EAP; EAP assumed a protected communication channel, such as that provided by physical security, so facilities for protection of the EAP conversation were not provided.<sup id="cite_ref-40" class="reference"><a href="#cite_note-40"><span class="cite-bracket">[</span>40<span class="cite-bracket">]</span></a></sup>
</p><p>PEAP was jointly developed by Cisco Systems, Microsoft, and RSA Security. PEAPv0 was the version included with <a href="Microsoft" title="Microsoft">Microsoft</a> <a href="Windows_XP" title="Windows XP">Windows XP</a> and was nominally defined in <a rel="nofollow" class="external text" href="http://tools.ietf.org/html/draft-kamath-pppext-peapv0-00">draft-kamath-pppext-peapv0-00</a>. PEAPv1 and PEAPv2 were defined in different versions of <i>draft-josefsson-pppext-eap-tls-eap</i>. PEAPv1 was defined in <a rel="nofollow" class="external text" href="http://tools.ietf.org/html/draft-josefsson-pppext-eap-tls-eap-00">draft-josefsson-pppext-eap-tls-eap-00</a> through <a rel="nofollow" class="external text" href="http://tools.ietf.org/html/draft-josefsson-pppext-eap-tls-eap-05">draft-josefsson-pppext-eap-tls-eap-05</a>,<sup id="cite_ref-41" class="reference"><a href="#cite_note-41"><span class="cite-bracket">[</span>41<span class="cite-bracket">]</span></a></sup> and PEAPv2 was defined in versions beginning with <a rel="nofollow" class="external text" href="http://tools.ietf.org/html/draft-josefsson-pppext-eap-tls-eap-06">draft-josefsson-pppext-eap-tls-eap-06</a>.<sup id="cite_ref-42" class="reference"><a href="#cite_note-42"><span class="cite-bracket">[</span>42<span class="cite-bracket">]</span></a></sup>
</p><p>The protocol only specifies chaining multiple EAP mechanisms and not any specific method.<sup id="cite_ref-peapv2-10_abstract_38-1" class="reference"><a href="#cite_note-peapv2-10_abstract-38"><span class="cite-bracket">[</span>38<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-43" class="reference"><a href="#cite_note-43"><span class="cite-bracket">[</span>43<span class="cite-bracket">]</span></a></sup> Use of the <a href="EAP-MSCHAPv2" class="mw-redirect" title="EAP-MSCHAPv2">EAP-MSCHAPv2</a> and <a href="EAP-GTC" class="mw-redirect" title="EAP-GTC">EAP-GTC</a> methods are the most commonly supported.
</p>
<div class="mw-heading mw-heading3"><h3 id="RADIUS_and_Diameter">RADIUS and Diameter</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main articles: <a href="RADIUS" title="RADIUS">RADIUS</a> and <a href="Diameter_(protocol)" title="Diameter (protocol)">Diameter (protocol)</a></div>
<p>Both the <a href="RADIUS" title="RADIUS">RADIUS</a> and <a href="Diameter_(protocol)" title="Diameter (protocol)">Diameter</a> <a href="AAA_protocol" class="mw-redirect" title="AAA protocol">AAA protocols</a> can encapsulate EAP messages. They are often used by <a href="Network_Access_Server" class="mw-redirect" title="Network Access Server">Network Access Server</a> (NAS) devices to forward EAP packets between IEEE 802.1X endpoints and AAA servers to facilitate IEEE 802.1X.
</p>
<div class="mw-heading mw-heading3"><h3 id="PANA">PANA</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Protocol_for_Carrying_Authentication_for_Network_Access" title="Protocol for Carrying Authentication for Network Access">Protocol for Carrying Authentication for Network Access</a></div>
<p>The <a href="Protocol_for_Carrying_Authentication_for_Network_Access" title="Protocol for Carrying Authentication for Network Access">Protocol for Carrying Authentication for Network Access</a> (PANA) is an IP-based protocol that allows a device to authenticate itself with a network to be granted access. PANA will not define any new authentication protocol, key distribution, key agreement or key derivation protocols; for these purposes, EAP will be used, and PANA will carry the EAP payload. PANA allows dynamic service provider selection, supports various authentication methods, is suitable for roaming users, and is independent from the link layer mechanisms.
</p>
<div class="mw-heading mw-heading3"><h3 id="PPP">PPP</h3></div>
<div role="note" class="hatnote navigation-not-searchable">Main article: <a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">Point-to-Point Protocol</a></div>
<p>EAP was originally an authentication extension for the <a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">Point-to-Point Protocol</a> (PPP). PPP has supported EAP since EAP was created as an alternative to the <a href="Challenge-Handshake_Authentication_Protocol" title="Challenge-Handshake Authentication Protocol">Challenge-Handshake Authentication Protocol</a> (CHAP) and the <a href="Password_Authentication_Protocol" title="Password Authentication Protocol">Password Authentication Protocol</a> (PAP), which were eventually incorporated into EAP. The EAP extension to PPP was first defined in <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc2284">2284</a>, now obsoleted by <a href="RFC_(identifier)" class="mw-redirect" title="RFC (identifier)">RFC</a>&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc3748">3748</a>.
