AAA
AAA (Authentication, Authorization, and Accounting) frameworks
Within this page
AAA RFCs (28)
RFC 7241: The IEEE 802/IETF Relationship
Informational- S. Dawkins
- P. Thaler
- D. Romascanu
- B. Aboba
- July 2014
- IAB publication
Abstract
This document describes the standardization cooperation between Project 802 of the Institute of Electrical and Electronics Engineers (IEEE) and the Internet Engineering Task Force (IETF). This document obsoletes RFC 4441.
Note: This document was collaboratively developed by authors from both the IEEE 802 and IETF leadership and was reviewed and approved by the IEEE 802 Executive Committee prior to publication.
Abstract
This document describes the standardization cooperation between Project 802 of the Institute of Electrical and Electronics Engineers (IEEE) and the Internet Engineering Task Force (IETF). This document obsoletes RFC 4441.
Note: This document was collaboratively developed by authors from both the IEEE 802 and IETF leadership and was reviewed and approved by the IEEE 802 Executive Committee prior to publication.
RFC 7057: Update to the Extensible Authentication Protocol (EAP) Applicability Statement for Application Bridging for Federated Access Beyond Web (ABFAB)
Proposed Standard- S. Winter
- J. Salowey
- December 2013
- IETF publication
- Security Area
Abstract
This document updates the Extensible Authentication Protocol (EAP) applicability statement from RFC 3748 to reflect recent usage of the EAP protocol in the Application Bridging for Federated Access Beyond web (ABFAB) architecture.
Abstract
This document updates the Extensible Authentication Protocol (EAP) applicability statement from RFC 3748 to reflect recent usage of the EAP protocol in the Application Bridging for Federated Access Beyond web (ABFAB) architecture.
RFC 6840: Clarifications and Implementation Notes for DNS Security (DNSSEC)
Proposed Standard- S. Weiler
- D. Blacka
- February 2013
- IETF publication
- Internet Area
Abstract
This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.
This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.
Abstract
This document is a collection of technical clarifications to the DNS Security (DNSSEC) document set. It is meant to serve as a resource to implementors as well as a collection of DNSSEC errata that existed at the time of writing.
This document updates the core DNSSEC documents (RFC 4033, RFC 4034, and RFC 4035) as well as the NSEC3 specification (RFC 5155). It also defines NSEC3 and SHA-2 (RFC 4509 and RFC 5702) as core parts of the DNSSEC specification.
RFC 6097: Local Mobility Anchor (LMA) Discovery for Proxy Mobile IPv6
Informational- J. Korhonen
- V. Devarapalli
- February 2011
- IETF publication
- Internet Area
Abstract
Large Proxy Mobile IPv6 deployments would benefit from a functionality where a Mobile Access Gateway could dynamically discover a Local Mobility Anchor for a Mobile Node attaching to a Proxy Mobile IPv6 domain. The purpose of the dynamic discovery functionality is to reduce the amount of static configuration in the Mobile Access Gateway. This document describes several possible dynamic Local Mobility Anchor discovery solutions. This document is not an Internet Standards Track specification; it is published for informational purposes.
Abstract
Large Proxy Mobile IPv6 deployments would benefit from a functionality where a Mobile Access Gateway could dynamically discover a Local Mobility Anchor for a Mobile Node attaching to a Proxy Mobile IPv6 domain. The purpose of the dynamic discovery functionality is to reduce the amount of static configuration in the Mobile Access Gateway. This document describes several possible dynamic Local Mobility Anchor discovery solutions. This document is not an Internet Standards Track specification; it is published for informational purposes.
RFC 5998: An Extension for EAP-Only Authentication in IKEv2
Proposed Standard- P. Eronen
- H. Tschofenig
- Y. Sheffer
- September 2010
- IETF publication
- Security Area
Abstract
IKEv2 specifies that Extensible Authentication Protocol (EAP) authentication must be used together with responder authentication based on public key signatures. This is necessary with old EAP methods that provide only unilateral authentication using, e.g., one- time passwords or token cards.
This document specifies how EAP methods that provide mutual authentication and key agreement can be used to provide extensible responder authentication for IKEv2 based on methods other than public key signatures. [STANDARDS-TRACK]
Abstract
IKEv2 specifies that Extensible Authentication Protocol (EAP) authentication must be used together with responder authentication based on public key signatures. This is necessary with old EAP methods that provide only unilateral authentication using, e.g., one- time passwords or token cards.
