Micron Document
<!DOCTYPE html>
<html class="client-nojs vector-feature-language-in-header-enabled vector-feature-language-in-main-page-header-disabled vector-feature-page-tools-pinned-disabled vector-feature-toc-pinned-clientpref-0 vector-toc-not-available vector-feature-main-menu-pinned-disabled vector-feature-limited-width-clientpref-1 vector-feature-limited-width-content-enabled vector-feature-custom-font-size-clientpref-1 vector-feature-appearance-pinned-clientpref-0 vector-feature-night-mode-enabled skin-theme-clientpref-os vector-sticky-header-enabled" lang="fr" dir="ltr"><head>
<meta charset="UTF-8">
<title>Extensible Authentication Protocol</title>
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link rel="icon" type="image/png" href="./_res_/favicon.png">
<link rel="canonical" href="https://fr.wikipedia.org/wiki/Extensible_Authentication_Protocol"> <link href="./_mw_/ext.cite.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/ext.wikimediamessages.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.icons.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.search.codex.styles.css" rel="stylesheet" type="text/css">
<link href="./_mw_/skins.vector.styles.css" rel="stylesheet" type="text/css">
<meta name="ResourceLoaderDynamicStyles" content="">
<link rel="stylesheet" type="text/css" href="./_mw_/site.styles.css">
<link rel="stylesheet" type="text/css" href="./_mw_/noscript.css">
<link rel="stylesheet" type="text/css" href="./_res_/footer.css">
<link rel="stylesheet" type="text/css" href="./_res_/vector-2022.css">
</head>
<body class="skin--responsive skin-vector skin-vector-search-vue mediawiki ltr sitedir-ltr mw-hide-empty-elt ns-0 ns-subject page-Extensible_Authentication_Protocol rootpage-Extensible_Authentication_Protocol skin-vector-2022 action-view">
<div class="mw-page-container">
<div class="mw-page-container-inner">
<div class="mw-content-container">
<main id="content" class="mw-body">
<header class="mw-body-header vector-page-titlebar">
<h1 id="firstHeading" class="firstHeading mw-first-heading"><span class="mw-page-title-main">Extensible Authentication Protocol</span></h1>
</header>
<a id="top"></a>
<div id="bodyContent" class="vector-body ve-init-mw-desktopArticleTarget-targetContainer" aria-labelledby="firstHeading" data-mw-ve-target-container="">
<div id="contentSub">
<div id="mw-content-subtitle"></div>
</div>
<div id="mw-content-text" class="mw-body-content mw-content-ltr" lang="fr" dir="ltr"><div class="mw-content-ltr mw-parser-output" lang="fr" dir="ltr">
<div class="infobox_v3 infobox infobox--frwiki noarchive">
<div class="entete icon communication" style="background-color: #DFEDFF;"><style data-mw-deduplicate="TemplateStyles:r228712581">
/* start https://fr.wikipedia.org/ */


.mw-parser-output .entete.communication{background-image:url("./_mw_/Picto_infobox_antenna.png")}


/* end https://fr.wikipedia.org/ */
</style>
<div>Extensible Authentication Protocol</div>
</div>
<p class="mw-empty-elt">
</p><p class="mw-empty-elt">
</p>
<table><caption style="">Informations</caption>

<tbody><tr>
<th scope="row"> Fonction
</th>
<td>
Authentification</td>
</tr>

<tr>
<th scope="row"> <a href="Sigle" title="Sigle">Sigle</a>
</th>
<td>
EAP</td>
</tr>

<tr>
<th scope="row"> Date de création
</th>
<td>
1998</td>
</tr>





<tr>
<th scope="row"> <a href="Request_for_comments" title="Request for comments">RFC</a>
</th>
<td>
1998&nbsp;: <a href="https://datatracker.ietf.org/doc/html/rfc2284" class="extiw external" title="rfc:2284">RFC 2284</a><br>2004&nbsp;: <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a><br>2008&nbsp;: <a href="https://datatracker.ietf.org/doc/html/rfc5247" class="extiw external" title="rfc:5247">RFC 5247</a></td>
</tr>

</tbody></table>
</div>
<p><b>Extensible Authentication Protocol</b> ou <b>EAP</b> est un protocole de communication réseau embarquant de multiples méthodes d'authentification, pouvant être utilisé sur les liaisons <a href="Protocole_point_%C3%A0_point" class="mw-redirect" title="Protocole point à point">point à point</a> (<abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;2284<sup id="cite_ref-RFC-2284-a-t-d_1-0" class="reference"><a href="#cite_note-RFC-2284-a-t-d-1"><span class="cite-bracket">[</span>1<span class="cite-bracket">]</span></a></sup>), les <a href="R%C3%A9seau_informatique" title="Réseau informatique">réseaux filaires</a> et les <a href="R%C3%A9seau_sans_fil" title="Réseau sans fil">réseaux sans fil</a> (<abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;3748<sup id="cite_ref-RFC-3748-a-t-d_2-0" class="reference"><a href="#cite_note-RFC-3748-a-t-d-2"><span class="cite-bracket">[</span>2<span class="cite-bracket">]</span></a></sup>, <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;5247<sup id="cite_ref-RFC-5247-a-t-d_3-0" class="reference"><a href="#cite_note-RFC-5247-a-t-d-3"><span class="cite-bracket">[</span>3<span class="cite-bracket">]</span></a></sup>) tels que les réseaux <a href="Wi-Fi" title="Wi-Fi">Wi-Fi</a>.
</p><p>Plusieurs méthodes d'authentification sont prédéfinies (<a href="MD5" title="MD5">MD5</a>, <a href="Mot_de_passe_unique" class="mw-redirect" title="Mot de passe unique">OTP</a>, Generic Token Card, etc.) mais il est possible d'en rajouter sans qu'il soit nécessaire de changer ou de créer un nouveau <a href="Protocole_de_communication" title="Protocole de communication">protocole réseau</a>.
</p>

