Return-Path: <iesg-secretary@ietf.org>
X-Original-To: radext@ietf.org
Delivered-To: radext@mail2.ietf.org
Received: from [10.244.21.25] (gaia.k8s.ietf.org [4.156.85.76])
	by mail2.ietf.org (Postfix) with ESMTP id EAE8011C59B7F;
	Wed, 22 Jul 2026 07:00:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1;
	t=1784728823; bh=4V4lxlORXfbyqAOZMf3xi69hn4fQVe0JJfCSQdjerfE=;
	h=From:To:Subject:Cc:Reply-To:Date;
	b=ZDbc/kSINDj+VC764M4kWn/WIG5YqygofebAu8vBrEjW128pZBmioG8tiGgGJBT+7
	 k6ab9YX9Uqq4gJE0VdUkOCQKW4uJo/Irsm4kxXDyClJHtqQNbBtqe+pA+C8PQJBhEz
	 z3uGYI3NnkP4IV3y0jHEjzK7p9U8LfYeiZrKpaUc=
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 12.69.0
Auto-Submitted: auto-generated
Precedence: bulk
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
Message-ID: 
 <178472882287.526045.5831393899938788836@dt-datatracker-d4d6ff9d9-fsx7d>
Date: Wed, 22 Jul 2026 07:00:22 -0700
Message-ID-Hash: UTJXGWRVUP2I6DAZUQH2IYRI5RMIUDUS
X-Message-ID-Hash: UTJXGWRVUP2I6DAZUQH2IYRI5RMIUDUS
X-MailFrom: iesg-secretary@ietf.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-radext.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: radext@ietf.org
X-Mailman-Version: 3.3.9rc6
Reply-To: iesg@ietf.org
Subject: =?utf-8?q?=5Bradext=5D_WG_Review=3A_RADIUS_EXTensions_=28radext=29?=
List-Id: RADIUS EXTensions working group discussion list <radext.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/radext/xlzL3nVMQ5vyATRiFAZM3Zaz2-0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/radext>
List-Help: <mailto:radext-request@ietf.org?subject=help>
List-Owner: <mailto:radext-owner@ietf.org>
List-Post: <mailto:radext@ietf.org>
List-Subscribe: <mailto:radext-join@ietf.org>
List-Unsubscribe: <mailto:radext-leave@ietf.org>

The RADIUS EXTensions (radext) WG in the Security Area of the IETF is
undergoing rechartering. The IESG has not made any determination yet. The
following draft charter was submitted, and is provided for informational
purposes only. Please send your comments to the IESG mailing list
(iesg@ietf.org) by 2026-08-01.

RADIUS EXTensions (radext)
-----------------------------------------------------------------------
Current status: Active WG

Chairs:
  Margaret Cullen <mrcullen42@gmail.com>
  Valery Smyslov <valery@smyslov.net>

Assigned Area Director:
  Christopher Inacio <stndrds-inacio@andrew.cmu.edu>

Security Area Directors:
  Deb Cooley <debcooley1@gmail.com>
  Christopher Inacio <stndrds-inacio@andrew.cmu.edu>

Mailing list:
  Address: radext@ietf.org
  To subscribe: https://www.ietf.org/mailman/listinfo/radext
  Archive: https://mailarchive.ietf.org/arch/browse/radext/

Group page: https://datatracker.ietf.org/group/radext/

Charter: https://datatracker.ietf.org/doc/charter-ietf-radext/

The RADIUS Extensions (RADEXT) Working Group is responsible for maintaining
the RADIUS protocol, including defining extensions or making modifications
to the RADIUS protocol and related specifications, as needed. The WG is also
responsible for publishing best practices or other guidance, as needed,
to encourage the security, privacy, stability and reliability of RADIUS
deployments.

The radext WG will publish minor RADIUS extensions, best-practices documents
and clarifications.

To ensure backward compatibility with existing RADIUS implementations,
as well as compatibility between RADIUS and Diameter, all documents produced
must specify means of interoperation with legacy RADIUS. Any non-backwards
compatibility changes with existing RADIUS RFCs, including the RadSec RFC
(when published) must be justified. Transport profiles should be compatible
with RFC 3539, with any non-backwards compatibility changes justified.

Work Items

The goals of the RADEXT working group are to:

* Define and publish minor extensions to RADIUS, such as new attribute
definitions.

* Define best practices for RADIUS roaming, and roaming consortia.

* Improve operations for multi-hop RADIUS networks, including:

** loop detection and prevention.

** a multi-hop Status-Server equivalent with ability to Trace the proxy steps
   a RADIUS message will follow.

** improve client-server signaling, and replace non-security requirements to
   "silently discard" of packets with explicit signaling that a packet
   (or a set of packets) cannot be processed.

** improve signaling of reasons for Access-Reject, including the ability to
signal
   explicit refusal of certain authentications.

Proposed milestones:

* Deprecating Insecure Practices in RADIUS draft to IESG ñ April 2026

* Review of RADIUS Security and Privacy draft to IESG - April 2026

* RADIUS Status-Realm and Loop Prevention draft to IESG - December 2026

* RADIUS Connect-Info attribute draft to IESG ñ August 2026

* RADIUS attributes for National Security and Emergency Preparedness draft to
IESG  ñ August 2026

* Carrying location objects with uncertainty in RADIUS draft to IESG ñ August
2026

* RADIUS Proxy Load Balancing draft to IESG - August 2026

* RADIUS Congestion Control draft to IESG - August 2026

Milestones:

  May 2026 - PS Deprecating Insecure Practices in RADIUS draft to IESG

  May 2026 - PS Review of RADIUS Security and Privacy draft to IESG

  Aug 2026 - PS RADIUS Connect-Info attribute draft to IESG

  Aug 2026 - PS RADIUS attributes for National Security and Emergency
  Preparedness draft to IESG

  Aug 2026 - INF Carrying location objects with uncertainty in RADIUS draft
  to IESG

  Aug 2026 - PS RADIUS Proxy Load Balancing draft to IESG

  Aug 2026 - PS RADIUS Congestion Control draft to IESG

  Dec 2026 - PS RADIUS Status-Realm and Loop Prevention draft to IESG



