Extensible Authentication Protocol (EAP)

An authentication framework, defined in RFC 3748, that carries many different authentication methods between a device and an authentication server; it is not itself one method.

The Extensible Authentication Protocol, defined in RFC 3748 (2004), is a framework for carrying authentication exchanges rather than a single way of authenticating. It originated with the Point-to-Point Protocol and is now best known as the language of IEEE 802.1X, where it travels between the connecting device and the switch or access point as EAP over LAN, and on to the authentication server, commonly inside RADIUS. EAP itself defines the message exchange (requests, responses, success and failure) and a few basic methods; the real work is done by whichever method the two ends agree on.

That is the point candidates commonly miss: EAP’s strength is the strength of the method in use. EAP-TLS authenticates both sides with certificates. PEAP builds a TLS tunnel with a server certificate and protects a password exchange inside it. Older methods such as EAP-MD5 offer no server authentication and expose the exchange to offline attack, so “we use EAP” says little on its own. The framework lets an organisation change methods without replacing its switches, which is why EAP underpins network access control.

Exam relevance: a scenario is likely to ask for the method rather than the framework, weighing certificate-based mutual authentication against password-based approaches. Candidates are expected to describe EAP as a framework that carries methods, and not as an authentication method in its own right.