<div class="mw-heading mw-heading2"><h2 id="Le_protocole_EAP">Le protocole EAP</h2></div>

<p>Le protocole EAP est&nbsp;:
</p>
<ul><li>Un <b>protocole de communication réseau</b>&nbsp;: il est constitué d'un échange de trames dans un format spécifique à EAP pour réaliser l'authentification d'un partenaire<sup id="cite_ref-rfc2284_p2_4-0" class="reference"><a href="#cite_note-rfc2284_p2-4"><span class="cite-bracket">[</span>RFC 1<span class="cite-bracket">]</span></a></sup></li>
<li>Un <b>protocole extensible</b>&nbsp;: quelques méthodes d'authentification sont prédéfinies (<a href="#EAP-MD5">MD5</a>, <a href="Mot_de_passe_%C3%A0_usage_unique" title="Mot de passe à usage unique">OTP</a>, Generic Token Card, etc.) mais d'autres peuvent être ajoutées sans qu'il soit nécessaire de changer le protocole réseau ou d'en définir un nouveau<sup id="cite_ref-rfc3748_p2_5-0" class="reference"><a href="#cite_note-rfc3748_p2-5"><span class="cite-bracket">[</span>RFC 2<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Le protocole EAP a été proposé en <b>mars 1998</b> dans la <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;2284<sup id="cite_ref-RFC-2284_6-0" class="reference"><a href="#cite_note-RFC-2284-6"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup> et <b>proposé comme standard Internet</b> auprès de l'IETF.<br>
Il est conçu pour fournir un mécanisme d'authentification pour les liaisons <a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">PPP</a> (<a href="Couche_liaison_de_donn%C3%A9es" title="Couche liaison de données">couche 2 du modèle OSI</a>) afin d'autoriser ou interdire l'établissement de la <a href="Couche_r%C3%A9seau" title="Couche réseau">couche réseau</a> (couche 3 du modèle OSI)<sup id="cite_ref-rfc2284_p2_4-1" class="reference"><a href="#cite_note-rfc2284_p2-4"><span class="cite-bracket">[</span>RFC 1<span class="cite-bracket">]</span></a></sup>. Ce protocole ne s'appuie donc pas sur le protocole <a href="Internet_Protocol" title="Internet Protocol">IP (couche 3 du modèle OSI)</a><sup id="cite_ref-rfc3748_p5_7-0" class="reference"><a href="#cite_note-rfc3748_p5-7"><span class="cite-bracket">[</span>RFC 3<span class="cite-bracket">]</span></a></sup>.
</p><p>La liaison <a href="Point-to-Point_Protocol" title="Point-to-Point Protocol">PPP</a> est définie entre un <i>peer</i><sup id="cite_ref-8" class="reference"><a href="#cite_note-8"><span class="cite-bracket">[</span>note 1<span class="cite-bracket">]</span></a></sup> et un <i>authenticator</i><sup id="cite_ref-9" class="reference"><a href="#cite_note-9"><span class="cite-bracket">[</span>note 2<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-rfc2284_p2_4-2" class="reference"><a href="#cite_note-rfc2284_p2-4"><span class="cite-bracket">[</span>RFC 1<span class="cite-bracket">]</span></a></sup>.<br>
L'<i>authenticator</i> peut envoyer une requête au <i>peer</i> pour connaître son identité ou alors de déterminer son identité par l'interface de communication (<a href="Ligne_sp%C3%A9cialis%C3%A9e" title="Ligne spécialisée">Liaisons louées</a>, <a href="Ligne_d%C3%A9di%C3%A9e" title="Ligne dédiée">Ligne dédiée</a>, etc.)<sup id="cite_ref-rfc2284_p2_4-3" class="reference"><a href="#cite_note-rfc2284_p2-4"><span class="cite-bracket">[</span>RFC 1<span class="cite-bracket">]</span></a></sup>.<br>
Cette identification est suivie d'une ou plusieurs requêtes envoyées par l'<i>authenticator</i> (obligatoire) avec un paramètre contenant la méthode d'authentification souhaitée<sup id="cite_ref-rfc2284_p2_4-4" class="reference"><a href="#cite_note-rfc2284_p2-4"><span class="cite-bracket">[</span>RFC 1<span class="cite-bracket">]</span></a></sup>&nbsp;:
</p>
<ul><li><a href="#EAP-MD5">MD5-challenge</a></li>
<li><a href="Mot_de_passe_%C3%A0_usage_unique" title="Mot de passe à usage unique">One-Time Passwords</a></li>
<li>Generic Token Card</li>
<li><a href="SIM" class="mw-redirect mw-disambig" title="SIM">SIM</a></li>
<li>etc.</li></ul>
<p>Le <i>peer</i> doit répondre à ce challenge et aura en fonction du résultat, un message envoyé par l'<i>authenticator</i> contenant un code<sup id="cite_ref-rfc2284_p6-7_10-0" class="reference"><a href="#cite_note-rfc2284_p6-7-10"><span class="cite-bracket">[</span>RFC 4<span class="cite-bracket">]</span></a></sup>&nbsp;:
</p>
<ul><li>Code 3&nbsp;: Succès (Établissement de la couche réseau)</li>
<li>Code 4&nbsp;: Échec (Impossible d'établir la couche réseau)</li></ul>
<p>Cette authentification peut être réalisée par l'<i>authenticator</i> lui-même ou déléguée à un <a href="Serveur_d'authentification" title="Serveur d'authentification">service tiers</a> (<i>authentication server</i>)<sup id="cite_ref-rfc2284_p2-3_11-0" class="reference"><a href="#cite_note-rfc2284_p2-3-11"><span class="cite-bracket">[</span>RFC 5<span class="cite-bracket">]</span></a></sup>.
</p><p><span class="need_ref" title="Ce passage nécessite une référence." style="cursor:help;">L'authentification peut être demandée par chaque extrémité</span><sup class="need_ref_tag" style="padding-left:2px;">[réf.&nbsp;nécessaire]</sup>
</p>

