@misc{rfc9191, series = {Request for Comments}, number = 9191, howpublished = {RFC 9191}, publisher = {RFC Editor}, doi = {10.17487/RFC9191}, url = {https://www.rfc-editor.org/info/rfc9191}, author = {Mohit Sethi and John Preuß Mattsson and Sean Turner}, title = {{Handling Large Certificates and Long Certificate Chains in TLS-Based EAP Methods}}, pagetotal = 12, year = 2022, month = feb, abstract = {The Extensible Authentication Protocol (EAP), defined in RFC 3748, provides a standard mechanism for support of multiple authentication methods. EAP-TLS and other TLS-based EAP methods are widely deployed and used for network access authentication. Large certificates and long certificate chains combined with authenticators that drop an EAP session after only 40 - 50 round trips is a major deployment problem. This document looks at this problem in detail and describes the potential solutions available.}, }