Network Working Group                                           B. Aboba
INTERNET-DRAFT                                                 Microsoft
Category: Standards Track
11 February 2003
Updates: RFC 2865

                     IANA Considerations for RADIUS

This document describes the IANA considerations for the Remote
Authentication Dial In User Service (RADIUS).

This document updates RFC 2865.

1.  Introduction

This document provides guidance to the Internet Assigned Numbers
Authority (IANA) regarding registration of values related to the Remote
Authentication Dial In User Service (RADIUS), defined in [RFC2865], in
accordance with BCP 26, [RFC2434].

1.1.  Specification of Requirements

In this document, several words are used to signify the requirements of
the specification.  These words are often capitalized.  The key words
NOT", "RECOMMENDED",  "MAY", and "OPTIONAL" in this document are to be
interpreted as described in [RFC2119].

1.2.  Terminology

The following terms are used here with the meanings defined in BCP 26:
"name space", "assigned value", "registration".

The following policies are used here with the meanings defined in BCP
26: "Private Use", "First Come First Served", "Expert Review",
"Specification Required", "IETF Consensus", "Standards Action".

2.  IANA Considerations

There are three name spaces in RADIUS that require registration: Packet
Type Codes, Attribute Types, and Attribute Values (for certain
Attributes). This draft creates no new IANA registries, since a RADIUS
registry was created by [RFC2865].

RADIUS is not intended as a general-purpose protocol, and allocations
SHOULD NOT be made for purposes unrelated to Authentication,
Authorization or Accounting.

2.1.  Recommended Registration Policies

For registration requests where a Designated Expert should be consulted,
the responsible IESG area director should appoint the Designated Expert.
Where a specification is required, this MUST be an Internet-Draft or
RFC.  For Designated Expert with Specification Required, the request is
posted to the AAA WG mailing list (or, if it has been disbanded, a
successor designated by the Area Director) for comment and review, and
MUST include an Internet-Draft or RFC. Before a period of 30 days has
passed, The Designated Expert will either approve or deny the
registration request and publish a notice of the decision to the AAA WG
mailing list or its successor.  A denial notice must be justified by an
explanation and, in the cases where it is possible, concrete suggestions

Packet Type Codes have a range from 1 to 249, of which 1-51 have been
allocated.  Type Codes 250-253 are allocated for Experimental Uses, and
254-255 are reserved.  Because a new Packet Type has considerable impact
on interoperability, a new Packet Type Code requires Standards Action,
and should be allocated starting at 52.  A list of allocated RADIUS Type
Codes is given in Appendix A.

Attribute Types have a range from 1 to 255, and are the scarcest
resource in RADIUS, thus must be allocated with care.  Attributes
1-53,55,60-88,90-91,94-100 have been allocated, with 17 and 21 available
for re-use.  Attributes 17, 21, 54, 56-59, 89, 101-191 may be allocated
by IETF Consensus.  It is recommended that attributes 17 and 21 be used
only after all others are exhausted.

Note that RADIUS defines a mechanism for Vendor-Specific extensions
(Attribute 26) and the use of that should be encouraged instead of
allocation of global attribute types, for functions specific only to one
vendor's implementation of RADIUS, where no interoperability is deemed

As noted in [RFC2865]:

   Attribute Type Values 192-223 are reserved for experimental
   use, values 224-240 are reserved for implementation-specific use,
   and values 241-255 are reserved and should not be used.

Therefore Attribute Type values 192-240 are considered Private Use, and
values 241-255 require Standards Action.

Certain attributes (for example, NAS-Port-Type) in RADIUS define a list
of values to correspond with various meanings.  There can be 4 billion
(2^32) values for each attribute. Additional values can be allocated by
Designated Expert with Specification Required.  The exception to this
policy is the Service-Type attribute (6), whose values define new modes
of operation for RADIUS.  Values 1-16 of the Service-Type attribute have
been allocated. Allocation of new Service-Type values are by IETF

Appendix A - RADIUS Packet Types

A list of allocated RADIUS Type Codes is given below:

1        Access-Request               [RFC2865]
2        Access-Accept                [RFC2865]
3        Access-Reject                [RFC2865]
4        Accounting-Request           [RFC2866]
5        Accounting-Response          [RFC2866]
6        Accounting-Status            [RFC2882]
7        Password-Request             [RFC2882]
8        Password-Ack                 [RFC2282]
9        Password-Reject              [RFC2882]
10       Accounting-Message           [RFC2882]
11       Access-Challenge             [RFC2865]
12       Status-Server (experimental) [RFC2865]
13       Status-Client (experimental) [RFC2865]
21       Resource-Free-Request        [RFC2882]
22       Resource-Free-Response       [RFC2882]
23       Resource-Query-Request       [RFC2882]
24       Resource-Query-Response      [RFC2882]
25       Alternate Resource
         Reclaim Request              [RFC2882]
26       NAS Reboot Request           [RFC2882]
27       NAS Reboot Response          [RFC2882]
28       Reserved
29       Next-Passcode                [RFC2882]
30       New-Pin                      [RFC2882]
31       Terminate-Session            [RFC2882]
32       Password-Expired             [RFC2882]
33       Event-Request                [RFC2882]
34       Event-Response               [RFC2882]
40       Disconnect-Request           [DynAuth]
41       Disconnect-ACK               [DynAuth]
42       Disconnect-NAK               [DynAuth]
43       CoF-Request                  [DynAuth]
44       CoF-ACK                      [DynAuth]
45       CoF-NAK                      [DynAuth]
46-49    Reserved
50       IP-Address-Allocate          [RFC2882]
51       IP-Address-Release           [RFC2882]
250-253  Experimental Use
254      Reserved
255      Reserved

Thanks to Ignacio Goyret of Lucent, Allison Mankin of Lucent Bell Labs,
and Harald Alvestrand of Cisco for discussions relating to this

Authors' Addresses

Bernard Aboba
Microsoft Corporation
One Microsoft Way
Redmond, WA 98052

EMail: bernarda@microsoft.com
Phone: +1 425 706 6605
Fax:   +1 425 936 7329

