| Internet-Draft | EPP over HTTPS | September 2026 |
| Loffredo, et al. | Expires 7 March 2027 | [Page] |
This document describes how an Extensible Provisioning Protocol (EPP) connection is mapped onto the Hypertext Transfer Protocol (HTTP). EPP over HTTP (EoH) requires the use of Transport Layer Security (TLS) to secure EPP information (i.e. HTTPS).¶
This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.¶
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.¶
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."¶
This Internet-Draft will expire on 7 March 2027.¶
Copyright (c) 2026 IETF Trust and the persons identified as the document authors. All rights reserved.¶
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Revised BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Revised BSD License.¶
This document describes how EPP [RFC5730] is mapped onto the Hypertext Transfer Protocol (HTTP) [RFC9110]. Note that there are several versions of HTTP currently in use, including: HTTP/1.1 [RFC9112], HTTP/2 [RFC9113], and HTTP/3 [RFC9114]. As the differences among such versions do not affect the EPP mapping described in this document, hereinafter the version number is omitted except for presenting the special features in the underlying layers of the HTTP stack.¶
HTTP represents a higher-level abstraction of a network connection, removing the need to directly deal with all of the lower-level details of transport protocols. This makes HTTP much more compatible with cloud-native infrastructures, and facilitates faster development times and reduced maintenance costs in such environments.¶
This mapping uses POST requests and 200 (OK) responses, effectively tunnelling EPP semantics and preserving its connection orientation. This promotes reuse of existing EPP software with minimal modification, but limits the use of HTTP features the surrounding infrastructure otherwise provides -- caching, multiplexing, authentication, logging, and automated retries.¶
Security services beyond those defined in EPP are provided by TLS via HTTPS Section 4.2.2 of [RFC9110].¶
This document makes use of the following terms:¶
The acronym used for the EPP over HTTPS transport that defines the use of HTTPS as an EPP transport following the considerations in Section 2.1 of [RFC5730].¶
Is a client-server connection, defined in Section 2.1 of [RFC5730], that supports the EPP Server State Machine, defined in Section 2 of [RFC5730]. The EoH connection is an EPP connection mapped onto the Hypertext Transfer Protocol (HTTP) using an HTTP session.¶
Is an authenticated EPP connection, using the Session Management Commands defined in Section 2.9.1 of [RFC5730]. The EoH session is an EPP session mapped onto the Hypertext Transfer Protocol (HTTP) using an HTTP session.¶
Is an EPP client-server connection, defined in Section 2.1 of [RFC5730], that is mapped onto the Hypertext Transfer Protocol (HTTP) using an HTTP session. Upon the client submitting the initial HTTP POST with empty content, the HTTP session is started by the server and the server returns an EPP <greeting>, establishing the EoH connection.¶
Is an authenticated EoH connection, which occurs after a successful EPP <login> on an EPP connection. In EPP, all messages except for the EPP <login> and <hello> need to be sent on an EPP session.¶
Used to facilitate a stateful EoH connection / EoH session that is required by Section 2.1 of [RFC5730]. The HTTP session is initiated using the Set-Cookie and Cookie header fields when the EoH connection is established. EPP messages belonging to the same EoH connection can be exchanged over different underlying HTTP connections.¶
The key words "MUST", "MUST NOT", "REQUIRED", "SHALL", "SHALL NOT", "SHOULD", "SHOULD NOT", "RECOMMENDED", "NOT RECOMMENDED", "MAY", and "OPTIONAL" in this document are to be interpreted as described in BCP 14 [RFC2119] [RFC8174] when, and only when, they appear in all capitals, as shown here.¶
Mapping EPP session management facilities onto HTTP is accomplished using the existing HTTP POST method. An EPP session exists on top of an EPP connection between two peers, one that initiates the connection request and one that responds to the connection request. The initiating peer is called the "client", and the responding peer is called the "server". An EPP server implementing this specification MUST listen for HTTPS requests at the server URL made available to clients. When the URL does not specify a port, the default HTTPS port 443 is used. There is no server discovery mechanism defined for EoH. The server URL for EoH is made available out-of-band by the server to the clients.¶
Even though HTTP itself is stateless, a stateful EPP session can be achieved using the mechanism described in [RFC6265]. This mechanism uses the Set-Cookie and Cookie header fields to facilitate a stateful HTTP session. Such a session is initiated by the client by sending an initial POST request with empty content to the server. The POST request MUST include "application/epp+xml" (Appendix B of [RFC5730]) in the Accept header field. Upon successful establishment of an EoH connection, the server MUST return a 200 (OK) HTTP response containing the EPP Greeting. The response MUST include "application/epp+xml" in the Content-Type header field, together with the character encoding of the EPP XML (e.g., "application/epp+xml;charset=UTF-8"), and a Cache-Control header field containing the "no-store" directive to disable caching. The response MUST also include the X-Content-Type-Options header field with the value "nosniff" to stop clients from guessing a file's format. The server MUST use the Set-Cookie header field to include a token that uniquely identifies the HTTP session. The client MUST include that cookie in all subsequent requests belonging to the EoH connection, and the server MUST treat those requests as part of the same EoH connection. If a 200 (OK) response does not include a Content-Type header field indicating "application/epp+xml", the client MUST treat the response as invalid and fail the EoH connection process. If the client receives a final HTTP status code other than 200 in response to the initial POST request, no EoH connection has been established and the client MUST treat the response as a failure of the connection process. The handling of such a response is governed by the HTTP status-code semantics described in Section 4. The HTTP session represents an EPP connection, referred to as an EPP over HTTP (EoH) connection, which is initiated by the initial POST request with empty content.¶
