IETF Daily Digest — Internet-Drafts & RFCs

New and revised Internet-Drafts and newly published RFCs across all IETF/IRTF groups · window: past 48 hours (2026-08-26 to 2026-08-28 UTC) · generated 2026-08-28
102 drafts 1 RFCs 86/102 drafts with official abstract Published: https://ietf-drafts-ok.pages.dev

Newly published RFCs

Thursday, August 27, 2026

YANG Library: Addition of the augmented-by List

RFC 10035 RFC stream published abstract

RFC 8525 defined the "ietf-yang-library" YANG module, which reports the YANG modules, datastores, and datastore schemas a network management server uses. This RFC augments that module with an "augmented-by" list, making it easier to obtain all dependencies between YANG modules by querying the server's YANG library directly. It updates RFC 8525 so that the library also includes the augmented-by list.

Drafts

Friday, August 28, 2026 · 8 drafts

Specifies a procedure for distributing BGP-LS key parameters for inter-domain links between two Autonomous Systems. It defines a new BGP-LS NLRI type for an Inter-AS Link plus three new TLVs for the Inter-AS Link descriptor. These extensions let a network controller retrieve topology across inter-AS environments, so operators can collect interconnect information and automatically compute the inter-AS topology from BGP-LS data.

draft-agentic-ai-tool-execution-finality-00 Individual new -00 abstract

Argues that agentic AI systems now call tools, write memory, move money and trigger physical actions, while most safety layers decide permission upstream and then trust the downstream path. Specifies a protected "execution-finality" architecture for the Decoupled Authorisation System (DAS) built on two-instance binding, mutually load-bearing cross-committed evidence, scoped non-bearer finality authority, and independent Finality Sink reconstruction. A Candidate Act stays non-effective until the sink re-derives the pending operation and every required condition still matches; any failure yields fail-closed denial before effectuation.

draft-das-protocols-candidate-act-finality-00 Individual new -00 abstract

Frames the missing boundary as the moment a machine-generated instruction becomes a real-world act, which today can be reached even after hallucination, stale citation or an unsafe agentic step. Specifies the DAS Protocols Candidate-Act Finality architecture: every effect-capable AI output is first converted into a non-effective Candidate Act that stays inert until a Protected Enforcement Domain validates output, provenance, factual support, consequence, jurisdiction, epoch and sink predicates. Only then is a scoped non-bearer capability or Execution Handle released and verified at a Finality Sink, with support for graduated and escalated conditional finality.

draft-ietf-mpls-stamp-pw-11 WG MPLS rev -11 abstract

Describes how to encapsulate the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) in MPLS networks. It covers LSPs and Pseudowires used for Layer 2 and Layer 3 services, with or without the Control Word and/or an IP/UDP header, and updates RFC 8972 by revising the STAMP Test Session Identifier for LSPs and PWs.

Defines a YANG data model that extends the network topology model of RFC 8345 to map network topologies to inventories. It introduces an "inventory-topology" network type plus augmentations for physical-entity mappings and capabilities, usable by any overlay topology for service-provisioning validation, network maintenance and capacity planning.

draft-das-protocols-enterprise-ai-00 Individual new -00 abstract

Warns that a compromised enterprise AI server can become a continuously updated reconstruction engine, correlating customer records, defects, financials and internal communications into competitive intelligence and then externalizing it. Presents the DAS Protocols enterprise-AI architecture enforcing Execution-Consequence Decoupling through decomposition of authority across independent vaults, mandatory mediation of every consequence-bearing candidate output, and "technical non-completability" so computation can finish without the ability to complete external consequence. Reconstruction is gated by a session-bound Reconstruction Authorization Object.

draft-somaratne-scitt-stc-stp-00 Individual new -00 abstract

Defines the Sovereign Tensor Container (STC-1.0) and Sovereign Tensor Provenance (STP-1.0). STC-1.0 establishes a strict 64-byte physical memory alignment standard for binary ML tensor payloads to enable zero-copy Direct Memory Access. STP-1.0 defines an embedded cryptographic provenance framework using C2PA profiles, X.509 signature chains and SCITT-compatible attestations to secure supply-chain integrity for distributed AI models.

draft-ietf-mpls-mna-ioam-13 WG MPLS rev -13 abstract

Uses MPLS Network Actions (MNA) mechanisms to collect and transport operational state and telemetry with In situ OAM (IOAM) data-fields, including IOAM Direct Export (IOAM-DEX, RFC 9326). It builds on IOAM (RFC 9197) Option-Types such as Pre-allocated Trace, Proof of Transit, Edge-to-Edge and Incremental Trace, letting MPLS carry the actions and data needed to compute performance metrics.