This document specifies how EAP methods that provide mutual authentication and key agreement can be used to provide extensible responder authentication for IKEv2 based on methods other than public key signatures. [STANDARDS-TRACK]
RFC 5637: Authentication, Authorization, and Accounting (AAA) Goals for Mobile IPv6
Informational- G. Giaretta
- I. Guardini
- E. Demaria
- J. Bournelle
- R. Lopez
- September 2009
- IETF publication
- Internet Area
Abstract
In commercial and enterprise deployments, Mobile IPv6 can be a service offered by a Mobility Services Provider (MSP). In this case, all protocol operations may need to be explicitly authorized and traced, requiring the interaction between Mobile IPv6 and the AAA infrastructure. Integrating the Authentication, Authorization, and Accounting (AAA) infrastructure (e.g., Network Access Server and AAA server) also offers a solution component for Mobile IPv6 bootstrapping. This document describes various scenarios where a AAA interface for Mobile IPv6 is required. Additionally, it lists design goals and requirements for such an interface. This memo provides information for the Internet community.
Abstract
In commercial and enterprise deployments, Mobile IPv6 can be a service offered by a Mobility Services Provider (MSP). In this case, all protocol operations may need to be explicitly authorized and traced, requiring the interaction between Mobile IPv6 and the AAA infrastructure. Integrating the Authentication, Authorization, and Accounting (AAA) infrastructure (e.g., Network Access Server and AAA server) also offers a solution component for Mobile IPv6 bootstrapping. This document describes various scenarios where a AAA interface for Mobile IPv6 is required. Additionally, it lists design goals and requirements for such an interface. This memo provides information for the Internet community.
RFC 5472: IP Flow Information Export (IPFIX) Applicability
Informational- T. Zseby
- E. Boschi
- N. Brownlee
- B. Claise
- March 2009
- IETF publication
- Operations and Management Area
Abstract
In this document, we describe the applicability of the IP Flow Information eXport (IPFIX) protocol for a variety of applications. We show how applications can use IPFIX, describe the relevant Information Elements (IEs) for those applications, and present opportunities and limitations of the protocol. Furthermore, we describe relations of the IPFIX framework to other architectures and frameworks. This memo provides information for the Internet community.
Abstract
In this document, we describe the applicability of the IP Flow Information eXport (IPFIX) protocol for a variety of applications. We show how applications can use IPFIX, describe the relevant Information Elements (IEs) for those applications, and present opportunities and limitations of the protocol. Furthermore, we describe relations of the IPFIX framework to other architectures and frameworks. This memo provides information for the Internet community.
RFC 5281: Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)
Informational- P. Funk
- S. Blake-Wilson
- August 2008
- IETF publication
Abstract
EAP-TTLS is an EAP (Extensible Authentication Protocol) method that encapsulates a TLS (Transport Layer Security) session, consisting of a handshake phase and a data phase. During the handshake phase, the server is authenticated to the client (or client and server are mutually authenticated) using standard TLS procedures, and keying material is generated in order to create a cryptographically secure tunnel for information exchange in the subsequent data phase. During the data phase, the client is authenticated to the server (or client and server are mutually authenticated) using an arbitrary authentication mechanism encapsulated within the secure tunnel. The encapsulated authentication mechanism may itself be EAP, or it may be another authentication protocol such as PAP, CHAP, MS-CHAP, or MS-CHAP-V2. Thus, EAP-TTLS allows legacy password-based authentication protocols to be used against existing authentication databases, while protecting the security of these legacy protocols against eavesdropping, man-in-the-middle, and other attacks. The data phase may also be used for additional, arbitrary data exchange. This memo provides information for the Internet community.
Abstract
EAP-TTLS is an EAP (Extensible Authentication Protocol) method that encapsulates a TLS (Transport Layer Security) session, consisting of a handshake phase and a data phase. During the handshake phase, the server is authenticated to the client (or client and server are mutually authenticated) using standard TLS procedures, and keying material is generated in order to create a cryptographically secure tunnel for information exchange in the subsequent data phase. During the data phase, the client is authenticated to the server (or client and server are mutually authenticated) using an arbitrary authentication mechanism encapsulated within the secure tunnel. The encapsulated authentication mechanism may itself be EAP, or it may be another authentication protocol such as PAP, CHAP, MS-CHAP, or MS-CHAP-V2. Thus, EAP-TTLS allows legacy password-based authentication protocols to be used against existing authentication databases, while protecting the security of these legacy protocols against eavesdropping, man-in-the-middle, and other attacks. The data phase may also be used for additional, arbitrary data exchange. This memo provides information for the Internet community.