<p>En <b>juin 2004</b>, la <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;3748<sup id="cite_ref-RFC-3748_12-0" class="reference"><a href="#cite_note-RFC-3748-12"><span class="cite-bracket">[</span>5<span class="cite-bracket">]</span></a></sup> vient étendre le fonctionnement du protocole EAP aux réseaux définis dans le standard <a href="IEEE_802" title="IEEE 802">IEEE 802</a> <b>rendant obsolète</b> la <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;2284<sup id="cite_ref-RFC-2284_6-1" class="reference"><a href="#cite_note-RFC-2284-6"><span class="cite-bracket">[</span>4<span class="cite-bracket">]</span></a></sup><sup id="cite_ref-rfc3748_p3_13-0" class="reference"><a href="#cite_note-rfc3748_p3-13"><span class="cite-bracket">[</span>RFC 6<span class="cite-bracket">]</span></a></sup>&nbsp;:
</p>
<ul><li>Les <a href="R%C3%A9seau_informatique" title="Réseau informatique">réseaux filaires</a>&nbsp;: Standard <a href="IEEE_802.1X" title="IEEE 802.1X">IEEE 802.1X</a></li>
<li>Les <a href="R%C3%A9seau_sans_fil" title="Réseau sans fil">réseaux sans fil</a>&nbsp;: Standard <a href="IEEE_802.11i" title="IEEE 802.11i">IEEE 802.11i</a></li></ul>
<p>Le protocole EAP sur ces réseaux est aussi connu sous le nom <b>EAPOL</b><sup id="cite_ref-14" class="reference"><a href="#cite_note-14"><span class="cite-bracket">[</span>note 3<span class="cite-bracket">]</span></a></sup><sup class="reference cite_virgule">,</sup><sup id="cite_ref-rfc3748_p54_15-0" class="reference"><a href="#cite_note-rfc3748_p54-15"><span class="cite-bracket">[</span>RFC 7<span class="cite-bracket">]</span></a></sup>.
</p><p>Bien que le protocole EAP possède un mécanisme de suppression de requêtes dupliquées et de retransmission de requêtes, il reste tributaire de la <a href="Couche_liaison_de_donn%C3%A9es" title="Couche liaison de données">couche de liaison de données</a><sup id="cite_ref-rfc3748_p15-16_16-0" class="reference"><a href="#cite_note-rfc3748_p15-16-16"><span class="cite-bracket">[</span>RFC 8<span class="cite-bracket">]</span></a></sup>. Par conséquent, des erreurs sur cette couche peuvent entraîner des erreurs d'authentification EAP<sup id="cite_ref-rfc3748_p16_17-0" class="reference"><a href="#cite_note-rfc3748_p16-17"><span class="cite-bracket">[</span>RFC 9<span class="cite-bracket">]</span></a></sup>.
</p><p>Le protocole EAP ne supporte pas nativement la <a href="Maximum_Transmission_Unit" class="mw-redirect" title="Maximum Transmission Unit">fragmentation des paquets réseau</a><sup id="cite_ref-rfc3748_p16-17_18-0" class="reference"><a href="#cite_note-rfc3748_p16-17-18"><span class="cite-bracket">[</span>RFC 10<span class="cite-bracket">]</span></a></sup> mais ce comportement peut être modifié avec certaines méthodes&nbsp;:
</p>
<ul><li><a href="#EAP-TLS">EAP-TLS</a><sup id="cite_ref-rfc5216_p14_19-0" class="reference"><a href="#cite_note-rfc5216_p14-19"><span class="cite-bracket">[</span>RFC 11<span class="cite-bracket">]</span></a></sup></li></ul>
<p>Quand le protocole EAP est utilisé en conjonction avec un point d'accès réseau compatible <a href="802.1X" class="mw-redirect" title="802.1X">802.1X</a> (sans-fil ou filaire), certaines méthodes EAP permettent de négocier une clé PMK (Pair-wise Master Key) entre le client et le point d'accès. Cette clé PMK peut ensuite être utilisée pour chiffrer les sessions <a href="TKIP" class="mw-redirect" title="TKIP">TKIP</a> ou <a href="CCMP" class="mw-disambig" title="CCMP">CCMP</a>.
</p><p><span class="need_ref" title="Ce passage nécessite une référence." style="cursor:help;">Les standards <a href="Wi-Fi_Protected_Access" title="Wi-Fi Protected Access">WPA</a> et <a href="Wi-Fi_Protected_Access#Présentation" title="Wi-Fi Protected Access">WPA2</a> ont adopté 5 types d’EAP comme mécanismes officiels d’identification</span><sup class="need_ref_tag" style="padding-left:2px;">[réf.&nbsp;nécessaire]</sup>&nbsp;:
</p>
<ul><li>EAP-TLS</li>
<li>EAP-TTLS/MSCHAPv2</li>
<li>PEAPv0/EAP-<a href="MS-CHAPv2" class="mw-redirect" title="MS-CHAPv2">MS-CHAPv2</a></li>
<li><a href="PEAP" class="mw-redirect" title="PEAP">PEAPv</a>1/EAP-GTC</li>
<li><a href="EAP-SIM" class="mw-redirect" title="EAP-SIM">EAP-SIM</a></li></ul>
<p>Mais EAP ne se limite pas à ces méthodes d'authentification. On présente ci-dessous des informations sur les EAP les plus connus.
</p><p><br>
</p>
<div class="mw-heading mw-heading3"><h3 id="Méthodes"><span id="M.C3.A9thodes"></span>Méthodes</h3></div>
<div class="mw-heading mw-heading4"><h4 id="LEAP">LEAP</h4></div>
<p><b>Lightweight Extensible Authentication Protocol (LEAP)</b> est une implémentation propriétaire de EAP conçue par Cisco Systems.
</p><p>Cisco a fait beaucoup d'efforts pour promouvoir ce protocole. Il a permis à d'autres fabricants de réaliser des produits «&nbsp;LEAP Compatible&nbsp;» au travers du programme CCX (Cisco Certified Extensions). Ce protocole n'est pas présent nativement sous Windows.
Il était connu pour être vulnérable aux attaques par dictionnaire comme EAP-MD5.
Mais il ne l'est plus depuis la version ASLEAP (2003) de Joshua Wright. Cisco continue de soutenir que LEAP est une solution sécurisée si l'on utilise des mots de passe suffisamment complexes, mais il est fréquent que des mots de passe trop faibles soient utilisés en entreprise. De nouveaux protocoles comme EAP-TTLS ou <a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">PEAP</a> ne rencontrent pas ce type de fragilité car ils créent un tunnel TLS pour sécuriser l'identification. De plus ces nouveaux protocoles étant plus ouverts, ils peuvent être utilisés sur des points d'accès de marque Cisco ou non.
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-TLS">EAP-TLS</h4></div>
<p>EAP-TLS est un standard ouvert <a href="IETF" class="mw-redirect" title="IETF">IETF</a>. On le retrouve utilisé chez de nombreux fabricants de matériel sans fil. C’est le seul protocole EAP qui doit obligatoirement être implanté sur un matériel pour que ce dernier puisse porter le logo <a href="Wi-Fi_Protected_Access" title="Wi-Fi Protected Access">WPA</a> ou <a href="WPA2" class="mw-redirect" title="WPA2">WPA2</a>.
</p><p>Il offre une bonne sécurité. En effet il utilise deux certificats pour la création d'un tunnel sécurisé qui permet ensuite l'identification&nbsp;: un côté serveur et un côté client. Cela signifie que même si le mot de passe est découvert, il ne sera d'aucune utilité sans le certificat client. Bien que EAP-TLS fournisse une excellente sécurité, l'obligation de disposer d'un certificat client est peut-être son talon d'Achille. En effet lorsque l'on dispose d'un grand parc de machines, il peut s'avérer difficile et coûteux de gérer un certificat par machine. C'est pour se passer du certificat client que les protocoles PEAP et EAP-TTLS ont été créés.
