Extensible Authentication Protocol EAP
O bjectives
• Understand PKI support with EAP.
• Describe EAP Transport Layer Security (TLS).
• Understand Protected EAP (PEAP).
• Introduce various EAP implementations.
Extensible Authentication Protocol (EAP) is an authentication protocol that was defined to support multiple authentication mechanisms. Point-to-Point Protocol (PPP) connections typically regotiate the authenticaten proIocol d urlng the cdnnection's Link Control Protocol (LCP) phase. This requ ired PPP to supge rt the authentication method being used.
Although authentication is not required for PPP connections during the connection's LCP phase, the endpoints negotiate which authentication protocol to use to establish the connection. They may choose no -autht PAP, or CHAP authentication. EAP defers the negotiation of this authentication mechanism until more information about the connection can be gathered. There has been growing concum as to the i nt egrity of authenti cation me chanisens, and EAP is an attempt to provide a foundation to secure this part of network access control. Many vendors are building support fou EAP i nto boUc client and server applications.
This chapiter explotes the protoco l itself. EAP -s defi ne d in RFC 2284r and thie chapter covers some of the specifics defined in that RFC to help you understand the basis of the protocol. You will see soieie of the advontages nf using EAu al ong with the security erncer ne that eeake this protocol so attractivp in a variety of: implementations. Remote Authentication DtehIn User Service (RADIUS) -s hh^f^ in addressing tleem concerns. This chaptPI describef how R°DIU° can te us ed as a back- end semce to provide authentication suppott fo r the user. Wrth this more-complete picture of the EAP authenticatioc process, you will look at different ^ptementations of1 EAP in time network
Continue reading here: Figure 261 EAP Packet Format
Was this article helpful?