RFC 4962: BCP 132: Guidance for Authentication, Authorization, and Accounting (AAA) Key Management
Best Current Practice- R. Housley
- B. Aboba
- July 2007
- IETF publication
Abstract
This document provides guidance to designers of Authentication, Authorization, and Accounting (AAA) key management protocols. The guidance is also useful to designers of systems and solutions that include AAA key management protocols. Given the complexity and difficulty in designing secure, long-lasting key management algorithms and protocols by experts in the field, it is almost certainly inappropriate for IETF working groups without deep expertise in the area to be designing their own key management algorithms and protocols based on Authentication, Authorization, and Accounting (AAA) protocols. The guidelines in this document apply to documents requesting publication as IETF RFCs. Further, these guidelines will be useful to other standards development organizations (SDOs) that specify AAA key management. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
Abstract
This document provides guidance to designers of Authentication, Authorization, and Accounting (AAA) key management protocols. The guidance is also useful to designers of systems and solutions that include AAA key management protocols. Given the complexity and difficulty in designing secure, long-lasting key management algorithms and protocols by experts in the field, it is almost certainly inappropriate for IETF working groups without deep expertise in the area to be designing their own key management algorithms and protocols based on Authentication, Authorization, and Accounting (AAA) protocols. The guidelines in this document apply to documents requesting publication as IETF RFCs. Further, these guidelines will be useful to other standards development organizations (SDOs) that specify AAA key management. This document specifies an Internet Best Current Practices for the Internet Community, and requests discussion and suggestions for improvements.
RFC 4441: The IEEE 802/IETF Relationship
Informational- B. Aboba
- March 2006
- IAB publication
Abstract
Since the late 1980s, IEEE 802 and IETF have cooperated in the development of Simple Network Management Protocol (SNMP) MIBs and Authentication, Authorization, and Accounting (AAA) applications. This document describes the policies and procedures that have developed in order to coordinate between the two organizations, as well as some of the relationship history. This memo provides information for the Internet community.
Obsoleted by RFC 7241
Abstract
Since the late 1980s, IEEE 802 and IETF have cooperated in the development of Simple Network Management Protocol (SNMP) MIBs and Authentication, Authorization, and Accounting (AAA) applications. This document describes the policies and procedures that have developed in order to coordinate between the two organizations, as well as some of the relationship history. This memo provides information for the Internet community.
RFC 3957: Authentication, Authorization, and Accounting (AAA) Registration Keys for Mobile IPv4
Proposed Standard- C. Perkins
- P. Calhoun
- March 2005
- IETF publication
- Internet Area
Abstract
Authentication, Authorization, and Accounting (AAA) servers, such as RADIUS and DIAMETER, are in use within the Internet today to provide authentication and authorization services for dial-up computers. Mobile IP for IPv4 requires strong authentication between the mobile node and its home agent. When the mobile node shares an AAA Security Association with its home AAA server, however, it is possible to use that AAA Security Association to create derived Mobility Security Associations between the mobile node and its home agent, and again between the mobile node and the foreign agent currently offering connectivity to the mobile node. This document specifies extensions to Mobile IP registration messages that can be used to create Mobility Security Associations between the mobile node and its home agent, and/or between the mobile node and a foreign agent. [STANDARDS-TRACK]
Abstract
Authentication, Authorization, and Accounting (AAA) servers, such as RADIUS and DIAMETER, are in use within the Internet today to provide authentication and authorization services for dial-up computers. Mobile IP for IPv4 requires strong authentication between the mobile node and its home agent. When the mobile node shares an AAA Security Association with its home AAA server, however, it is possible to use that AAA Security Association to create derived Mobility Security Associations between the mobile node and its home agent, and again between the mobile node and the foreign agent currently offering connectivity to the mobile node. This document specifies extensions to Mobile IP registration messages that can be used to create Mobility Security Associations between the mobile node and its home agent, and/or between the mobile node and a foreign agent. [STANDARDS-TRACK]
RFC 3846: Mobile IPv4 Extension for Carrying Network Access Identifiers
Proposed Standard- F. Johansson
- T. Johansson
- June 2004
- IETF publication
- Internet Area
Abstract
When a mobile node moves between two foreign networks, it has to be re-authenticated. If the home network has both multiple Authentication Authorization and Accounting (AAA) servers and Home Agents (HAs) in use, the Home AAA server may not have sufficient information to process the re-authentication correctly (i.e., to ensure that the same HA continues to be used). This document defines a Mobile IP extension that carries identities for the Home AAA and HA servers in the form of Network Access Identifiers (NAIs). The extension allows a Home Agent to pass its identity (and that of the Home AAA server) to the mobile node, which can then pass it on to the local AAA server when changing its point of attachment. This extension may also be used in other situations requiring communication of a NAI between Mobile IP nodes. [STANDARDS-TRACK]