</p><p><a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a> est considéré comme le successeur du standard SSL. Il utilise une <a href="Infrastructure_%C3%A0_cl%C3%A9s_publiques" title="Infrastructure à clés publiques">Infrastructure à clés publiques</a> pour sécuriser les communications d'identification entre les clients et le serveur RADIUS.
</p><p>Il existe des implémentations client ou serveur pour&nbsp;: Microsoft, Cisco, Apple, Linux...
EAP-TLS est présent nativement dans MAC OS 10.3 et supérieur, Windows 2000 SP4, Windows XP, Windows Mobile 2003 et supérieur, et Windows CE 4.2.
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-MD5">EAP-MD5</h4></div>
<p>EAP-MD5 est un autre standard ouvert IETF, mais il offre un niveau de sécurité faible. La fonction de hachage MD5 utilisée est vulnérable aux attaques par dictionnaire, et elle ne supporte pas les clefs WEP dynamiques.
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-TTLS">EAP-TTLS</h4></div>
<p>EAP-Tunneled Transport Layer Security, a été codéveloppé par Funk Software et Certicom&nbsp;; c'est également un standard ouvert IETF. Il est supporté sur de nombreuses plates-formes, et offre un très bon niveau de sécurité. Il utilise des certificats X-509 uniquement sur le serveur d'identification. Le certificat est optionnel du côté client.
</p><p>Le défaut de EAP-TTLS par rapport à PEAP est de ne pas être présent nativement sur les systèmes Microsoft et Cisco.
En revanche, il est légèrement plus sécurisé que PEAP car il ne diffuse pas le nom de l'utilisateur en clair.
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-FAST">EAP-FAST</h4></div>
<p>EAP-Flexible Authentication via Secure Tunneling est une proposition de Cisco Systems pour pallier les faiblesses de LEAP. L'utilisation de certificats serveur est optionnelle dans EAP-FAST. Il utilise Protected Access Credential (PAC). EAP-FAST dispose de trois phases.
</p>
<ul><li>Phase 0&nbsp;: Elle est optionnelle et permet de renseigner dynamiquement PAC. PAC peut être complété manuellement, auquel cas il n'y aura pas de phase 0.</li>
<li>Phase 1&nbsp;: Le client et le serveur <a href="Protocole_AAA" title="Protocole AAA">AAA</a> (Authentication Authorization Accounting) utilisent PAC pour établir un tunnel TLS.</li>
<li>Phase 2&nbsp;: Le client envoie les informations utilisateur à travers le tunnel.</li></ul>
<p>EAP-FAST est défini dans un brouillon Internet IETF «&nbsp;draft-com-winget-eap-fast-03&nbsp;».
</p><p>Actuellement il est proposé comme <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;4851<sup id="cite_ref-RFC-4851_20-0" class="reference"><a href="#cite_note-RFC-4851-20"><span class="cite-bracket">[</span>6<span class="cite-bracket">]</span></a></sup>.
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-SIM">EAP-SIM</h4></div>
<p>EAP-SIM est une méthode EAP pour les clients des réseaux <a href="Wi-Fi" title="Wi-Fi">Wi-Fi</a> et des <a href="R%C3%A9seaux_de_t%C3%A9l%C3%A9phonie_mobile" class="mw-redirect" title="Réseaux de téléphonie mobile">réseaux de téléphonie mobile</a> <a href="Global_System_for_Mobile_Communications" title="Global System for Mobile Communications">GSM</a>, <a href="UMTS" class="mw-redirect" title="UMTS">UMTS</a> et <a href="LTE_(r%C3%A9seaux_mobiles)" title="LTE (réseaux mobiles)">LTE</a>. Il est utilisé pour l'identification et la distribution de clefs au travers des réseaux&nbsp;; <a href="Carte_SIM" title="Carte SIM">SIM</a> signifie «&nbsp;Subscriber Identity Module&nbsp;». EAP-SIM est décrit dans la <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;4186<sup id="cite_ref-RFC-4186_21-0" class="reference"><a href="#cite_note-RFC-4186-21"><span class="cite-bracket">[</span>7<span class="cite-bracket">]</span></a></sup>.
</p><p><a href="Free_Mobile" title="Free Mobile">Free Mobile</a> a été le premier opérateur français à mettre en service ce protocole d'authentification en <time class="nowrap" datetime="2012-04" data-sort-value="2012-04">avril 2012</time> pour ses clients détenteurs du <a href="Free_Mobile#Offre_de_d.C3.A9tail" title="Free Mobile">forfait illimité</a><sup id="cite_ref-22" class="reference"><a href="#cite_note-22"><span class="cite-bracket">[</span>8<span class="cite-bracket">]</span></a></sup>. Cela permet aux abonnés d'accéder au réseau <a href="Freebox#FreeWiFi" title="Freebox">Free Wifi</a>. <a href="SFR" title="SFR">SFR</a> a activé mi-<time class="nowrap" datetime="2012-06" data-sort-value="2012-06">juin 2012</time>, sur l'ensemble de son réseau, ce service déployé depuis <time class="nowrap" datetime="2012-03" data-sort-value="2012-03">mars 2012</time>, d'abord en phase d’expérimentation limitée <sup id="cite_ref-23" class="reference"><a href="#cite_note-23"><span class="cite-bracket">[</span>9<span class="cite-bracket">]</span></a></sup>, sous le nom «&nbsp;Auto-connect&nbsp;».
</p>
<div class="mw-heading mw-heading4"><h4 id="EAP-AKA">EAP-AKA</h4></div>
<p>EAP-AKA (Authentication and Key Agreement) est une méthode EAP pour les clients des réseaux de téléphonie mobile de <abbr class="abbr" title="Troisième">3<sup>e</sup></abbr>&nbsp;génération (UMTS et CDMA2000). Elle est décrite dans la <abbr class="abbr" title="Request for comments" lang="en">RFC</abbr>&nbsp;4187<sup id="cite_ref-RFC-4187_24-0" class="reference"><a href="#cite_note-RFC-4187-24"><span class="cite-bracket">[</span>10<span class="cite-bracket">]</span></a></sup>.
</p><p>Contrairement à EAP-SIM, EAP-AKA permet de réaliser une authentification mutuelle de l'équipement utilisateur et du réseau. La longueur de la clé générée par accord mutuel est plus longue (128 bits) qu'avec EAP-SIM (64 bits)<sup id="cite_ref-25" class="reference"><a href="#cite_note-25"><span class="cite-bracket">[</span>11<span class="cite-bracket">]</span></a></sup>.
</p><p>Ce protocole est principalement employé dans les cadres suivants<sup id="cite_ref-26" class="reference"><a href="#cite_note-26"><span class="cite-bracket">[</span>12<span class="cite-bracket">]</span></a></sup>:
</p>
<ul><li>Authentification lors de l'attachement à un réseau de téléphonie mobile de <abbr class="abbr" title="Troisième">3<sup>e</sup></abbr>&nbsp;génération.</li>
<li>Réutilisation des éléments d'authentification du réseau mobile lors de l'attachement à un réseau sans fil [Wifi] qui appartient à l'opérateur.</li></ul>
<div class="mw-heading mw-heading4"><h4 id="EAP-AKA'"><span id="EAP-AKA.27"></span>EAP-AKA'</h4></div>

