RADEXT WG Agenda

IETF 123, Madrid

Monday, July 21, 2025, 12:00 - 13:00 CEST (10:00 - 11:00 GMT/UTC)

Chairs: Margaret Cullen, Valery Smyslov

Note taker: Alexander Clouter

Administrivia and WG Status

(Datagram) Transport Layer Security (D)TLS Encryption for RADIUS (Janfred, 20 min)

draft-ietf-radext-radiusdtls-bis

Janfred went through his slides. 3 new versions since the last IETF
meeting.

Decision that CN for validation is forbidden for servers but for clients
it is acceptable.

Open issues:

  1. DTLS retransmissions
  1. Retranmissions (general)

  2. Event-Timestamp / Acct-Delay-Time

Margaret

Valery

Alan

Hekki

Margaret

Janfred

Margaret

Q (re: DTLS transmissions)

Hannes

Janfred

Q

Janfred

Margaret

Hekki/Valery

Methods for Mitigation of Congestion and Load Issues on RADIUS Servers (Janfred, 10 min)

draft-janfred-radext-radius-congestion-control

Idea originated from the RADIUS 'retreat' workshop in March.

Manual interventions have been found not as helpful as they could be.

Call to operators to provide feedback if they see this as a problem

Margaret:

Alan

Q

Proxy Best Practices for the Remote Authentication Dial In User Service (RADIUS) Protocol (Alan, 10 min)

draft-dekok-proxy-bcp

Has been documenting on the WG wiki a collecting of problems around
proxy implementations.

Wants to describe 30 years of experience to prevent others repeating
mistakes.

Standardising Protocol-Error (Alan, 8 min)

draft-dekok-protocol-error

aka "Better signalling"

Proxies would most benefit from this.

Does not expect there to be any push back here, document only requires
some updates.

Margaret

Alan

Eliot

Alan

Janfred

RADIUS over QUIC (Changwang, 7 min)

draft-yl-radext-quic-transport

Margaret:

Q

Changwang:

Q

Changwang:

Q

Valery