IETF — drafts and RFCs

Last 48 h · window 2026-08-14 → 2026-08-16 (UTC) · source: mailarchive indexes i-d-announce / ietf-announce
64 drafts 3 RFCs 4 fetches Online: ietf-drafts-ok.pages.dev

Newly published RFCs

2026-08-14

RFC 10030 RFC published
Network Time Protocol (NTP) over the Precision Time Protocol (PTP)
Defines how to carry Network Time Protocol (NTP) messages over a Precision Time Protocol (PTP, IEEE 1588) infrastructure. It lets networks that already deploy PTP — common in telecom, finance and industry — also serve NTP synchronization by reusing the same timing plane. It describes the encapsulation, the mapping between the clock models of both protocols, and the accuracy and security considerations when crossing the two worlds. The goal is interoperability and avoiding the need to run two separate timing infrastructures.
RFC 10031 RFC published
Media Access Control (MAC) Addresses in X.509 Certificates
Specifies how to include MAC addresses (IEEE 802) as an identity inside X.509 certificates, defining the name type and its encoding in the subjectAltName. It is used to authenticate devices by their hardware address in network-access scenarios (for example 802.1AR/DevID or IoT). It details the format, the textual representation and the matching rules, as well as the privacy implications of exposing a MAC address inside a long-lived credential.
RFC 9971 RFC published
Multiple Loss Ratio Search
Defines MLRsearch (Multiple Loss Ratio search), a performance measurement methodology that finds the throughput of a device or network by searching for several loss ratios simultaneously. It improves on the classic binary-search method of RFC 2544 by greatly reducing test time and producing more repeatable results. It describes the algorithm, the stopping criteria and how to report rates for different loss thresholds. It underpins data-plane benchmarking test beds such as those of FD.io/TRex.

Drafts

2026-08-16 · 13 drafts

Individual proposal on how to compose the accountability of AI agents when several of them collaborate on a task. It addresses chaining responsibility and traceability across agent compositions, so that the actions of a composite agent can be attributed to the parts that originated them. It fits the current IETF stream on governance, auditing and attribution of autonomous systems.
Extends the STIR (Secure Telephone Identity Revisited) framework to carry SIP request context within the signed information. The goal is for the recipient of a call to verify not only the caller's identity but also the request context (purpose or associated metadata), strengthening the fight against spoofing and fraudulent calls. It fits the STIR/SHAKEN call-authentication ecosystem.
Defines action receipts for agents: verifiable records proving that an autonomous agent executed a specific action. The idea is to leave a signed, auditable proof of each relevant operation the agent performs, useful for accountability, non-repudiation and compliance. It is part of the recent set of drafts on AI-agent traceability.
draft-wolfe-faf-agent-01 Individual rev -01
Individual draft about an agent within a FAF framework. It describes the role, the interactions and probably the message model of the agent in that context. Being an individual proposal with an uncommon naming, its precise scope is defined in the document itself; broadly it sits in the emerging area of protocols for automated agents.
draft-reilly-aigov-00 Individual new -00
Individual proposal on AI governance. It raises considerations, terminology or mechanisms to govern the behavior of artificial-intelligence systems in the context of Internet protocols. It aligns with the IETF's growing interest in control, auditability and accountability of AI-based agents and services.
Work of the IPPM (performance metrics) working group on version 2, encrypted, of the IPv6 Performance and Diagnostic Metrics (PDM) Destination Option. PDM inserts metrics (sequences and timestamps) into the extension header for fine-grained diagnosis of latency and loss. This revision adds encryption to protect that telemetry from on-path observers, balancing diagnostics and privacy. It is an advanced revision (-16), close to maturity.
Related to SCITT (Supply Chain Integrity, Transparency and Trust): defines disclosure evidence. It proposes how to record and transparently prove the disclosure of information within a software supply chain, relying on SCITT's transparency ledger. It serves to audit what was disclosed, when and by whom.
Extension in the MASQUE area to use CONNECT-UDP as a rendezvous mechanism between peers. It would let two endpoints locate each other and establish UDP communication through a MASQUE proxy, useful for NAT traversal and session establishment. It fits MASQUE's work on proxying UDP over HTTP/3.
Work of the SIDROPS working group on a protocol (Erik) in the RPKI (Resource Public Key Infrastructure) ecosystem. RPKI secures the origin of BGP announcements via resource certificates. This document defines a protocol to distribute or synchronize RPKI objects more efficiently between repositories and validators, improving scalability and the freshness of routing-security data.
draft-gaikwad-ba64-00 Individual new -00
Individual proposal defining BA64, probably a compact encoding or format (base64-like) for a specific use. The exact detail is specified in the document; by its name, it addresses a text representation of data for transport or interoperability. It is an initial draft (-00).
Individual draft along the lines of 'Web4' concepts that deals with node admission and state. It would set out how a node joins a network and publishes or validates its state within it, with admission rules. It is an initial, conceptual proposal, outside the established working groups.
Within the SCITT framework, defines receipts for the engagement of a physical site. It proposes issuing verifiable proofs (receipts) that an interaction or engagement with a physical location has occurred, integrating it into supply-chain transparency. Useful for traceability of real-world assets and processes.
Proposal on Path MTU discovery (PLPMTUD, Packetization Layer Path MTU Discovery) applied to QUIC, with some 'PPD' variant. It seeks to improve how QUIC determines the maximum packet size it can send without fragmentation over the path, optimizing performance and avoiding MTU black holes. It builds on QUIC's probing mechanisms.