</p>
<div class="mw-heading mw-heading2"><h2 id="See_also">See also</h2></div>
<ul><li><a href="Authentication_protocol" title="Authentication protocol">Authentication protocol</a></li>
<li><a href="Handover_keying" title="Handover keying">Handover keying</a></li>
<li><a href="ITU-T" title="ITU-T">ITU-T</a> <a href="X.1035" title="X.1035">X.1035</a></li></ul>
<div class="mw-heading mw-heading2"><h2 id="References">References</h2></div>
<style data-mw-deduplicate="TemplateStyles:r1239543626">
/* start https://en.wikipedia.org/ */


.mw-parser-output .reflist{margin-bottom:0.5em;list-style-type:decimal}@media screen{.mw-parser-output .reflist{font-size:90%}}.mw-parser-output .reflist .references{font-size:100%;margin-bottom:0;list-style-type:inherit}.mw-parser-output .reflist-columns-2{column-width:30em}.mw-parser-output .reflist-columns-3{column-width:25em}.mw-parser-output .reflist-columns{margin-top:0.3em}.mw-parser-output .reflist-columns ol{margin-top:0}.mw-parser-output .reflist-columns li{page-break-inside:avoid;break-inside:avoid-column}.mw-parser-output .reflist-upper-alpha{list-style-type:upper-alpha}.mw-parser-output .reflist-upper-roman{list-style-type:upper-roman}.mw-parser-output .reflist-lower-alpha{list-style-type:lower-alpha}.mw-parser-output .reflist-lower-greek{list-style-type:lower-greek}.mw-parser-output .reflist-lower-roman{list-style-type:lower-roman}


/* end https://en.wikipedia.org/ */
</style><div class="reflist">
<div class="mw-references-wrap mw-references-columns"><ol class="references">
<li id="cite_note-rfc3748_sec1-1"><span class="mw-cite-backlink">^ <a href="#cite_ref-rfc3748_sec1_1-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-rfc3748_sec1_1-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748#section-1">"Introduction"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748"><i>Extensible Authentication Protocol (EAP)</i></a>. sec.&nbsp;1. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC3748">10.17487/RFC3748</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748">3748</a>.</cite></span>
</li>
<li id="cite_note-2"><span class="mw-cite-backlink"><b><a href="#cite_ref-2">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://www.iana.org/assignments/eap-numbers/eap-numbers.xhtml">"Extensible Authentication Protocol (EAP) Registry"</a>. <i>www.iana.org</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2021-06-01</span></span>.</cite></span>
</li>
<li id="cite_note-3"><span class="mw-cite-backlink"><b><a href="#cite_ref-3">^</a></b></span> <span class="reference-text"><cite id="CITEREFGeorge_Ou2007" class="citation magazine cs1">George Ou (January 11, 2007). <a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/ultimate-wireless-security-guide-an-introduction-to-leap-authentication/">"Ultimate wireless security guide: An introduction to LEAP authentication"</a>. <i><a href="TechRepublic" title="TechRepublic">TechRepublic</a></i><span class="reference-accessdate">. Retrieved <span class="nowrap">2008-02-17</span></span>.</cite></span>
</li>
<li id="cite_note-4"><span class="mw-cite-backlink"><b><a href="#cite_ref-4">^</a></b></span> <span class="reference-text"><cite id="CITEREFDan_Jones2003" class="citation web cs1">Dan Jones (October 1, 2003). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20080209200945/http://www.unstrung.com/document.asp?doc_id=41185">"Look Before You LEAP"</a>. Unstrung. Archived from <a rel="nofollow" class="external text" href="http://www.unstrung.com/document.asp?doc_id=41185">the original</a> on February 9, 2008<span class="reference-accessdate">. Retrieved <span class="nowrap">2008-02-17</span></span>.</cite></span>
</li>
<li id="cite_note-5"><span class="mw-cite-backlink"><b><a href="#cite_ref-5">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://blogs.techrepublic.com.com/Ou/?p=67">"Understanding the updated WPA and WPA2 standards"</a>. techrepublic.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2008-02-17</span></span>.</cite></span>
</li>
<li id="cite_note-opensecurewireless-6"><span class="mw-cite-backlink">^ <a href="#cite_ref-opensecurewireless_6-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-opensecurewireless_6-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite id="CITEREFByrd2010" class="citation web cs1">Byrd, Christopher (5 May 2010). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20131212085700/http://riosec.com/files/Open-Secure-Wireless.pdf">"Open Secure Wireless"</a> <span class="cs1-format">(PDF)</span>. Archived from <a rel="nofollow" class="external text" href="http://riosec.com/files/Open-Secure-Wireless.pdf">the original</a> <span class="cs1-format">(PDF)</span> on 12 December 2013<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-rfc5216s211-7"><span class="mw-cite-backlink">^ <a href="#cite_ref-rfc5216s211_7-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-rfc5216s211_7-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc5216"><i>The EAP-TLS Authentication Protocol</i></a>. March 2008. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC5216">10.17487/RFC5216</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc5216">5216</a>. <q>The certificate_request message is included when the server desires the peer to authenticate itself via public key. While the EAP server SHOULD require peer authentication, this is not mandatory, since there are circumstances in which peer authentication will not be needed (e.g., emergency services, as described in [UNAUTH]), or where the peer will authenticate via some other means.</q></cite></span>
