Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC4169
Discuss this RFC: Send questions or comments to the mailing listiesg@ietf.org
Other actions:Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 4169
HTTP Digest, as specified in RFC 2617, is known to be vulnerable toman-in-the-middle attacks if the client fails to authenticate theserver in TLS, or if the same passwords are used for authenticationin some other context without TLS. This is a general problem thatexists not just with HTTP Digest, but also with other IETF protocolsthat use tunneled authentication. This document specifies version 2of the HTTP Digest AKA algorithm (RFC 3310). This algorithm can beimplemented in a way that it is resistant to the man-in-the-middleattack. This memo provides information for the Internet community.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.