A framework (RFC 3748) for carrying authentication conversations, most commonly over 802.1X wired/wireless networks and VPNs. EAP itself does not authenticate anyone; specific methods such as EAP-TLS, PEAP and EAP-TTLS plug into it and define the actual credential exchange. The network passes EAP messages between the client (supplicant) and an authentication server, typically RADIUS.