2026-08-15 · 15 drafts

draft-intra-handshake-fail-06 Individual rev -06
Draft on the handling of handshake failures (probably in a transport-security protocol). It defines how to detect, signal and react to failed handshakes to improve robustness or diagnostics. Intermediate revision (-06), suggesting consolidated work.
Document associated with the quantum-networking area (QIRG, Quantum Internet Research Group). It describes an architecture for quantum networks: the entities, layers and functions needed to distribute entanglement and communicate quantum information. It is research work that lays conceptual foundations for a future quantum Internet.
Related to SCITT (Supply Chain Integrity, Transparency and Trust): defines disclosure evidence. It proposes how to record and transparently prove the disclosure of information within a software supply chain, relying on SCITT's transparency ledger. It serves to audit what was disclosed, when and by whom.
Related to SCITT (Supply Chain Integrity, Transparency and Trust): defines disclosure evidence. It proposes how to record and transparently prove the disclosure of information within a software supply chain, relying on SCITT's transparency ledger. It serves to audit what was disclosed, when and by whom.
Revision (bis) of RFC 5884 in the BFD working group, covering BFD (Bidirectional Forwarding Detection) over MPLS LSPs. It updates and corrects the specification of how BFD detects fast forwarding failures in MPLS tunnels, incorporating accumulated operational experience. It is WG work (-01) to replace the current standard.
draft-etcheverry-action-ref-03 Individual rev -03
Individual proposal on action references (action ref). It defines how to refer unambiguously to actions within some system or protocol, probably tied to agents or automated flows. Revision -03. The precise scope is detailed in the document.
Framework combining MCP (Model Context Protocol, for AI agents) with Decentralized Identifiers (DID). It proposes how to give verifiable, decentralized identity to agents that interoperate via MCP, enabling authentication and trust between agents. Initial draft within the wave of work on agent identity.
Work of the QUIC working group for an endpoint to discover its observed address (the one the other endpoint sees, behind NAT). It defines a mechanism to communicate the observed peer address within QUIC, useful for NAT traversal, P2P connectivity and protocols that need to know the public IP. WG work (-01).
draft-swhited-contra-tags-04 Individual rev -04
Individual proposal about 'contra tags'. By its name, it defines a scheme of tags with some counter/control semantics. Revision -04. The precise meaning is specified in the document.
Individual draft on the enforcement of something called OASNT. It would define how to enforce rules or policies of that framework. It is the 'enforce' variant of the pair of oasnt documents from the same author.
draft-thallapelly-oasnt-02 Individual rev -02
Individual draft defining the OASNT framework. It establishes the base concepts and mechanisms that the 'enforce' variant complements. Revision -02; scope detailed in the document itself.
draft-reddy-rats-key-binding-02 Individual rev -02
In the RATS (Remote ATtestation procedureS) area, deals with key binding: cryptographically binding a key to remote-attestation evidence. It lets one prove that a key resides in an environment whose state has been attested, strengthening trust in devices and TEEs. Revision -02.
Collects session requirements for an agent protocol (agentproto). It enumerates what a session between agents needs: establishment, state, security and lifecycle. It serves as a basis for designing an interoperable communication protocol between AI agents. Initial draft.
Combines SCITT with attested agent payments. It proposes recording, transparently and verifiably, payments made by autonomous agents, providing attestation evidence that the agent was authorized and in a trusted state when paying. A crossover of supply chain, attestation and automated payments.
Defines SCITT receipts for AI-agent actions. It issues verifiable proofs (receipts), anchored in a transparency ledger, that an AI agent performed a specific action. It brings traceability and non-repudiation to agent activity. Revision -01.