</li>
<li id="cite_note-8"><span class="mw-cite-backlink"><b><a href="#cite_ref-8">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.today/20130213070147/http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commit;h=065d2895b4693e8c923580dbfa31123297c8bb7d">"Add UNAUTH-TLS vendor specific EAP type"</a>. <i><a href="Hostapd" title="Hostapd">hostapd</a></i>. Archived from <a rel="nofollow" class="external text" href="http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commit;h=065d2895b4693e8c923580dbfa31123297c8bb7d">the original</a> on 2013-02-13<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><b><a href="#cite_ref-9">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.today/20140930045346/http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commitdiff;h=8e5fdfabf69a7692d1a0d04f00fa103e9ff72010">"HS 2.0R2: Add WFA server-only EAP-TLS peer method"</a>. <i><a href="Hostapd" title="Hostapd">hostapd</a></i>. Archived from <a rel="nofollow" class="external text" href="http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commitdiff;h=8e5fdfabf69a7692d1a0d04f00fa103e9ff72010">the original</a> on 2014-09-30<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-05-06</span></span>.</cite></span>
</li>
<li id="cite_note-10"><span class="mw-cite-backlink"><b><a href="#cite_ref-10">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://archive.today/20140930045348/http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commitdiff;h=b61e70c4f37837baf17956817f8d80a586f75770">"HS 2.0R2: Add WFA server-only EAP-TLS server method"</a>. <i><a href="Hostapd" title="Hostapd">hostapd</a></i>. Archived from <a rel="nofollow" class="external text" href="http://hostap.epitest.fi/gitweb/gitweb.cgi?p=hostap.git;a=commitdiff;h=b61e70c4f37837baf17956817f8d80a586f75770">the original</a> on 2014-09-30<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-05-06</span></span>.</cite></span>
</li>
<li id="cite_note-11"><span class="mw-cite-backlink"><b><a href="#cite_ref-11">^</a></b></span> <span class="reference-text"><cite id="CITEREFByrd2011" class="citation web cs1">Byrd, Christopher (1 November 2011). <a rel="nofollow" class="external text" href="https://web.archive.org/web/20131126183610/http://riosec.com/open-secure-wireless-2.0">"Open Secure Wireless 2.0"</a>. Archived from <a rel="nofollow" class="external text" href="http://riosec.com/open-secure-wireless-2.0">the original</a> on 26 November 2013<span class="reference-accessdate">. Retrieved <span class="nowrap">2013-08-14</span></span>.</cite></span>
</li>
<li id="cite_note-12"><span class="mw-cite-backlink"><b><a href="#cite_ref-12">^</a></b></span> <span class="reference-text"><cite id="CITEREFRand_MorimotoKenton_GardinierMichael_NoelJoe_Coca2003" class="citation book cs1">Rand Morimoto; Kenton Gardinier; Michael Noel; Joe Coca (2003). <a rel="nofollow" class="external text" href="https://books.google.com/books?id=5x7iLC7fKIAC&amp;pg=PA244"><i>Microsoft Exchange Server 2003 Unleashed</i></a>. Sams. p.&nbsp;244. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-672-32581-6</bdi>.</cite></span>
</li>
<li id="cite_note-13"><span class="mw-cite-backlink"><b><a href="#cite_ref-13">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://arstechnica.com/articles/paedia/security.ars/4">"Alternative Encryption Schemes: Targeting the weaknesses in static WEP"</a>. <i>Ars Technica</i><span class="reference-accessdate">. Retrieved <span class="nowrap">2008-02-17</span></span>.</cite></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><b><a href="#cite_ref-14">^</a></b></span> <span class="reference-text"><cite class="citation cs2"><a rel="nofollow" class="external text" href="http://support.microsoft.com/kb/922574">"922574"</a>, <i>Knowledge Base</i>, Microsoft</cite></span>
</li>
<li id="cite_note-15"><span class="mw-cite-backlink"><b><a href="#cite_ref-15">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.juniper.net/techpubs/software/aaa_802/sbrc/sbrc70/sw-sbrc-admin/html/EAP-027.html">"EAP-POTP Authentication Protocol"</a>. Juniper.net<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-04-17</span></span>.</cite></span>
</li>