<div class="mw-heading mw-heading3"><h3 id="Encapsulation">Encapsulation</h3></div>

<div class="mw-heading mw-heading4"><h4 id="PEAP">PEAP</h4></div>

<p><b>Protected Extensible Authentication Protocol, Protected EAP</b>, ou plus simplement <b>PEAP</b>, est une méthode de transfert sécurisée d'informations d'identification, pour les réseaux filaires et sans fil. Ce protocole a été développé conjointement par Microsoft, RSA Security et Cisco Systems. C’est un standard ouvert de l'<a href="IETF" class="mw-redirect" title="IETF">IETF</a> (Internet Engineering Task Force).
PEAP n'est pas une méthode de chiffrement, c'est une procédure pour identifier un client sur un réseau.
</p><p>PEAP est très similaire à une autre méthode EAP&nbsp;: EAP-TTLS. Protected EAP a été créé pour contrer EAP-TTLS qui était jusque-là la seule méthode EAP à utiliser une <a href="Infrastructure_%C3%A0_cl%C3%A9s_publiques" title="Infrastructure à clés publiques">Infrastructure à clés publiques</a> (Public Key Infrastructure, PKI) <b>que</b> du côté serveur, pour la création d'un tunnel <a href="Transport_Layer_Security" title="Transport Layer Security">TLS</a> protégeant l'identification. Dans ces deux standards, l'utilisation d'une clef publique côté client est optionnelle.
</p><p>Il existe deux versions de PEAP certifiées <a href="Wi-Fi_Protected_Access" title="Wi-Fi Protected Access">WPA</a> (mise à jour) et <a href="WPA2" class="mw-redirect" title="WPA2">WPA2</a>&nbsp;:
</p>
<ul><li>PEAPv0/EAP-<a href="MS-CHAPv2" class="mw-redirect" title="MS-CHAPv2">MS-CHAPv2</a></li>
<li>PEAPv1/EAP-GTC</li></ul>
<p>PEAP se déroule en deux phases&nbsp;:
</p>
<ol><li>La phase 1 permet l'identification du serveur grâce à une Infrastructure à clés publiques. Une fois le serveur identifié, il y a la création d'un tunnel sécurisé qui permettra à la phase 2 d'être chiffrée.</li>
<li>La phase 2 permet l'identification du client au travers du tunnel chiffré.</li></ol>
<div class="mw-heading mw-heading4"><h4 id="Radius">Radius</h4></div>

<div class="mw-heading mw-heading4"><h4 id="Diameter">Diameter</h4></div>

<div class="mw-heading mw-heading3"><h3 id="Sécurité"><span id="S.C3.A9curit.C3.A9"></span>Sécurité</h3></div>

