ietf-corpus

rfc-7360

Datagram Transport Layer Security (DTLS) as a Transport Layer for RADIUS

A. DeKok
date2014-09 streamIETF areasec wgradext statusEXPERIMENTAL pages27 canonicalhttps://www.rfc-editor.org/rfc/rfc7360 doi10.17487/RFC7360
The RADIUS protocol defined in RFC 2865 has limited support for authentication and encryption of RADIUS packets. The protocol transports data in the clear, although some parts of the packets can have obfuscated content. Packets may be replayed verbatim by an attacker, and client-server authentication is based on fixed shared secrets. This document specifies how the Datagram Transport Layer Security (DTLS) protocol may be used as a fix for these problems. It also describes how implementations of this proposal can coexist with current RADIUS systems.

updated by