<li id="cite_note-16"><span class="mw-cite-backlink"><b><a href="#cite_ref-16">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://code.metager.de/source/xref/freeradius/server/src/modules/rlm_eap/types/">FreeRADIUS EAP module rlm_eap_pwd</a></span>
</li>
<li id="cite_note-17"><span class="mw-cite-backlink"><b><a href="#cite_ref-17">^</a></b></span> <span class="reference-text"><cite id="CITEREFMcCauley" class="citation mailinglist cs1">McCauley, Mike. <a rel="nofollow" class="external text" href="http://www.open.com.au/pipermail/radiator-announce/2012-June/000018.html">"Added support for EAP-PWD per RFC 5931"</a>. <i>radiator-announce</i> (Mailing list).</cite></span>
</li>
<li id="cite_note-18"><span class="mw-cite-backlink"><b><a href="#cite_ref-18">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://community.arubanetworks.com/t5/Technology-Blog/Secure-authentication-with-only-a-password/ba-p/36524">Secure-authentication with only a password</a></span>
</li>
<li id="cite_note-19"><span class="mw-cite-backlink"><b><a href="#cite_ref-19">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/hh945104(v=ws.11)">Extensible Authentication Protocol (EAP) Settings for Network Access</a></span>
</li>
<li id="cite_note-20"><span class="mw-cite-backlink"><b><a href="#cite_ref-20">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://forums.wpcentral.com/windows-phone-8/200619-802-1x-eap-ttls-support.html">"802.1x / EAP TTLS support? – Windows Phone Central Forums"</a>. Forums.wpcentral.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-04-17</span></span>.</cite></span>
</li>
<li id="cite_note-21"><span class="mw-cite-backlink"><b><a href="#cite_ref-21">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://technet.microsoft.com/library/dn643706.aspx">"Enterprise Wi-Fi authentication (EAP)"</a>. Microsoft.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-04-23</span></span>.</cite></span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><b><a href="#cite_ref-22">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-funk-eap-ttls-v1-01"><i>EAP Tunneled TLS Authentication Protocol Version 1 (EAP-TTLSv1)</i></a>. I-D draft-funk-eap-ttls-v1-01.</cite></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><b><a href="#cite_ref-23">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20080324094115/http://articles.techrepublic.com.com/5100-1035-6148557.html">"Ultimate wireless security guide: A primer on Cisco EAP-FAST authentication"</a>. techrepublic.com. Archived from <a rel="nofollow" class="external text" href="http://articles.techrepublic.com.com/5100-1035-6148557.html">the original</a> on 2008-03-24<span class="reference-accessdate">. Retrieved <span class="nowrap">2008-02-17</span></span>.</cite></span>
</li>
<li id="cite_note-24"><span class="mw-cite-backlink"><b><a href="#cite_ref-24">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.ciscopress.com/articles/article.asp?p=369223&amp;seqNum=5">"EAP-FAST &gt; EAP Authentication Protocols for WLANs"</a>. Ciscopress.com<span class="reference-accessdate">. Retrieved <span class="nowrap">2014-04-17</span></span>.</cite></span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><b><a href="#cite_ref-25">^</a></b></span> <span class="reference-text"><cite class="citation web cs1"><a rel="nofollow" class="external text" href="https://web.archive.org/web/20090210002337/http://www.cisco.com/en/US/docs/wireless/wlan_adapter/eap_types/fast/admin/guide/FAST_admin.html">"EAP-FAST for Windows Vista Administrator Guide"</a>. Archived from <a rel="nofollow" class="external text" href="http://www.cisco.com/en/US/docs/wireless/wlan_adapter/eap_types/fast/admin/guide/FAST_admin.html">the original</a> on February 10, 2009.</cite></span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><b><a href="#cite_ref-26">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://blogs.msdn.com/eapteam/archive/2008/10/17/how-do-i-install-cisco-eap-fast-on-my-computer.aspx">How do I install CISCO EAP-FAST on my computer?</a></span>
</li>
<li id="cite_note-27"><span class="mw-cite-backlink"><b><a href="#cite_ref-27">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="http://www.microsoft.com/technet/technetmag/issues/2007/05/CableGuy/default.aspx">EAPHost in Windows</a></span>
</li>
<li id="cite_note-28"><span class="mw-cite-backlink"><b><a href="#cite_ref-28">^</a></b></span> <span class="reference-text"><cite id="CITEREFAuraSethiPeltonen2021" class="citation cs1">Aura, Tuomas; Sethi, Mohit; Peltonen, A. (December 2021). <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc9140"><i>Nimble out-of-band authentication for EAP (EAP-NOOB)</i></a>. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC9140">10.17487/RFC9140</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc9140">9140</a>.</cite></span>
</li>