<div class="mw-heading mw-heading2"><h2 id="Notes_et_références"><span id="Notes_et_r.C3.A9f.C3.A9rences"></span>Notes et références</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Notes">Notes</h3></div>
<div class="references-small decimal" style="column-width:30em; column-count:2;"><ol class="references" data-mw-group="note">
<li id="cite_note-8"><span class="mw-cite-backlink"><a href="#cite_ref-8">↑</a> </span><span class="reference-text">que l'on pourrait traduire par&nbsp;: <i>Pair.</i></span>
</li>
<li id="cite_note-9"><span class="mw-cite-backlink"><a href="#cite_ref-9">↑</a> </span><span class="reference-text">que l'on pourrait traduire par&nbsp;: <i>Authentificateur .</i></span>
</li>
<li id="cite_note-14"><span class="mw-cite-backlink"><a href="#cite_ref-14">↑</a> </span><span class="reference-text"><i>Extensible Authentication Protocol Over LAN</i></span>
</li>
</ol>
</div>
<div class="mw-heading mw-heading3"><h3 id="Références"><span id="R.C3.A9f.C3.A9rences"></span>Références</h3></div>
<div class="mw-heading mw-heading4"><h4 id="RFC">RFC</h4></div>
<div class="references-small decimal" style="column-width:30em; column-count:2;"><ol class="references" data-mw-group="RFC">
<li id="cite_note-rfc2284_p2-4"><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc2284" class="extiw external" title="rfc:2284">RFC 2284</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;2</span>
</li>
<li id="cite_note-rfc3748_p2-5"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p2_5-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;2</span>
</li>
<li id="cite_note-rfc3748_p5-7"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p5_7-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;5</span>
</li>
<li id="cite_note-rfc2284_p6-7-10"><span class="mw-cite-backlink"><a href="#cite_ref-rfc2284_p6-7_10-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc2284" class="extiw external" title="rfc:2284">RFC 2284</a> <abbr class="abbr" title="pages">p.</abbr>&nbsp;<span class="nowrap">6-7</span></span>
</li>
<li id="cite_note-rfc2284_p2-3-11"><span class="mw-cite-backlink"><a href="#cite_ref-rfc2284_p2-3_11-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc2284" class="extiw external" title="rfc:2284">RFC 2284</a> <abbr class="abbr" title="pages">p.</abbr>&nbsp;<span class="nowrap">2-3</span></span>
</li>
<li id="cite_note-rfc3748_p3-13"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p3_13-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;3</span>
</li>
<li id="cite_note-rfc3748_p54-15"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p54_15-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;54</span>
</li>
<li id="cite_note-rfc3748_p15-16-16"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p15-16_16-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="pages">p.</abbr>&nbsp;<span class="nowrap">15-16</span></span>
</li>
<li id="cite_note-rfc3748_p16-17"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p16_17-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;16</span>
</li>
<li id="cite_note-rfc3748_p16-17-18"><span class="mw-cite-backlink"><a href="#cite_ref-rfc3748_p16-17_18-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a> <abbr class="abbr" title="pages">p.</abbr>&nbsp;<span class="nowrap">16-17</span></span>
</li>
<li id="cite_note-rfc5216_p14-19"><span class="mw-cite-backlink"><a href="#cite_ref-rfc5216_p14_19-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc5216" class="extiw external" title="rfc:5216">RFC 5216</a> <abbr class="abbr" title="page">p.</abbr>&nbsp;14</span>
</li>
</ol>
</div>
<div class="mw-heading mw-heading4"><h4 id="Autres">Autres</h4></div>
<div class="references-small decimal" style="column-width:30em; column-count:2;"><ol class="references">
<li id="cite_note-RFC-2284-a-t-d-1"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-2284-a-t-d_1-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> L. Blunk et J. Vollbrecht, «&nbsp;<a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc2284"><span class="lang-en" lang="en">PPP Extensible Authentication Protocol (EAP)</span></a>&nbsp;», <span class="lang-en" lang="en"><a href="Request_for_comments" title="Request for comments">Request for comments</a></span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;2284, <time class="nowrap" datetime="1998-03" data-sort-value="1998-03">mars 1998</time>
</span>
</li>
<li id="cite_note-RFC-3748-a-t-d-2"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-3748-a-t-d_2-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> B. Aboba, L. Blunk, J. Vollbrecht, J. Carlson, H. Levkowetz, Ed., «&nbsp;<a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc3748"><span class="lang-en" lang="en">Extensible Authentication Protocol (EAP)</span></a>&nbsp;», <span class="lang-en" lang="en"><a href="Request_for_comments" title="Request for comments">Request for comments</a></span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;3748, <time class="nowrap" datetime="2004-06" data-sort-value="2004-06">juin 2004</time>
</span>
</li>