Thursday, August 27, 2026 · 58 drafts

draft-schinazi-masque-proxy-09 Individual rev -09 abstract

Describes the architectural principles behind MASQUE (Multiplexed Application Substrate over QUIC Encryption), a set of protocols and HTTP extensions that allow proxying all kinds of Internet traffic over HTTP, and the properties MASQUE can provide.

draft-ietf-manet-inet-gap-analysis-10 WG MANET rev -10 abstract

Presents a MANET internetworking problem statement and gap analysis. Building on RFC 2501's definition of a Mobile Ad hoc Network as an autonomous system of mobile nodes that may operate in isolation or interface with a fixed network such as the public Internet, it examines the gaps in connecting MANETs to the wider Internet.

draft-mih-sokolov-scitt-payload-binding-02 Individual rev -02 abstract

Observes that systems anchoring records to a SCITT Transparency Service repeatedly re-derive the same construction: a canonical form of structured content, a content-addressed identifier from that form, a receipt in the Signed Statement's unprotected header, and a typed reference letting one record cite another by digest across profiles. Defines this reusable pattern as the Canonical Payload Binding profile, so payload classes declare canonicalization algorithms once and gain interoperable derived identifiers with statement-to-receipt binding and typed digest references.

Describes an approach for storing a fingerprint-based identifier for an OpenPGP key packet on a hardware security device whose identifier field is size-constrained.

Chips Message Robust Authentication (Chimera) lets a GNSS constellation such as GPS provide receivers with authentication of pseudorange measurements on open PNT signals. Specifies a Fast Channel Chimera Marker Key Package, an efficient data structure encoding one or more marker keys and metadata with a digital signature over all security-relevant parameters, using CBOR Object Signing and Encryption (COSE). Also describes a streaming network protocol to distribute these packages over the Internet.

draft-aegisfs-secdispatch-rats-00 Individual new -00 abstract

Specifies AegisFS, a programmable secure file and folder runtime that turns ordinary filesystem objects into policy-driven, state-, execution- and behavior-aware security objects. It introduces the Octal-to-OpCode (OtO) framework, compiling file operations and intent declarations into a 9-bit octal instruction set for microsecond-latency policy enforcement, and the Aegis Policy Language (APL), where the policy definition is the executable architecture: an operation not expressible in valid APL cannot produce a valid opcode and cannot execute. Submitted for the SECDISPATCH and RATS working groups.

draft-ietf-intarea-dhcp-rate-signaling-00 WG INTAREA new -00 abstract

Defines new DHCPv4 and DHCPv6 options to explicitly signal available upstream and downstream data rates. In many broadband access networks CPE and intermediate nodes cannot see the subscriber's provisioned service tier; communicating these capacities natively via DHCP lets clients, relay agents and snooping switches configure localized traffic shaping and queuing, reducing reliance on indiscriminate dropping and enabling AQM and the L4S architecture.

draft-ietf-intarea-reordering-00 WG INTAREA new -00 abstract

Notes that several link-layer standards mandate in-order delivery of Layer 2 frames, apparently believing higher layers require it, and implement resequencing that can add delay and net performance loss. Points out that modern TCP and QUIC tolerate out-of-order delivery well, and provides information for Layer 2 technology standards on the actual need to assure in-order delivery for IETF protocols.

draft-faltstrom-unicode-18-01 Individual rev -01 abstract

Describes the changes between Unicode 12.0.0 and Unicode 18.0.0 in the context of IDNA2008, where additions and changes affect the values produced by the IDNA2008 algorithm. It assigns the derived property value "UNDER REVIEW" to certain code points as exceptions and provides the tables IANA needs to make its database consistent with Unicode 18.0.0. The document is based on pre-release data, so figures concerning Unicode 18.0.0 are provisional until regenerated against released files.

draft-dogru-cedulon-02 Individual rev -02 abstract

Defines the Cedulon Protocol, an audit layer for agent-to-agent commerce. Payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2) already move value but do not by themselves produce a fail-closed policy check and a signed spend receipt reconcilable against a rail extract. Cedulon specifies a signed Trade Manifest, a default-deny Policy Decision Point, a COSE/CWT Spend Receipt, epoch checkpoints and rail-extract reconciliation, plus a Dispute Evidence Bundle and optional SCITT anchoring. It sits above x402 and AP2 rather than competing with them.

draft-kondoju-evc-01 Individual rev -01 abstract

Specifies the External Verifier Contract (EVC), a small, testable, proof-system-agnostic boundary between a host (about to take a privileged action for an agent) and an external verifier subprocess that returns an allow/deny verdict on an opaque proof bundle. It governs only transport and verdict: a single JSON request over stdin, exactly one JSON verdict on stdout, and fail-closed interpretation of exit codes, timeouts and malformed output. The same envelope carries classical-signature, zero-knowledge and third-party verdicts; it is deliberately not a governance, delegation or policy framework.