<li id="cite_note-29"><span class="mw-cite-backlink"><b><a href="#cite_ref-29">^</a></b></span> <span class="reference-text"><a rel="nofollow" class="external text" href="https://github.com/tuomaura/eap-noob/tree/master/protocolmodel">EAP-NOOB Model on GitHub</a></span>
</li>
<li id="cite_note-30"><span class="mw-cite-backlink"><b><a href="#cite_ref-30">^</a></b></span> <span class="reference-text"><cite id="CITEREFPedersen2005" class="citation book cs1">Pedersen, Torben (2005). "HTTPS, Secure HTTPS". <i>Encyclopedia of Cryptography and Security</i>. pp.&nbsp;<span class="nowrap">268–</span>269. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<a rel="nofollow" class="external text" href="https://doi.org/10.1007%2F0-387-23483-7_189">10.1007/0-387-23483-7_189</a>. <a href="ISBN_(identifier)" class="mw-redirect" title="ISBN (identifier)">ISBN</a>&nbsp;<bdi>978-0-387-23473-1</bdi>.</cite></span>
</li>
<li id="cite_note-31"><span class="mw-cite-backlink"><b><a href="#cite_ref-31">^</a></b></span> <span class="reference-text"><cite id="CITEREFPlumb,_Michelle" class="citation cs2">Plumb, Michelle, <i>CAPPS&nbsp;: HTTPS Networking</i>, <a href="OCLC_(identifier)" class="mw-redirect" title="OCLC (identifier)">OCLC</a>&nbsp;<a rel="nofollow" class="external text" href="https://search.worldcat.org/oclc/944514826">944514826</a></cite></span>
</li>
<li id="cite_note-32"><span class="mw-cite-backlink"><b><a href="#cite_ref-32">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748#section-3.3">"EAP Usage Within IEEE 802"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748"><i>Extensible Authentication Protocol (EAP)</i></a>. sec.&nbsp;3.3. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC3748">10.17487/RFC3748</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748">3748</a>.</cite></span>
</li>
<li id="cite_note-33"><span class="mw-cite-backlink"><b><a href="#cite_ref-33">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748#section-7.12">"Link Layer"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748"><i>Extensible Authentication Protocol (EAP)</i></a>. sec.&nbsp;7.12. <a href="Doi_(identifier)" class="mw-redirect" title="Doi (identifier)">doi</a>:<span class="id-lock-free" title="Freely accessible"><a rel="nofollow" class="external text" href="https://doi.org/10.17487%2FRFC3748">10.17487/RFC3748</a></span>. <a href="Request_for_Comments" title="Request for Comments">RFC</a> <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/rfc3748">3748</a>.</cite></span>
</li>
<li id="cite_note-34"><span class="mw-cite-backlink"><b><a href="#cite_ref-34">^</a></b></span> <span class="reference-text">IEEE 802.1X-2001, § 7</span>
</li>
<li id="cite_note-35"><span class="mw-cite-backlink"><b><a href="#cite_ref-35">^</a></b></span> <span class="reference-text">IEEE 802.1X-2004, § 3.2.2</span>
</li>
<li id="cite_note-36"><span class="mw-cite-backlink"><b><a href="#cite_ref-36">^</a></b></span> <span class="reference-text">IEEE 802.1X-2010, § 5</span>
</li>
<li id="cite_note-37"><span class="mw-cite-backlink"><b><a href="#cite_ref-37">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-kamath-pppext-peapv0-00#section-1.1">"EAP encapsulation"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-kamath-pppext-peapv0-00"><i>Microsoft's PEAP version 0 (Implementation in Windows XP SP1)</i></a>. sec.&nbsp;1.1. I-D draft-kamath-pppext-peapv0-00.</cite></span>
</li>
<li id="cite_note-peapv2-10_abstract-38"><span class="mw-cite-backlink">^ <a href="#cite_ref-peapv2-10_abstract_38-0"><sup><i><b>a</b></i></sup></a> <a href="#cite_ref-peapv2-10_abstract_38-1"><sup><i><b>b</b></i></sup></a></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-10#section-Abstract"><i>Protected EAP Protocol (PEAP) Version 2</i></a>. Abstract. I-D draft-josefsson-pppext-eap-tls-eap-10.</cite></span>
</li>
<li id="cite_note-39"><span class="mw-cite-backlink"><b><a href="#cite_ref-39">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-10#section-1">"Introduction"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-10"><i>Protected EAP Protocol (PEAP) Version 2</i></a>. sec.&nbsp;1. I-D draft-josefsson-pppext-eap-tls-eap-10.</cite></span>
</li>
<li id="cite_note-40"><span class="mw-cite-backlink"><b><a href="#cite_ref-40">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-07#section-1">"Introduction"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-07"><i>Protected EAP Protocol (PEAP) Version 2</i></a>. sec.&nbsp;1. I-D draft-josefsson-pppext-eap-tls-eap-07.</cite></span>
</li>
<li id="cite_note-41"><span class="mw-cite-backlink"><b><a href="#cite_ref-41">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-05#section-2.3"><i>Protected EAP Protocol (PEAP)</i></a>. sec.&nbsp;2.3. I-D draft-josefsson-pppext-eap-tls-eap-05.</cite></span>
</li>
<li id="cite_note-42"><span class="mw-cite-backlink"><b><a href="#cite_ref-42">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-06#section-2.3">"Version negotiation"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-06"><i>Protected EAP Protocol (PEAP)</i></a>. sec.&nbsp;2.3. I-D draft-josefsson-pppext-eap-tls-eap-06.</cite></span>