<li id="cite_note-RFC-5247-a-t-d-3"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-5247-a-t-d_3-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> B. Aboba, D. Simon, P. Eronen, «&nbsp;<a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc5247"><span class="lang-en" lang="en">Extensible Authentication Protocol (EAP) Key Management Framework</span></a>&nbsp;», <span class="lang-en" lang="en"><a href="Request_for_comments" title="Request for comments">Request for comments</a></span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;5247, <time class="nowrap" datetime="2008-08" data-sort-value="2008-08">août 2008</time>
</span>
</li>
<li id="cite_note-RFC-2284-6"><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc2284"><span class="lang-en" lang="en">Request for comments</span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;2284</a>
</span>
</li>
<li id="cite_note-RFC-3748-12"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-3748_12-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc3748"><span class="lang-en" lang="en">Request for comments</span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;3748</a>
</span>
</li>
<li id="cite_note-RFC-4851-20"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-4851_20-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc4851"><span class="lang-en" lang="en">Request for comments</span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;4851</a>
</span>
</li>
<li id="cite_note-RFC-4186-21"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-4186_21-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc4186"><span class="lang-en" lang="en">Request for comments</span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;4186</a>
</span>
</li>
<li id="cite_note-22"><span class="mw-cite-backlink"><a href="#cite_ref-22">↑</a> </span><span class="reference-text"><span class="ouvrage">«&nbsp;<a rel="nofollow" class="external text" href="http://www.freemobileasso.com/articles/646-free-mobile-active-l-eap-sim-permettant-d-acces-automatique-au-free-wifi"><cite style="font-style:normal;">Article d'annonce de l'activation de l'EAP-SIM chez Free</cite></a>&nbsp;» <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2012-04-19" data-sort-value="2012-04-19">19 avril 2012</time>)</small></span></span>
</li>
<li id="cite_note-23"><span class="mw-cite-backlink"><a href="#cite_ref-23">↑</a> </span><span class="reference-text"><span class="ouvrage">«&nbsp;<a rel="nofollow" class="external text" href="http://www.pcworld.fr/2012/04/20/high-tech/telephonie-voip/eap-sim-sfr-etait-avant-free-mobile-veut-faire-savoir/527029/"><cite style="font-style:normal;">EAP-SIM&nbsp;: SFR était là avant Free Mobile, et veut le faire savoir&nbsp;!</cite></a>&nbsp;» <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2012-04-19" data-sort-value="2012-04-19">19 avril 2012</time>)</small></span></span>
</li>
<li id="cite_note-RFC-4187-24"><span class="mw-cite-backlink"><a href="#cite_ref-RFC-4187_24-0">↑</a> </span><span class="reference-text"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a rel="nofollow" class="external text" href="https://tools.ietf.org/html/rfc4187"><span class="lang-en" lang="en">Request for comments</span> <abbr class="abbr" title="numéro">n<sup>o</sup></abbr>&nbsp;4187</a>
</span>
</li>
<li id="cite_note-25"><span class="mw-cite-backlink"><a href="#cite_ref-25">↑</a> </span><span class="reference-text"><span class="ouvrage"><span class="noarchive">«&nbsp;<a rel="nofollow" class="external text" href="http://www.cse.wustl.edu/~jain/cse571-07/ftp/l_18aaa/sld001.htm"><cite style="font-style:normal;">Authentication, Authorization, Accounting (AAA)</cite></a>&nbsp;» <small class=" cachelinks">[<a rel="nofollow" class="external text" href="https://web.archive.org/web/20080906001547/http://www.cse.wustl.edu/%7ejain/cse571-07/ftp/l_18aaa/sld001.htm">archive du <time class="nowrap" datetime="2008-09-06" data-sort-value="2008-09-06">6 septembre 2008</time></a>]</small></span> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2013-05-16" data-sort-value="2013-05-16">16 mai 2013</time>)</small></span>, diapositives 29 à 32. Consulté le 16 mai 2013.</span>
</li>
<li id="cite_note-26"><span class="mw-cite-backlink"><a href="#cite_ref-26">↑</a> </span><span class="reference-text"><a href="https://datatracker.ietf.org/doc/html/rfc4187" class="extiw external" title="rfc:4187">RFC 4187</a>, §1: Introduction and Motivation. Consulté le 16 mai 2013.</span>
</li>
</ol>
</div>
<div class="mw-heading mw-heading2"><h2 id="Bibliographie">Bibliographie</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Articles">Articles</h3></div>
<div class="mw-heading mw-heading3"><h3 id="Ouvrages">Ouvrages</h3></div>
<div class="mw-heading mw-heading2"><h2 id="Voir_aussi">Voir aussi</h2></div>
<div class="mw-heading mw-heading3"><h3 id="Articles_connexes">Articles connexes</h3></div>
<ul><li><a href="IEEE_802.1X" title="IEEE 802.1X">IEEE 802.1X</a></li>
<li><a href="IEEE_802.11i" title="IEEE 802.11i">IEEE 802.11i</a></li>
<li><a href="Authentification" title="Authentification">Authentification</a></li>
<li><a href="Serveur_d'authentification" title="Serveur d'authentification">Serveur d'authentification</a></li>