Abstract
When a mobile node moves between two foreign networks, it has to be re-authenticated. If the home network has both multiple Authentication Authorization and Accounting (AAA) servers and Home Agents (HAs) in use, the Home AAA server may not have sufficient information to process the re-authentication correctly (i.e., to ensure that the same HA continues to be used). This document defines a Mobile IP extension that carries identities for the Home AAA and HA servers in the form of Network Access Identifiers (NAIs). The extension allows a Home Agent to pass its identity (and that of the Home AAA server) to the mobile node, which can then pass it on to the local AAA server when changing its point of attachment. This extension may also be used in other situations requiring communication of a NAI between Mobile IP nodes. [STANDARDS-TRACK]
RFC 3702: Authentication, Authorization, and Accounting Requirements for the Session Initiation Protocol (SIP)
Informational- J. Loughney
- G. Camarillo
- February 2004
- IETF publication
- Real-time Applications and Infrastructure Area
Abstract
As Session Initiation Protocol (SIP) services are deployed on the Internet, there is a need for authentication, authorization, and accounting of SIP sessions. This document sets out the basic requirements for this work. This memo provides information for the Internet community.
Abstract
As Session Initiation Protocol (SIP) services are deployed on the Internet, there is a need for authentication, authorization, and accounting of SIP sessions. This document sets out the basic requirements for this work. This memo provides information for the Internet community.
RFC 3539: Authentication, Authorization and Accounting (AAA) Transport Profile
Proposed Standard- B. Aboba
- J. Wood
- June 2003
- IETF publication
- Operations and Management Area
Abstract
This document discusses transport issues that arise within protocols for Authentication, Authorization and Accounting (AAA). It also provides recommendations on the use of transport by AAA protocols. This includes usage of standards-track RFCs as well as experimental proposals. [STANDARDS-TRACK]
Abstract
This document discusses transport issues that arise within protocols for Authentication, Authorization and Accounting (AAA). It also provides recommendations on the use of transport by AAA protocols. This includes usage of standards-track RFCs as well as experimental proposals. [STANDARDS-TRACK]
RFC 3334: Policy-Based Accounting
Experimental- T. Zseby
- S. Zander
- C. Carle
- October 2002
- Legacy publication
Abstract
This document describes policy-based accounting which is an approach
to provide flexibility to accounting architectures. Accounting
policies describe the configuration of an accounting architecture in
a standardized way. They are used to instrument the accounting
architecture and can be exchanged between AAA entities in order to
share configuration information.
This document describes building blocks and message sequences for
policy-based accounting in the generic AAA architecture [RFC2903].
Examples are given for the usage of accounting policies in different
scenarios. Furthermore it is shown how accounting components can be
integrated into the AAA authorization framework [RFC2904]. This
document does not propose a language for the description of
accounting policies. It is rather assumed that a suitable policy
language can be chosen from existing or upcoming standards.
Abstract
This document describes policy-based accounting which is an approach
to provide flexibility to accounting architectures. Accounting
policies describe the configuration of an accounting architecture in
a standardized way. They are used to instrument the accounting
architecture and can be exchanged between AAA entities in order to
share configuration information.
This document describes building blocks and message sequences for
policy-based accounting in the generic AAA architecture [RFC2903].
Examples are given for the usage of accounting policies in different
scenarios. Furthermore it is shown how accounting components can be
integrated into the AAA authorization framework [RFC2904]. This
document does not propose a language for the description of
accounting policies. It is rather assumed that a suitable policy
language can be chosen from existing or upcoming standards.
RFC 3374: Problem Description: Reasons For Performing Context Transfers Between Nodes in an IP Access Network
Informational- J. Kempf
- September 2002
- IETF publication
- Transport Area
Abstract
In IP access networks that support host mobility, the routing paths
between the host and the network may change frequently and rapidly.
In some cases, the host may establish certain routing-related
services on subnets that are left behind when the host moves.
Examples of such services are AAA, header compression, and QoS. In
order for the host to obtain those services on the new subnet, the
host must explicitly re-establish the service by performing the
necessary signaling flows from scratch. In some cases, this process
would considerably slow the process of establishing the mobile host
on the new subnet. An alternative is to transfer information on the
existing state associated with these services, or context, to the
new subnet, a process called 'context transfer'. This document
discusses the desirability of context transfer for facilitating
seamless IP mobility.