</li>
<li id="cite_note-43"><span class="mw-cite-backlink"><b><a href="#cite_ref-43">^</a></b></span> <span class="reference-text"><cite class="citation cs1"><a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-10#page-11">"Protocol Overview"</a>. <a rel="nofollow" class="external text" href="https://datatracker.ietf.org/doc/html/draft-josefsson-pppext-eap-tls-eap-10"><i>Protected EAP Protocol (PEAP) Version 2</i></a>. p.&nbsp;11. I-D draft-josefsson-pppext-eap-tls-eap-10.</cite></span>
</li>
</ol></div></div>
<div class="mw-heading mw-heading2"><h2 id="Further_reading">Further reading</h2></div>
<ul><li>"AAA and Network Security for Mobile Access. RADIUS, DIAMETER, EAP, PKI and IP mobility". M Nakhjiri. John Wiley and Sons, Ltd.</li></ul>
<div class="mw-heading mw-heading2"><h2 id="External_links">External links</h2></div>
<ul><li>RFC&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc3748">3748</a>: Extensible Authentication Protocol (EAP) (June 2004)</li>
<li>RFC&nbsp;<a rel="nofollow" class="external text" href="https://www.rfc-editor.org/rfc/rfc5247">5247</a>: Extensible Authentication Protocol (EAP) Key Management Framework (August 2008)</li>
<li><a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/ultimate-wireless-security-guide-microsoft-ias-radius-for-wireless-authentication/6148579">Configure RADIUS for secure 802.1x wireless LAN</a></li>
<li><a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/ultimate-wireless-security-guide-self-signed-certificates-for-your-radius-server/6148560">How to self-sign a RADIUS server for secure PEAP or EAP-TTLS authentication</a></li>
<li><a rel="nofollow" class="external text" href="https://technet.microsoft.com/en-us/network/bb643147.aspx">Extensible Authentication Protocol</a> on Microsoft TechNet</li>
<li><a rel="nofollow" class="external text" href="http://www.microsoft.com/technet/technetmag/issues/2007/05/CableGuy/default.aspx">EAPHost in Windows Vista and Windows Server 2008</a></li>
<li><a rel="nofollow" class="external text" href="http://wire.cs.nctu.edu.tw/wire1x/">WIRE1x</a></li>
<li><a rel="nofollow" class="external text" href="https://web.archive.org/web/20071023234216/http://www.ietf.org/html.charters/emu-charter.html">"IETF EAP Method Update (emu) Working Group"</a></li>
<li><cite class="citation web cs1"><a rel="nofollow" class="external text" href="http://www.juniper.net/techpubs/software/aaa_802/sbrc/sbrc70/sw-sbrc-admin/html/EAP-027.html">"EAP-POTP Authentication Protocol"</a>. <i>Steel Belted Radius Carrier 7.0 Administration and Configuration Guide</i>. <a href="Juniper_Networks" title="Juniper Networks">Juniper Networks</a>.</cite></li></ul>
<div class="navbox-styles"><style data-mw-deduplicate="TemplateStyles:r1129693374">
/* start https://en.wikipedia.org/ */


.mw-parser-output .hlist dl,.mw-parser-output .hlist ol,.mw-parser-output .hlist ul{margin:0;padding:0}.mw-parser-output .hlist dd,.mw-parser-output .hlist dt,.mw-parser-output .hlist li{margin:0;display:inline}.mw-parser-output .hlist.inline,.mw-parser-output .hlist.inline dl,.mw-parser-output .hlist.inline ol,.mw-parser-output .hlist.inline ul,.mw-parser-output .hlist dl dl,.mw-parser-output .hlist dl ol,.mw-parser-output .hlist dl ul,.mw-parser-output .hlist ol dl,.mw-parser-output .hlist ol ol,.mw-parser-output .hlist ol ul,.mw-parser-output .hlist ul dl,.mw-parser-output .hlist ul ol,.mw-parser-output .hlist ul ul{display:inline}.mw-parser-output .hlist .mw-empty-li{display:none}.mw-parser-output .hlist dt::after{content:": "}.mw-parser-output .hlist dd::after,.mw-parser-output .hlist li::after{content:" · ";font-weight:bold}.mw-parser-output .hlist dd:last-child::after,.mw-parser-output .hlist dt:last-child::after,.mw-parser-output .hlist li:last-child::after{content:none}.mw-parser-output .hlist dd dd:first-child::before,.mw-parser-output .hlist dd dt:first-child::before,.mw-parser-output .hlist dd li:first-child::before,.mw-parser-output .hlist dt dd:first-child::before,.mw-parser-output .hlist dt dt:first-child::before,.mw-parser-output .hlist dt li:first-child::before,.mw-parser-output .hlist li dd:first-child::before,.mw-parser-output .hlist li dt:first-child::before,.mw-parser-output .hlist li li:first-child::before{content:" (";font-weight:normal}.mw-parser-output .hlist dd dd:last-child::after,.mw-parser-output .hlist dd dt:last-child::after,.mw-parser-output .hlist dd li:last-child::after,.mw-parser-output .hlist dt dd:last-child::after,.mw-parser-output .hlist dt dt:last-child::after,.mw-parser-output .hlist dt li:last-child::after,.mw-parser-output .hlist li dd:last-child::after,.mw-parser-output .hlist li dt:last-child::after,.mw-parser-output .hlist li li:last-child::after{content:")";font-weight:normal}.mw-parser-output .hlist ol{counter-reset:listitem}.mw-parser-output .hlist ol>li{counter-increment:listitem}.mw-parser-output .hlist ol>li::before{content:" "counter(listitem)"\a0 "}.mw-parser-output .hlist dd ol>li:first-child::before,.mw-parser-output .hlist dt ol>li:first-child::before,.mw-parser-output .hlist li ol>li:first-child::before{content:" ("counter(listitem)"\a0 "}


