RFC 2869 RADIUS Extensions June 2000 5.1 Acct-Input-Gigawords ............................ 22 5.2 Acct-Output-Gigawords ........................... 23 5.3 Event-Timestamp ................................. 23 5.4 ARAP-Password ................................... 24 5.5 ARAP-Features ................................... 25 5.6 ARAP-Zone-Access ................................ 26 5.7 ARAP-Security ................................... 27 5.8 ARAP-Security-Data .............................. 28 5.9 Password-Retry .................................. 28 5.10 Prompt .......................................... 29 5.11 Connect-Info .................................... 30 5.12 Configuration-Token ............................. 31 5.13 EAP-Message ..................................... 32 5.14 Message-Authenticator ........................... 33 5.15 ARAP-Challenge-Response ......................... 35 5.16 Acct-Interim-Interval ........................... 36 5.17 NAS-Port-Id ..................................... 37 5.18 Framed-Pool ..................................... 37 5.19 Table of Attributes ............................. 38 6. IANA Considerations ................................... 39 7. Security Considerations ............................... 39 7.1 Message-Authenticator Security .................. 39 7.2 EAP Security .................................... 39 7.2.1 Separation of EAP server and PPP authenticator .. 40 7.2.2 Connection hijacking ............................ 41 7.2.3 Man in the middle attacks ....................... 41 7.2.4 Multiple databases .............................. 41 7.2.5 Negotiation attacks ............................. 42 8. References ............................................ 43 9. Acknowledgements ...................................... 44 10. Chair's Address ....................................... 44 11. Authors' Addresses .................................... 45 12. Full Copyright Statement .............................. 47 1. Introduction RFC 2865 [1] describes the RADIUS Protocol as it is implemented and deployed today, and RFC 2866 [2] describes how Accounting can be performed with RADIUS. Rigney, et al. Informational