Specifies BGP Failure Propagation (BGP-FP), an infrastructure and protocol that improves inter-domain convergence by accelerating removal of stale routes. It uses a per-AS Agent to detect inter-AS reachability changes and configure routers, a logically centralized Repository to store and selectively forward reachability state, and BGP Large Communities as a route-freshness marker. It clarifies that "AS reachability" is between two ASes rather than individual links, and proposes a Repository run by a new organization of Tier-1 ASes and RIRs with Byzantine fault-tolerant consensus.

By its name, this individual draft probably proposes a mechanism for enforcing trust for AI agents. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-intra-handshake-fail-14 Individual rev -14 abstract

Provides technical details of CVE-2026-33697 and EUVD-2026-16488 as evidence of how intra-handshake attestation fails in practice, even without physical access. It argues that, because continuous attestation is generally required, intra-handshake attestation adds unnecessary complexity, and backs the results with formal analysis artifacts in ProVerif (Apache-2.0) for reproducibility, acknowledged by the relevant stakeholders.

draft-ietf-v6ops-rfc7915-bis-01 WG V6OPS rev -01 abstract

Describes the Stateless IP/ICMP Translation Algorithm (SIIT), which translates between IPv4 and IPv6 packet headers, including ICMP headers. This document obsoletes RFC 7915.

draft-jags-intarea-icmp-ext-underlay-info-05 Individual rev -05 abstract

Addresses overlay operators' need for visibility into underlay hops during traceroute from overlay endpoints. Defines an ICMP extension object, the Underlay Information Object (UIO), that lets underlay head-end nodes encapsulate underlay error information within ICMP error messages, giving overlay operators visibility into underlay paths for troubleshooting.

draft-yl-cats-data-model-09 Individual rev -09 abstract

Defines a YANG data model for the management of Computing-Aware Traffic Steering (CATS) systems.

Defines an extension to the RESTCONF protocol to support Trace Context propagation as defined by the W3C, enabling distributed tracing across RESTCONF interactions.

draft-ietf-netconf-trace-ctx-extension-08 WG NETCONF rev -08 abstract

Defines how to propagate trace-context information across the Network Configuration Protocol (NETCONF) to enable distributed tracing scenarios. It is an adaptation of the HTTP-based W3C Trace Context specification.

By its name, this individual draft probably defines a framework for AI agent identity. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

By its name, this individual draft probably concerns trust for agent-initiated payments. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-ietf-asdf-sdf-protocol-mapping-11 WG ASDF rev -11 abstract

Defines protocol-mapping extensions for the Semantic Definition Format (SDF) so protocol-agnostic SDF affordances can map to protocol-specific operations. It specifies how properties, actions and events are accessed with a given protocol, provides mappings for Bluetooth Low Energy and Zigbee (extensible to HTTP and CoAP), and describes a method to extend SCIM with an SDF model mapping.

By its name, this individual draft probably addresses attestation across the AI model lifecycle. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

By its name, this individual draft probably defines an Agent Trust Transport Protocol (ATTP). The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

By its name, this individual draft probably applies an Agent Trust Transport Protocol to industrial control systems. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

By its name, this individual draft probably relates OpenID to AI agent identity. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-sharif-apki-agent-pki-01 Individual rev -01

By its name, this individual draft probably defines an agent PKI (APKI). The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

By its name, this individual draft probably defines a transport protocol for AI agents. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-sharif-aeba-01 Individual rev -01

By its name (AEBA), this individual draft's exact topic is unclear from the name alone. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-hawkins-scitt-attested-agent-payment-02 Individual rev -02 abstract

A formal administrative notice that the individual Internet-Draft draft-hawkins-scitt-attested-agent-payment has been discontinued and will not be progressed as an individual submission.

draft-das-child-safe-rendering-finality-01 Individual rev -01 abstract

Notes that online child-safety controls usually operate before the final rendering boundary, and an upstream decision does not guarantee content cannot later be decrypted, composited, rendered, forwarded or mirrored through another path. Defines a protected rendering execution-finality architecture for age-restricted content: a proposed rendering is a Restricted Content Candidate Act that stays non-renderable until a Protected Enforcement Domain validates recipient, content, device, policy, eligibility, freshness and revocation predicates, then a Rendering Finality Sink verifies scoped authority right before content becomes perceptible. The principle: permission to deliver is not permission to render.