/* end https://en.wikipedia.org/ */
</style><style data-mw-deduplicate="TemplateStyles:r1236075235">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbox{box-sizing:border-box;border:1px solid #a2a9b1;width:100%;clear:both;font-size:88%;text-align:center;padding:1px;margin:1em auto 0}.mw-parser-output .navbox .navbox{margin-top:0}.mw-parser-output .navbox+.navbox,.mw-parser-output .navbox+.navbox-styles+.navbox{margin-top:-1px}.mw-parser-output .navbox-inner,.mw-parser-output .navbox-subgroup{width:100%}.mw-parser-output .navbox-group,.mw-parser-output .navbox-title,.mw-parser-output .navbox-abovebelow{padding:0.25em 1em;line-height:1.5em;text-align:center}.mw-parser-output .navbox-group{white-space:nowrap;text-align:right}.mw-parser-output .navbox,.mw-parser-output .navbox-subgroup{background-color:#fdfdfd}.mw-parser-output .navbox-list{line-height:1.5em;border-color:#fdfdfd}.mw-parser-output .navbox-list-with-group{text-align:left;border-left-width:2px;border-left-style:solid}.mw-parser-output tr+tr>.navbox-abovebelow,.mw-parser-output tr+tr>.navbox-group,.mw-parser-output tr+tr>.navbox-image,.mw-parser-output tr+tr>.navbox-list{border-top:2px solid #fdfdfd}.mw-parser-output .navbox-title{background-color:#ccf}.mw-parser-output .navbox-abovebelow,.mw-parser-output .navbox-group,.mw-parser-output .navbox-subgroup .navbox-title{background-color:#ddf}.mw-parser-output .navbox-subgroup .navbox-group,.mw-parser-output .navbox-subgroup .navbox-abovebelow{background-color:#e6e6ff}.mw-parser-output .navbox-even{background-color:#f7f7f7}.mw-parser-output .navbox-odd{background-color:transparent}.mw-parser-output .navbox .hlist td dl,.mw-parser-output .navbox .hlist td ol,.mw-parser-output .navbox .hlist td ul,.mw-parser-output .navbox td.hlist dl,.mw-parser-output .navbox td.hlist ol,.mw-parser-output .navbox td.hlist ul{padding:0.125em 0}.mw-parser-output .navbox .navbar{display:block;font-size:100%}.mw-parser-output .navbox-title .navbar{float:left;text-align:left;margin-right:0.5em}body.skin--responsive .mw-parser-output .navbox-image img{max-width:none!important}@media print{body.ns-0 .mw-parser-output .navbox{display:none!important}}


/* end https://en.wikipedia.org/ */
</style></div><div role="navigation" class="navbox" aria-labelledby="Authentication330" style="padding:3px"><table class="nowraplinks hlist mw-collapsible autocollapse navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="col" class="navbox-title" colspan="2"><style data-mw-deduplicate="TemplateStyles:r1239400231">
/* start https://en.wikipedia.org/ */


.mw-parser-output .navbar{display:inline;font-size:88%;font-weight:normal}.mw-parser-output .navbar-collapse{float:left;text-align:left}.mw-parser-output .navbar-boxtext{word-spacing:0}.mw-parser-output .navbar ul{display:inline-block;white-space:nowrap;line-height:inherit}.mw-parser-output .navbar-brackets::before{margin-right:-0.125em;content:"[ "}.mw-parser-output .navbar-brackets::after{margin-left:-0.125em;content:" ]"}.mw-parser-output .navbar li{word-spacing:-0.125em}.mw-parser-output .navbar a>span,.mw-parser-output .navbar a>abbr{text-decoration:inherit}.mw-parser-output .navbar-mini abbr{font-variant:small-caps;border-bottom:none;text-decoration:none;cursor:inherit}.mw-parser-output .navbar-ct-full{font-size:114%;margin:0 7em}.mw-parser-output .navbar-ct-mini{font-size:114%;margin:0 4em}html.skin-theme-clientpref-night .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}@media(prefers-color-scheme:dark){html.skin-theme-clientpref-os .mw-parser-output .navbar li a abbr{color:var(--color-base)!important}}@media print{.mw-parser-output .navbar{display:none!important}}


/* end https://en.wikipedia.org/ */
</style><div id="Authentication330" style="font-size:114%;margin:0 4em"><a href="Authentication" title="Authentication">Authentication</a></div></th></tr><tr><th scope="row" class="navbox-group" style="width:1%">Authentication<br>APIs</th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="BSD_Authentication" title="BSD Authentication">BSD Authentication</a> (BSD Auth)</li>
<li><a href="EAuthentication" class="mw-redirect" title="EAuthentication">eAuthentication</a> (eAuth)</li>
<li><a href="Generic_Security_Services_Application_Program_Interface" class="mw-redirect" title="Generic Security Services Application Program Interface">Generic Security Services API</a> (GSSAPI)</li>
<li><a href="Java_Authentication_and_Authorization_Service" title="Java Authentication and Authorization Service">Java Authentication and Authorization Service</a> (JAAS)</li>
