<?xml version="1.0" encoding="UTF-8"?>
<reference anchor="I-D.ietf-radext-deprecating-radius" target="https://datatracker.ietf.org/doc/html/draft-ietf-radext-deprecating-radius-00">
   <front>
      <title>Deprecating Insecure Practices in RADIUS</title>
      <author initials="A." surname="DeKok" fullname="Alan DeKok">
         <organization>FreeRADIUS</organization>
      </author>
      <date month="November" day="7" year="2023" />
      <abstract>
	 <t>   RADIUS crypto-agility was first mandated as future work by RFC 6421.
   The outcome of that work was the publication of RADIUS over TLS (RFC
   6614) and RADIUS over DTLS (RFC 7360) as experimental documents.
   Those transport protocols have been in wide-spread use for many years
   in a wide range of networks.  They have proven their utility as
   replacements for the previous UDP (RFC 2865) and TCP (RFC 6613)
   transports.  With that knowledge, the continued use of insecure
   transports for RADIUS has serious and negative implications for
   privacy and security.

   This document formally deprecates using the User Datagram Protocol
   (UDP) and of the Transmission Control Protocol (TCP) as transport
   protocols for RADIUS.  These transports are permitted inside of
   secure networks, but their use in those networks is still
   discouraged.  For all other environments, the use of secure
   transports such as IPsec or TLS is mandated.  We also discuss
   additional security issues with RADIUS deployments, and give
   recommendations for practices which increase security and privacy.

	 </t>
      </abstract>
   </front>
   <seriesInfo name="Internet-Draft" value="draft-ietf-radext-deprecating-radius-00" />
   
</reference>