The EPP session begins with a successful EPP <login> command on the EoH connection and can be referred to as an EPP over HTTP (EoH) session.¶
An EPP session is normally ended by the client issuing an EPP <logout> command. A server receiving an EPP <logout> command MUST end the EPP session. A server MAY also end an EPP session that has been either active or inactive for longer than a server-defined period. A server MAY end the HTTP session after ending the EPP session.¶
EPP describes client-server interaction as a command-response exchange where the client sends one command to the server and the server returns one response to the client. With the exception of the EPP Greeting, EPP messages are initiated by the EPP client in the form of EPP commands. An EPP client MUST send all commands as HTTP POST requests (Section 6.4 of [RFC9110]). Each POST request MUST include the HTTP session identifier in the Cookie header field and "application/epp+xml" in the Accept header field. When an HTTP request carrying an EPP command reaches the EPP processing layer, the EoH server MUST return the corresponding EPP response in the HTTP response. The HTTP request carrying the EPP command and the HTTP response carrying the EPP response MUST include "application/epp+xml" in the Content-Type header field, together with the character encoding of the EPP XML (e.g., "application/epp+xml;charset=UTF-8"). The EPP response MUST include "no-store" in the Cache-Control header field to disable caching.¶
HTTP does not define the POST method as idempotent. This does not prevent an application from assigning idempotent semantics to the content of a particular POST request. As specified in Section 2 of [RFC5730], EPP commands are designed so that they can be made idempotent. An EoH client that does not receive a valid EPP response MAY retry the HTTP POST request only when the failure might be transient, retrying is consistent with the semantics of any HTTP status code received, and the client knows that the enclosed EPP command, including any extensions, has idempotent application semantics, as permitted by Section 9.2.2 of [RFC9110]. The retry MUST contain the same EPP command, including the same client transaction identifier, if present. The client MUST NOT send a subsequent EPP command until it has received a valid response to the command being retried or has abandoned the EPP session. Operators MUST configure HTTP intermediaries under their control not to automatically retry an EPP POST request. Automatic retry behavior is limited to EoH clients that understand the idempotent semantics of EPP commands and preserve their ordering.¶
The EPP command XML is framed by the content of the HTTP POST request, and the EPP response XML is framed by the content of the HTTP response. Except for the initial POST request described in Section 3, each EoH HTTP request MUST contain a single EPP message. Each HTTP response generated after processing an EPP command MUST contain a single EPP response. Commands MUST be processed independently and in the same order as received from the client.¶
HTTP status codes MUST NOT be used to convey the result of an EPP command. When an EoH server accepts an HTTP request for EPP processing and generates an EPP response, it MUST return that response with the HTTP status code 200 (OK), regardless of whether the EPP response indicates command success or failure. This requirement applies only to responses generated after the request has reached the EPP processing layer. If an HTTP request cannot be delivered to or accepted for EPP processing, the EoH server or an HTTP intermediary can return any status code applicable under HTTP. Examples include malformed HTTP requests, unsupported media types, request-size limits, rate limits, overload conditions, and gateway failures. Such a response represents an HTTP-layer outcome and is not an EPP response. EoH clients MUST be prepared to receive any HTTP status code. Clients MUST process unrecognized status codes according to the status-code class semantics defined in Section 15 of [RFC9110]. If a client does not receive a valid EPP response, it has not received an authoritative EPP command result. The client MUST process any HTTP response according to its status-code semantics. If the request might have reached the EPP processing layer but no valid EPP response is received, the outcome of the EPP command is indeterminate.¶
If a request containing an EPP command and either an empty or an invalid HTTP session identifier reaches the EPP processing layer, the server MUST return an EPP 2002 response (i.e. Command use error) in a 200 (OK) HTTP response.¶
A server SHOULD impose a limit on the amount of time required for a client to issue a well-formed EPP command. A server SHOULD end an EPP session if a well-formed command is not received within the time limit.¶
HTTP/2 and HTTP/3 support a multiplexing feature that was introduced to address head-of-line blocking issues in previous HTTP versions. In the context of multiple requests being sent on a single HTTP connection, multiplexing allows the delivery of responses in a different order from how the requests were made. EPP allows pipelining of commands, but this mapping does not enable it. While HTTP is capable of having more than one outstanding request (through pipelining or multiple connections in HTTP/1, and multiplexing in later versions), this mapping explicitly forbids it. Clients MUST NOT have more than one outstanding HTTP request per EPP session at any given time. Regardless of the client not using EPP pipelining, an intermediary can produce concurrent HTTP requests per EPP session, so the server MUST define the behavior when EPP pipelining is identified (i.e. fail or serialize HTTP requests).¶
A general state machine for an EPP server is described in Section 2 of [RFC5730]. A general client-server message exchange using HTTP is illustrated in Figure 1.¶
Client Server
| |
| POST <empty content> Server URL |
| >>------------------------------->> |
| |
| Send Greeting |
| <<-------------------------------<< |
| |
| POST <login> |
| >>------------------------------->> |
| |
| Send Response |
| <<-------------------------------<< |
| |
| POST Command X |
| >>------------------------------->> |
| |
| Send Response X |
| <<-------------------------------<< |
| |
| POST Command Y |
| >>------------------------------->> |
| |
| Send Response Y |
| <<-------------------------------<< |
| .|
.
