RFC 3748 specifies that the EAP-response/identity frame must comply with what criteria?

A.
The EAP-response/identity frame must contain the user identity.
B.
When TLS-tunneling mode is active, the EAP-response/identity frame must have a blank user identity.
C.
The EAP-response/identity frame must not contain a null identity value.
D.
The user identity value must be hashed prior to insertion into the EAP-response/identity frame.