Password Authentication Protocol (PAP)

A PPP authentication method in which the client sends its username and password to the server in clear text, with no challenge and no protection against capture or replay.

Password Authentication Protocol is the simplest authentication option for a Point-to-Point Protocol link. RFC 1334 defines it as a two-way handshake: once the link is established, the connecting peer sends its identifier and password, repeating until the server acknowledges or rejects them. Nothing is hashed or encrypted by PAP itself, so the password crosses the link in clear text, and the server has no way of testing whether the same credentials are being replayed later. It was used mainly for dial-up.

The comparison candidates are expected to make is with the Challenge-Handshake Authentication Protocol (CHAP), defined alongside it. CHAP never sends the password: the server issues a random challenge, the client returns a hash computed from the challenge and the shared secret, and the server can repeat the challenge during the session. That makes CHAP resistant to replay attacks and to simple packet sniffing, where PAP is exposed to both. Both were later supplemented by the Extensible Authentication Protocol, which carries stronger methods. PAP can still appear where it runs inside an already encrypted tunnel, which protects the password in transit.

Exam relevance: a scenario in which remote access credentials are sent in clear text is likely to point to PAP. Questions in this area tend to ask for the stronger alternative, which is CHAP or an EAP method.