.
| POST <logout> |
| >>------------------------------->> |
| |
| Send Response |
| <<-------------------------------<< |
The EPP server MUST follow the "EPP Server State Machine" procedure described in [RFC5730].¶
This section includes an example message exchange used to establish the EoH session, which includes the initial EoH connection that returns the EPP <greeting>, followed by the EPP <login> command and EPP response. The example EPP XML is taken from [RFC5730].¶
Example of the initial EoH connection using an HTTP POST with empty content to establish the EoH connection:¶
POST / HTTP/1.1 Host: eoh.example.com Accept: application/epp+xml
Example of the initial EoH connection response containing the HTTP session identifier and the EPP <greeting> content that establishes the EoH connection:¶
HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: application/epp+xml;charset=UTF-8
Content-Length: 815
Set-Cookie: session_id=xyz1234567; Secure; HttpOnly; SameSite=Strict
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<epp xmlns="urn:ietf:params:xml:ns:epp-1.0">
<greeting>
<svID>Example EPP server epp.example.com</svID>
<svDate>2000-06-08T22:00:00.0Z</svDate>
<svcMenu>
<version>1.0</version>
<lang>en</lang>
<lang>fr</lang>
<objURI>urn:ietf:params:xml:ns:obj1</objURI>
<objURI>urn:ietf:params:xml:ns:obj2</objURI>
<objURI>urn:ietf:params:xml:ns:obj3</objURI>
<svcExtension>
<extURI>http://custom/obj1ext-1.0</extURI>
</svcExtension>
</svcMenu>
<dcp>
<access><all/></access>
<statement>
<purpose><admin/><prov/></purpose>
<recipient><ours/><public/></recipient>
<retention><stated/></retention>
</statement>
</dcp>
</greeting>
</epp>
Example sending of the EPP <login> command to authenticate the client and establish the EoH session.:¶
POST / HTTP/1.1
Host: eoh.example.com
Accept: application/epp+xml
Content-Type: application/epp+xml;charset=UTF-8
Content-Length: 664
Cookie: session_id=xyz1234567
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<epp xmlns="urn:ietf:params:xml:ns:epp-1.0">
<command>
<login>
<clID>ClientX</clID>
<pw>foo-BAR2</pw>
<newPW>bar-FOO2</newPW>
<options>
<version>1.0</version>
<lang>en</lang>
</options>
<svcs>
<objURI>urn:ietf:params:xml:ns:obj1</objURI>
<objURI>urn:ietf:params:xml:ns:obj2</objURI>
<objURI>urn:ietf:params:xml:ns:obj3</objURI>
<svcExtension>
<extURI>http://custom/obj1ext-1.0</extURI>
</svcExtension>
</svcs>
</login>
<clTRID>ABC-12345</clTRID>
</command>
</epp>
Example EPP <login> response that establishes the EoH session:¶
HTTP/1.1 200 OK
Cache-Control: no-store
Content-Type: application/epp+xml;charset=UTF-8
Content-Length: 320
<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<epp xmlns="urn:ietf:params:xml:ns:epp-1.0">
<response>
<result code="1000">
<msg>Command completed successfully</msg>
</result>
<trID>
<clTRID>ABC-12345</clTRID>
<svTRID>54321-XYZ</svTRID>
</trID>
</response>
</epp>
Section 2.1 of [RFC5730] describes considerations to be addressed by protocol transport mappings. This document addresses each of those considerations using a combination of features of the HTTP protocol itself and features of this document.¶
The EPP transport described in this document should be registered by IANA in the "Extensions for the Extensible Provisioning Protocol (EPP)" registry described in RFC 7451 [RFC7451]. The details of the registration are as follows:¶
Note to RFC Editor: Please remove this section and the reference to [RFC7942] before publication.¶
This section records the status of known implementations of the protocol defined by this specification at the time of posting of this Internet-Draft, and is based on a proposal described in [RFC7942]. The description of implementations in this section is intended to assist the IETF in its decision processes in progressing drafts to RFCs. Please note that the listing of any individual implementation here does not imply endorsement by the IETF. Furthermore, no effort has been spent to verify the information presented here that was supplied by IETF contributors. This is not intended as, and must not be construed to be, a catalog of available implementations or their features. Readers are advised to note that other implementations may exist.¶
