Summary

  • RFC 5413 is a Historic record of SLAPP, not a current Internet Standard or deployment certificate.
  • A secure discovery exchange can establish protocol evidence without proving trusted acquisition, policy approval or client service.
  • RFC 5415, current product support, key exchange traces and live wireless telemetry remain separate evidence.

Historic security still has a boundary

SLAPP describes how a Wireless Termination Point can discover an Access Controller and how the parties can establish authenticated, protected exchanges. That makes the document useful for protocol archaeology. It does not make every described exchange a current product capability. The RFC Editor explicitly warns that the text may contain errors and omissions and should not ground deployment.

Discovery is not acquisition

A discover request and response can identify a candidate controller. Authentication and secure transport can protect a conversation. None of those events alone proves that the controller accepted the WTP, applied a WLAN policy, provisioned credentials, or delivered service to a client. The security boundary is not the same as an authorization or operational-success boundary.

CAPWAP and observed evidence

RFC 5415 documents the standards-track CAPWAP solution and obsoletes mechanisms in RFC 5413. A current decision therefore needs exact controller and WTP versions, the negotiated protocol, certificate or key exchange, authorization decision, applied configuration, association and data-plane telemetry. Historic SLAPP explains a path; it cannot certify the live path.