Abstract
In IP access networks that support host mobility, the routing paths
between the host and the network may change frequently and rapidly.
In some cases, the host may establish certain routing-related
services on subnets that are left behind when the host moves.
Examples of such services are AAA, header compression, and QoS. In
order for the host to obtain those services on the new subnet, the
host must explicitly re-establish the service by performing the
necessary signaling flows from scratch. In some cases, this process
would considerably slow the process of establishing the mobile host
on the new subnet. An alternative is to transfer information on the
existing state associated with these services, or context, to the
new subnet, a process called 'context transfer'. This document
discusses the desirability of context transfer for facilitating
seamless IP mobility.
RFC 3127: Authentication, Authorization, and Accounting: Protocol Evaluation
Informational- D. Mitton
- M. St.Johns
- S. Barkley
- D. Nelson
- B. Patil
- M. Stevens
- B. Wolff
- June 2001
- IETF publication
- Operations and Management Area
Abstract
This memo represents the process and findings of the Authentication, Authorization, and Accounting Working Group (AAA WG) panel evaluating protocols proposed against the AAA Network Access Requirements, RFC 2989. This memo provides information for the Internet community.
Abstract
This memo represents the process and findings of the Authentication, Authorization, and Accounting Working Group (AAA WG) panel evaluating protocols proposed against the AAA Network Access Requirements, RFC 2989. This memo provides information for the Internet community.
RFC 3141: CDMA2000 Wireless Data Requirements for AAA
Informational- T. Hiller
- P. Walsh
- X. Chen
- M. Munson
- G. Dommety
- S. Sivalingham
- B. Lim
- P. McCann
- H. Shiino
- B. Hirschman
- S. Manning
- R. Hsu
- H. Koo
- M. Lipford
- P. Calhoun
- C. Lo
- E. Jaques
- E. Campbell
- Y. Xu
- S. Baba
- T. Ayaki
- T. Seki
- A. Hameed
- June 2001
- Legacy publication
Abstract
This memo specifies cdma2000 wireless data AAA (Authentication, Authorization, Accounting) requirements associated with third generation wireless architecture that supports roaming among service providers for traditional PPP and Mobile IP services. This memo provides information for the Internet community.
Abstract
This memo specifies cdma2000 wireless data AAA (Authentication, Authorization, Accounting) requirements associated with third generation wireless architecture that supports roaming among service providers for traditional PPP and Mobile IP services. This memo provides information for the Internet community.
RFC 2989: Criteria for Evaluating AAA Protocols for Network Access
Informational- B. Aboba
- P. Calhoun
- S. Glass
- T. Hiller
- P. McCann
- H. Shiino
- P. Walsh
- G. Zorn
- G. Dommety
- C. Perkins
- B. Patil
- D. Mitton
- S. Manning
- M. Beadles
- X. Chen
- S. Sivalingham
- A. Hameed
- M. Munson
- S. Jacobs
- B. Lim
- B. Hirschman
- R. Hsu
- H. Koo
- M. Lipford
- E. Campbell
- Y. Xu
- S. Baba
- E. Jaques
- November 2000
- IETF publication
- Operations and Management Area
Abstract
This document represents a summary of Authentication, Authorization, Accounting (AAA) protocol requirements for network access. This memo provides information for the Internet community.
Abstract
This document represents a summary of Authentication, Authorization, Accounting (AAA) protocol requirements for network access. This memo provides information for the Internet community.
RFC 2975: Introduction to Accounting Management
Informational- B. Aboba
- J. Arkko
- D. Harrington
- October 2000
- IETF publication
- Operations and Management Area
Abstract
This document describes and discusses the issues involved in the design of the modern accounting systems. The field of Accounting Management is concerned with the collection the collection of resource consumption data for the purposes of capacity and trend analysis, cost allocation, auditing, and billing. This memo provides information for the Internet community.
Abstract
This document describes and discusses the issues involved in the design of the modern accounting systems. The field of Accounting Management is concerned with the collection the collection of resource consumption data for the purposes of capacity and trend analysis, cost allocation, auditing, and billing. This memo provides information for the Internet community.
RFC 2977: Mobile IP Authentication, Authorization, and Accounting Requirements
Informational- S. Glass
- T. Hiller
- S. Jacobs
- C. Perkins
- October 2000
- IETF publication
- Internet Area
Abstract
This document contains the requirements which would have to be supported by a AAA service to aid in providing Mobile IP services. This memo provides information for the Internet community.