According to [RFC7942], "this will allow reviewers and working groups to assign due consideration to documents that have the benefit of running code, which may serve as evidence of valuable experimentation and feedback that have made the implemented protocols more mature. It is up to the individual working groups to use this information as they see fit".¶
Organization: Verisign Inc.¶
Name: Verisign EPP SDK¶
Description: The Verisign EPP SDK includes both a full client implementation and a full server stub implementation of this specification. Both HTTP/1.1 and HTTP/2 were implemented, but HTTP/3 was not due to the lack of support of the underlying library.¶
Level of maturity: Development¶
Coverage: All aspects of the protocol are implemented with HTTP/1.1 and HTTP/2.¶
Licensing: GNU Lesser General Public License¶
Contact: jgould@verisign.com¶
URL: https://www.verisign.com/en_US/channel-resources/domain-registry-products/epp-sdks¶
Organization: Institute of Informatics and Telematics of National Research Council (IIT-CNR)/Registro.it¶
Name: .it EPP client and server¶
Description: This specification has been partially implemented on both the client and server sides. A slightly different implementation, which initiates the HTTP session upon completion of an EPP Login request, has been running on the live platform since 2009. Registro .it is currently working to release a fully compliant implementation to the public test environment.¶
Level of Maturity: This is an implementation running in the live platform.¶
Coverage: This implementation includes all the functionality described in this specification, except that the HTTP session begins after an EPP Login request has been successfully processed.¶
Contact Information: Mario Loffredo, mario.loffredo@iit.cnr.it¶
This section addresses the operational aspects of transporting EPP over HTTPS, as outlined in [I-D.ietf-opsawg-rfc5706bis].¶
Since client credentials are included in the EPP <login> command, HTTPS (Section 4.2.2 of [RFC9110]) MUST be used to protect them from disclosure while in transit. HTTPS indicates that TLS is being used to secure the HTTP connection between the client and server. Transferring over TLS also prevents sniffing the HTTP session identifier and, consequently, impersonating a client to perform actions on registrars' objects. Servers are REQUIRED to support TLS 1.2 or higher and follow the Recommendations for Secure Use of Transport Layer Security (TLS) and Datagram Transport Layer Security (DTLS) [RFC9325] for the HTTPS connection.¶
As a further measure to enforce the security, servers SHOULD require clients to present a digital certificate. Clients who possess and present a valid X.509 digital certificate, issued by a recognized Certification Authority (CA), could be identified and authenticated by a server who trusts the corresponding CA. This certificate-based mechanism is supported by HTTPS and can be used with EPP over HTTP.¶
Servers are RECOMMENDED to implement additional measures to verify the client. These measures include IP allow-listing and locking the HTTP session identifier to the client's IP address.¶
HTTP session identifiers SHOULD be randomly generated to mitigate the risk of obtaining a valid one through a brute-force search. HTTP session identifiers MUST be generated using a cryptographically secure random number generator and SHOULD contain at least 128 bits of entropy. Servers MAY limit the lifetime of active sessions to avoid them being exchanged for a long time.¶
The following server measures MAY also be taken:¶
The server MUST set the HttpOnly, Secure, and SameSite=Strict attributes on EoH session cookies. The HttpOnly attribute prevents client-side scripts from accessing the cookie, the Secure attribute restricts transmission of the cookie to secure connections, and the SameSite=Strict attribute [I-D.ietf-httpbis-rfc6265bis] mitigates Cross-Site Request Forgery (CSRF) when these attributes are supported by the client. Finally, servers are RECOMMENDED to perform additional checks to limit the rate of open EPP sessions and HTTP connections to mitigate the risk of congestion of requests. Here again, IP allow-listing could also be implemented to prevent DDoS attacks.¶
If the EPP server is configured as a load balancer routing the requests to a pool of backend servers, some of the aforementioned checks SHOULD be implemented on the load balancer side.¶
The authors wish to acknowledge the input from the .IT technical team.¶
Incorporated review feedback, including feedback from Mark Nottingham:¶