<li><a href="Protected_Extensible_Authentication_Protocol" title="Protected Extensible Authentication Protocol">Protected Extensible Authentication Protocol</a></li>
<li><a href="Protocole_AAA" title="Protocole AAA">Protocole AAA</a></li>
<li><a href="Remote_Authentication_Dial-In_User_Service" title="Remote Authentication Dial-In User Service">Remote Authentication Dial-In User Service</a></li>
<li><a href="FreeRADIUS" title="FreeRADIUS">FreeRADIUS</a></li>
<li><a href="Diameter" title="Diameter">Diameter</a></li>
<li><a href="Wi-Fi_Protected_Access" title="Wi-Fi Protected Access">Wi-Fi Protected Access</a></li>
<li><a href="Wpa_supplicant" title="Wpa supplicant">wpa_supplicant</a></li></ul>
<div class="mw-heading mw-heading3"><h3 id="Liens_externes">Liens externes</h3></div>
<ul><li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc2284" class="extiw external" title="rfc:2284">RFC 2284</a>&nbsp;: (Obsolète) PPP Extensible Authentication Protocol (EAP)</li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3748" class="extiw external" title="rfc:3748">RFC 3748</a>&nbsp;: Extensible Authentication Protocol (EAP)</li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc3579" class="extiw external" title="rfc:3579">RFC 3579</a>&nbsp;: RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)</li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <a href="https://datatracker.ietf.org/doc/html/rfc4017" class="extiw external" title="rfc:4017">RFC 4017</a>&nbsp;: EAP Method Requirements for Wireless LANs</li>
<li><span class="ouvrage" id="FreeradiusEapProtocol"><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> «&nbsp;<a rel="nofollow" class="external text" href="http://wiki.freeradius.org/protocol/EAP"><cite style="font-style:normal;" lang="en">protocol/EAP</cite></a>&nbsp;», sur <span class="italique">freeradius.org</span> <small style="line-height:1em;">(consulté le <time class="nowrap" datetime="2015-03-25" data-sort-value="2015-03-25">25 mars 2015</time>)</small></span></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage" id="Radius802.1xWirelessLan">«&nbsp;<a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/ultimate-wireless-security-guide-microsoft-ias-radius-for-wireless-authentication/6148579"><cite style="font-style:normal;">Configure RADIUS for secure 802.1x wireless LAN</cite></a>&nbsp;», sur <span class="italique">techrepublic.com</span></span></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage" id="SelfSignRadiusPEAP-TTLS">«&nbsp;<a rel="nofollow" class="external text" href="https://www.techrepublic.com/article/ultimate-wireless-security-guide-self-signed-certificates-for-your-radius-server/6148560"><cite style="font-style:normal;">How to self-sign a RADIUS server for secure PEAP or EAP-TTLS authentication</cite></a>&nbsp;», sur <span class="italique">techrepublic.com</span></span></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage" id="MicrosoftTechnetEAP">«&nbsp;<a rel="nofollow" class="external text" href="https://technet.microsoft.com/en-us/network/bb643147.aspx"><cite style="font-style:normal;">Extensible Authentication Protocol</cite></a>&nbsp;», sur <span class="italique">technet.microsoft.com</span></span></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage" id="Wire1x">«&nbsp;<a rel="nofollow" class="external text" href="http://wire.cs.nctu.edu.tw/wire1x/"><cite style="font-style:normal;">WIRE1x</cite></a>&nbsp;», sur <span class="italique">wire.cs.nctu.edu.tw</span></span></li>
<li><abbr class="abbr indicateur-langue" title="Langue : anglais">(en)</abbr> <span class="ouvrage" id="IetfEapMethod">«&nbsp;<a rel="nofollow" class="external text" href="http://www.ietf.org/html.charters/emu-charter.html"><cite style="font-style:normal;">IETF EAP Method Update (emu) Working Group</cite></a>&nbsp;», sur <span class="italique">ietf.org</span></span></li></ul>
<ul id="bandeau-portail" class="bandeau-portail"><li><span class="bandeau-portail-element"><span class="bandeau-portail-icone"><span class="noviewer" typeof="mw:File"></span></span> <span class="bandeau-portail-texte">Portail de la cryptologie</span> </span></li> <li><span class="bandeau-portail-element"><span class="bandeau-portail-icone"><span class="noviewer" typeof="mw:File"></span></span> <span class="bandeau-portail-texte">Portail de la sécurité des systèmes d'information</span> </span></li> <li><span class="bandeau-portail-element"><span class="bandeau-portail-icone"><span class="noviewer" typeof="mw:File"></span></span> <span class="bandeau-portail-texte">Portail des télécommunications</span> </span></li> </ul></div><!--htdig_noindex--><div><div class="zim-footer">
Cet article est issu de <a class="external text" title="Dernière modification le 2024-12-19" href="https://fr.wikipedia.org/wiki/?title=Extensible_Authentication_Protocol&amp;oldid=221283442">Wikipédia</a>. Sauf mention contraire, le texte est disponible sous <a class="external text" href="https://creativecommons.org/licenses/by-sa/4.0/deed.fr">Creative Commons Attribution-Share Alike 4.0</a>. Des conditions supplémentaires peuvent s’appliquer aux fichiers multimédias.
</div>
</div><!--/htdig_noindex--></div>
</div>
</main>
</div>
</div>
</div>
<script src="./_webp_/webpHandler.js"></script>

</body></html>