With the increase number of devices, protocols, and applications that rely on strong credentials (e.g., digital certificates, keys, or tokens) for network access, the need for a standard credentials provisioning layer is paramount. In particular, since EAP is deployed for authentication needs, the authors extend this use-case by including support for provisioning and management of credentials.

In particular, this specification defines how to support the provisioning of strong credentials to users and/or devices without the need for providing IP connectivity. The use of EAP not only for provisiong but also for managing network credentials provides a general conduit that can be exploited in different environments (e.g., Wired and WiFi networks credentials management).

The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in [RFC2119].

2. Introduction

Because of the increasing number of highly available and highly utilized websites that require secure communications to protect the flow of information from the server to the client and the raising number of devices (IoT) that require strong authentication capabilities, the need for a low-cost and efficient approach to network credentials management is evident.

This specification addresses the problem of providing a simple-to-use and simple-to-deploy system for credentials management by extending the EAP protocol to support credentials provisioning and management functionality.

3. Overview of existing solutions

4. Scope Statement

5. Protocol Overview

6. IANA Considerations

This document uses a new DEAP type, CPROM, whose value (TBD) MUST be allocated by IANA from the EAP TYPEs subregistry of the RADIUS registry.

7. Security Considerations

Several security considerations need to be explicitly considered for the system administrators and application developers to understand the weaknesses of the overall architecture.