2026-08-14 · 36 drafts

draft-ietf-pim-gaap-20 WG pim rev -20
Work of the PIM (multicast) working group on GAAP. It defines a mechanism within the multicast-routing ecosystem; given its advanced state (-20) it is a mature, heavily reviewed document. It addresses allocation or announcement of addresses/groups in multicast. The exact detail is in the document.
draft-jennings-moq-discovery-00 Individual new -00
Proposal in the Media over QUIC (MoQ) area on discovery. It defines how participants locate senders, relays or media tracks in a MoQ session. It eases bootstrapping of low-latency streaming over QUIC. Initial draft (-00).
Work of the IDR working group with the YANG data model for BGP. It specifies a normalized representation of BGP configuration and operational state, for programmatic management (NETCONF/RESTCONF). Advanced revision (-21), reflecting broad consensus. A basis for network automation.
Proposal on a state-graph cryptographic protocol. It would model the protocol as transitions over a state graph with cryptographic guarantees. Initial, conceptual draft.
Work of the MANET (mobile ad hoc networks) working group analyzing the gaps for operating MANET over the Internet. It identifies what is missing in current protocols to integrate ad hoc networks with the fixed Internet. Revision -07.
draft-nike-cis-clay-tablet-00 Individual new -00
Individual draft with an evocative name ('clay tablet'). It probably proposes a persistent, immutable record format, using the clay-tablet metaphor. Exact scope in the document; initial proposal.
draft-irtf-cfrg-vdaf-22 RG cfrg rev -22
Document of the CFRG (IRTF's crypto research group) on VDAF (Verifiable Distributed Aggregation Functions). It defines functions to aggregate data privately and verifiably across several servers, the basis of privacy-preserving measurement systems like Prio/DAP. Advanced revision (-22), a central reference for private telemetry.
draft-ietf-regext-balance-02 WG regext rev -02
Work of the REGEXT (registration extensions) working group on 'balance', probably an EPP extension to query a registrar's balance/credit at a domain registry. It standardizes how registrars learn their financial balance via EPP. Revision -02.
Proposal in the OAuth/AuthZEN space on authorization claims. It defines claims (assertions) to express authorization decisions or attributes interoperably, aligned with AuthZEN's work on authorization APIs. Initial draft.
Revision (bis) in the DNSOP working group of RFC 9364, the umbrella document for DNSSEC (DNS Security Extensions). It updates and consolidates the DNSSEC reference, incorporating clarifications and operational experience. WG revision -01.
draft-swhited-mka-stems-12 Individual rev -12
Individual proposal related to MKA (MACsec Key Agreement) and 'stems'. It would cover a mechanism associated with MACsec key management (802.1X/802.1AE). Advanced revision (-12). The detail is in the document.
Proposal in the DNSOP space on the handling of RRSIG when the response is REFUSED. It addresses how resolvers and signers behave regarding DNSSEC signature records in refusal scenarios, improving robustness and diagnostics. Initial draft.
Scenario and gap analysis for gateways in a DMSC context. It enumerates use cases and what is missing in current protocols to support them. Revision -04. It fits work on multi-cloud/distributed-service connectivity.
draft-moskowitz-ads-b-auth-02 Individual rev -02
Proposal on authentication of ADS-B, the aviation surveillance system that broadcasts aircraft positions. ADS-B lacks native authentication; this document proposes adding mechanisms to verify the origin of those messages and mitigate spoofing. Revision -02.
draft-dahm-tacacs-sshpk-00 Individual new -00
TACACS+ extension for SSH public keys. It would let SSH public-key authentication be managed and authorized through the TACACS+ AAA service, common in network-device administration. Initial draft.
draft-sfluhrer-ssh-mldsa-07 Individual rev -07
Integrates ML-DSA (the lattice-based post-quantum signature scheme, formerly Dilithium, FIPS 204) into the SSH protocol. It defines how to use ML-DSA for host and user authentication in SSH, preparing the protocol against the quantum threat. Revision -07, fairly consolidated work.
Proposes using ML-DSA (post-quantum signature) with MTL (Merkle Tree Ladder) trees in DNSSEC. It seeks viable post-quantum signatures in DNS, where signature size is critical; MTL helps amortize that cost. It fits DNSSEC's migration to quantum-resistant cryptography. Revision -01.
Work of the LSR working group on a flooding-reduction architecture in link-state protocols (IS-IS/OSPF). In highly meshed topologies, flooding of LSAs/LSPs is redundant and costly; this document defines an architecture to reduce it while preserving convergence. Revision -03.