<li><a href="Pluggable_authentication_module" class="mw-redirect" title="Pluggable authentication module">Pluggable Authentication Modules</a> (PAM)</li>
<li><a href="Simple_Authentication_and_Security_Layer" title="Simple Authentication and Security Layer">Simple Authentication and Security Layer</a> (SASL)</li>
<li><a href="Security_Support_Provider_Interface" title="Security Support Provider Interface">Security Support Provider Interface</a> (SSPI)</li>
<li><a href="XUDA" title="XUDA">XCert Universal Database API</a> (XUDA)</li></ul>
</div></td></tr><tr><th scope="row" class="navbox-group" style="width:1%"><a href="Authentication_protocol" title="Authentication protocol">Authentication<br>protocols</a></th><td class="navbox-list-with-group navbox-list navbox-even" style="width:100%;padding:0"><div style="padding:0 0.25em">
<ul><li><a href="ACF2" title="ACF2">ACF2</a></li>
<li><a href="Authentication_and_Key_Agreement_(protocol)" class="mw-redirect" title="Authentication and Key Agreement (protocol)">Authentication and Key Agreement</a> (AKA)</li>
<li><a href="CAVE-based_authentication" title="CAVE-based authentication">CAVE-based authentication</a></li>
<li><a href="Challenge-Handshake_Authentication_Protocol" title="Challenge-Handshake Authentication Protocol">Challenge-Handshake Authentication Protocol</a> (CHAP)
<ul><li><a href="MS-CHAP" title="MS-CHAP">MS-CHAP</a></li></ul></li>
<li><a href="Central_Authentication_Service" title="Central Authentication Service">Central Authentication Service</a> (CAS)</li>
<li><a href="CRAM-MD5" title="CRAM-MD5">CRAM-MD5</a></li>
<li><a href="Diameter_(protocol)" title="Diameter (protocol)">Diameter</a></li>
<li> (EAP)</li>
<li><a href="Host_Identity_Protocol" title="Host Identity Protocol">Host Identity Protocol</a> (HIP)</li>
<li><a href="IndieAuth" title="IndieAuth">IndieAuth</a></li>
<li><a href="Kerberos_(protocol)" title="Kerberos (protocol)">Kerberos</a></li>
<li><a href="LAN_Manager" title="LAN Manager">LAN Manager</a></li>
<li><a href="NT_LAN_Manager" class="mw-redirect" title="NT LAN Manager">NT LAN Manager</a> (NTLM)</li>
<li><a href="OAuth" title="OAuth">OAuth</a></li>
<li><a href="OpenID" title="OpenID">OpenID</a></li>
<li><a href="OpenID_Connect" class="mw-redirect" title="OpenID Connect">OpenID Connect</a> (OIDC)</li>
<li><a href="Password-authenticated_key_agreement" title="Password-authenticated key agreement">Password-authenticated key agreement</a> protocols</li>
<li><a href="Password_Authentication_Protocol" title="Password Authentication Protocol">Password Authentication Protocol</a> (PAP)</li>
<li><a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">Protected Extensible Authentication Protocol</a> (PEAP)</li>
<li><a href="RADIUS" title="RADIUS">Remote Access Dial In User Service</a> (RADIUS)</li>
<li><a href="Resource_Access_Control_Facility" title="Resource Access Control Facility">Resource Access Control Facility</a> (RACF)</li>
<li><a href="Secure_Remote_Password_protocol" title="Secure Remote Password protocol">Secure Remote Password protocol</a> (SRP)</li>
<li><a href="TACACS" title="TACACS">TACACS</a></li>
<li><a href="Woo%E2%80%93Lam" title="Woo–Lam">Woo–Lam</a></li></ul>
</div></td></tr><tr><td class="navbox-abovebelow" colspan="2"><div>
<ul><li><span class="noviewer" typeof="mw:File"><span title="Category"></span></span> Category</li>
<li><span class="noviewer" typeof="mw:File"><span title="Commons page"></span></span> <a href="https://commons.wikimedia.org/wiki/Category:Authentication" class="extiw external" title="commons:Category:Authentication">Commons</a></li></ul>
</div></td></tr></tbody></table></div>
<div class="navbox-styles"></div><div role="navigation" class="navbox authority-control" aria-label="Navbox391" style="padding:3px"><table class="nowraplinks hlist navbox-inner" style="border-spacing:0;background:transparent;color:inherit"><tbody><tr><th scope="row" class="navbox-group" style="width:1%">Authority control databases: National </th><td class="navbox-list-with-group navbox-list navbox-odd" style="width:100%;padding:0"><div style="padding:0 0.25em"><ul><li><span class="uid"><a rel="nofollow" class="external text" href="https://d-nb.info/gnd/7730299-0">Germany</a></span></li></ul></div></td></tr></tbody></table></div></div><!--htdig_noindex--><div><div class="zim-footer">
This article is issued from <a class="external text" title="Last edited on 2025-08-04" href="https://en.wikipedia.org/wiki/?title=Extensible_Authentication_Protocol&amp;oldid=1304172237">Wikipedia</a>. The text is available under <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.en">Creative Commons Attribution-Share Alike 4.0</a> unless otherwise noted. Additional terms may apply for the media files.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>

</body></html>