Abstract
This document contains the requirements which would have to be supported by a AAA service to aid in providing Mobile IP services. This memo provides information for the Internet community.
RFC 2924: Accounting Attributes and Record Formats
Informational- N. Brownlee
- A. Blount
- September 2000
- IETF publication
- Operations and Management Area
Abstract
This document summarises Internet Engineering Task Force (IETF) and International Telecommunication Union (ITU-T) documents related to Accounting. This memo provides information for the Internet community.
Abstract
This document summarises Internet Engineering Task Force (IETF) and International Telecommunication Union (ITU-T) documents related to Accounting. This memo provides information for the Internet community.
RFC 2903: Generic AAA Architecture
Experimental- C. de Laat
- G. Gross
- L. Gommans
- J. Vollbrecht
- D. Spence
- August 2000
- Legacy publication
Abstract
This memo proposes an Authentication, Authorization, Accounting (AAA) architecture that would incorporate a generic AAA server along with an application interface to a set of Application Specific Modules that could perform application specific AAA functions. This memo defines an Experimental Protocol for the Internet community.
Abstract
This memo proposes an Authentication, Authorization, Accounting (AAA) architecture that would incorporate a generic AAA server along with an application interface to a set of Application Specific Modules that could perform application specific AAA functions. This memo defines an Experimental Protocol for the Internet community.
RFC 2904: AAA Authorization Framework
Informational- J. Vollbrecht
- P. Calhoun
- S. Farrell
- L. Gommans
- G. Gross
- B. de Bruijn
- C. de Laat
- M. Holdrege
- D. Spence
- August 2000
- Legacy publication
Abstract
This memo serves as the base requirements for Authorization of Internet Resources and Services (AIRS). It presents an architectural framework for understanding the authorization of Internet resources and services and derives requirements for authorization protocols. This memo provides information for the Internet community.
Abstract
This memo serves as the base requirements for Authorization of Internet Resources and Services (AIRS). It presents an architectural framework for understanding the authorization of Internet resources and services and derives requirements for authorization protocols. This memo provides information for the Internet community.
RFC 2905: AAA Authorization Application Examples
Informational- J. Vollbrecht
- P. Calhoun
- S. Farrell
- L. Gommans
- G. Gross
- B. de Bruijn
- C. de Laat
- M. Holdrege
- D. Spence
- August 2000
- Legacy publication
Abstract
This memo describes several examples of applications requiring authorization. This memo provides information for the Internet community.
Abstract
This memo describes several examples of applications requiring authorization. This memo provides information for the Internet community.
RFC 2906: AAA Authorization Requirements
Informational- S. Farrell
- J. Vollbrecht
- P. Calhoun
- L. Gommans
- G. Gross
- B. de Bruijn
- C. de Laat
- M. Holdrege
- D. Spence
- August 2000
- Legacy publication
Abstract
This document specifies the requirements that Authentication Authorization Accounting (AAA) protocols must meet in order to support authorization services in the Internet. This memo provides information for the Internet community.
Abstract
This document specifies the requirements that Authentication Authorization Accounting (AAA) protocols must meet in order to support authorization services in the Internet. This memo provides information for the Internet community.
RFC 1704: On Internet Authentication
Informational- N. Haller
- R. Atkinson
- October 1994
- Legacy publication
Abstract
This document describes a spectrum of authentication technologies and provides suggestions to protocol developers on what kinds of authentication might be suitable for some kinds of protocols and applications used in the Internet. This document provides information for the Internet community. This memo does not specify an Internet standard of any kind.
Abstract
This document describes a spectrum of authentication technologies and provides suggestions to protocol developers on what kinds of authentication might be suitable for some kinds of protocols and applications used in the Internet. This document provides information for the Internet community. This memo does not specify an Internet standard of any kind.
RFC 1272: Internet Accounting: Background
Informational- C. Mills
- D. Hirsh
- G.R. Ruth
- November 1991
- IETF publication
- Network Management Area
Abstract
This document provides background information for the "Internet Accounting Architecture". This memo provides information for the Internet community. It does not specify an Internet standard.
Abstract
This document provides background information for the "Internet Accounting Architecture". This memo provides information for the Internet community. It does not specify an Internet standard.
Subscribe to AAA
Get notified when:
- RFC changes to status, obsoleted by, updates, updated by, or subseries.
- New RFC added to this subject or below
- The subject was merged into another.