Work of the V6OPS working group on the use of the NAT64 well-known prefix with RFC 1918 private addresses. It clarifies and gives operational guidance for NAT64 behavior when IPv4 private addresses are involved, avoiding ambiguities and failures. Advanced revision (-07).
Work of the LAMPS working group on post-quantum composite KEMs: it combines a post-quantum key-encapsulation mechanism (e.g. ML-KEM) with a traditional one into a single hybrid construction. That way, security holds if at least one of the two resists. It defines its use in X.509/CMS. Advanced revision (-19).
draft-ietf-cellar-codec-20 WG cellar rev -20
Work of the CELLAR working group (which standardizes Matroska/FFV1) on a codec specification. It formally documents the format for audiovisual preservation and interoperability. Advanced revision (-20), reflecting mature specification work.
In the NOA framework (related to agent actions), defines settlement evidence. It provides verifiable proof that a settlement or closing of a transaction between agents has occurred. Part of the set of drafts on autonomous-agent traceability.
In the NOA framework, defines an action digest: a compact, verifiable fingerprint of an agent's action. It allows referencing and integrating the action into audit records without exposing its full content. It complements the NOA evidence drafts.
In the NOA framework (related to agent actions), defines settlement evidence. It provides verifiable proof that a settlement or closing of a transaction between agents has occurred. Part of the set of drafts on autonomous-agent traceability.
In the NOA framework, defines an action digest: a compact, verifiable fingerprint of an agent's action. It allows referencing and integrating the action into audit records without exposing its full content. It complements the NOA evidence drafts.
draft-gomez-iotops-quic-iot-00 Individual new -00
In the IOTOPS area, analyzes the use of QUIC in IoT environments. It studies the benefits (fast connections, mobility, encryption) and the challenges (power, memory, footprint) of QUIC on constrained devices, and gives guidance for its application. Initial draft.
Collects requirements for intent-based routing in a DMSC context. It defines what a system that translates high-level intents into routing decisions must satisfy. Initial draft that lays groundwork for later work.
Proposal in OAuth on scope aggregation. It addresses how to combine or consolidate multiple authorization scopes coherently when a client needs permissions from several sources, improving management of complex authorizations. Revision -01.
draft-pq-secchannel-00 Individual new -00
Proposal on a post-quantum secure channel. It would define the establishment of an encrypted channel using quantum-resistant cryptography. Initial draft; exact scope in the document.
draft-pq-sectunnel-00 Individual new -00
Proposal on a post-quantum secure tunnel. It complements the secure channel with a tunnel-style encapsulation using post-quantum primitives. Initial draft.
WebSocket extension relating to PMCE (Per-Message Compression Extensions) for state reset. It would allow resetting the per-message compression context, useful for memory control or recovery. Initial draft.
draft-hillier-scitt-arp-03 Individual rev -03
In the SCITT framework, defines 'ARP' (probably a registration/attestation profile or procedure within supply-chain transparency). It specifies how to register a certain kind of evidence verifiably. Revision -03.
Proposal on agent proxy modes. It defines different ways in which a proxy mediates AI-agent communication (for example transparent, inspecting or transforming), with their implications. Initial draft.
In the IOTOPS area, a security specification for Modbus over serial link. Serial Modbus lacks native security; the document defines mechanisms to authenticate and integrate protection into legacy industrial (OT/ICS) deployments. Advanced revision (-07).
Proposal in the IDR area on SR Policy (Segment Routing Policy) templates in BGP. It would allow defining Segment Routing policies in a parameterized, reusable way via templates, simplifying provisioning at scale. Advanced revision (-08).
Work of the AVTCORE working group to carry 'green' metadata (Green Metadata, from MPEG, for energy efficiency in decoding) via RTCP. It allows signaling information that helps reduce the receiver's power consumption in real-time video sessions. Advanced revision (-16).
Pages crawled: i-d-announce ?qdr=m (pages 1–2), ietf-announce ?qdr=m (page 1). Most recent item: drafts 2026-08-16, RFCs 2026-08-14.
Links: drafts → www.ietf.org/archive/id/<name>.html · RFCs → rfc-editor.org/rfc/rfc<N>.html · Published at https://ietf-drafts-ok.pages.dev.
Descriptions written from each announcement's name/title and domain knowledge; individual messages are NOT opened and abstracts are NOT fetched (for reliability). For individual drafts with a non-descriptive name, the explanation is approximate; follow the link for detail. Generated 2026-08-16 (UTC).