draft-borthwick-msebenzi-environment-state-02 Individual rev -02 abstract

Observes that agent-authorization mandate formats describe properties of the transaction (what, by whom, how much, against which credential) but not properties of the execution environment (whether a venue is open, whether a source of funds is funded). Specifies the environment.* constraint family for agent-authorization mandate vocabularies against a host-binding profile satisfied by the Verifiable Intent format, defining the membership criterion, family-wide vocabulary, composition discipline, register discipline, security considerations and IANA mechanics, without defining any individual constraint type.

draft-wang-cats-odsi-01 Individual rev -01 abstract

Describes a system model in which independently operated, mutually untrusted participants contribute compute, memory, model storage and network capacity to one LLM inference service, with no single entity admitting participants, selecting every path, holding the whole model, verifying all results or settling all contributions. Defines the Open, Decentralized and Scalable Inference (ODSI) architecture: roles, trust boundaries, named objects, protocol-independent interfaces, execution workflow, verification choices, timing model, and security and privacy requirements. It relates to CATS but does not extend the CATS single-provider model across trust domains; Informational.

draft-ietf-intarea-ipv6-resolved-gateway-00 WG INTAREA new -00 abstract

Specifies host behavior enabling IPv4 communication for dual-stack hosts on IPv6-only segments without subnets, ARP, tunneling or translation. Hosts that receive 192.0.0.11/32 as their IPv4 default gateway resolve the next-hop link-layer address from the IPv6 neighbor cache rather than via ARP, and forward IPv4 packets natively end-to-end. It is incrementally deployable with no DHCPv4 changes and requests allocation of 192.0.0.11/32 in the IANA IPv4 Special-Purpose Address Registry.

draft-ietf-sidrops-publication-server-bcp-10 WG SIDROPS rev -10 abstract

Describes best current practices for operating an RFC 8181 publication engine and its associated publicly accessible rsync and RRDP repositories.

draft-asor-wimse-agent-delegation-chain-00 Individual new -00 abstract

Addresses AI agents delegating tasks to other agents, where each delegation should convey only a bounded subset of the delegating party's authority. Aims to let any enforcement point verify offline, with no call to an authorization server, that a token presented at hop N carries authority no greater than the token at hop N-1, back to a trusted root.

draft-ietf-fann-problem-statement-00 WG FANN new -00 abstract

Notes that AI/ML training and inference and cloud services need networks combining high bandwidth, low delay, low jitter and minimal loss, requiring rapid adaptation to faults, degradation and congestion that existing routing and traffic management handle poorly at large scale (e.g. data centers and DCI). Describes the gap analysis and the need for fast network notification, and identifies the set of problems a fast-network-notification solution must address.

By its name, this BMWG working-group draft probably specifies a benchmarking methodology for Segment Routing. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-ietf-wimse-wpt-02 WG WIMSE rev -02 abstract

Within the WIMSE architecture for workload authentication and authorization, specifies the Workload Proof Token (WPT), a mechanism for a workload to prove possession of the private key tied to its Workload Identity Token (WIT). The WPT is a signed JWT binding authentication to a specific HTTP request, giving application-layer proof of possession for workload-to-workload communication, designed to work alongside the WIT credential format and other WIMSE protocols in multi-hop call chains.

draft-li-idr-ipv6-bgp-identifier-01 Individual rev -01 abstract

Defines a new BGP Capability that lets an IPv6 BGP speaker use its global unicast IPv6 address as its BGP Identifier. This simplifies configuration in IPv6-only networks by leveraging the inherent uniqueness of IPv6 addresses while maintaining full backward compatibility with existing BGP implementations.

draft-ietf-regext-rdap-jscontact-26 WG REGEXT rev -26 abstract

Defines an RDAP extension that represents entity contact information in JSON responses using JSContact.

draft-yuyou-moq-conditional-filtering-00 Individual new -00 abstract

In Media over QUIC Transport (MOQT), subscribers use Range Filters to select subgroups, objects or priorities within a track, but those filters are static once set and change only through explicit subscriber signaling. Proposes an extension binding conditional evaluation logic directly to Range Filter sets so a relay can autonomously adapt intra-track forwarding based on real-time network conditions, avoiding the round-trip delay of explicit subscriber updates.

draft-ma-6man-ra-dns64-flag-02 Individual rev -02 abstract

Defines a new flag in the DNS Router Advertisement option to advertise DNS64 functionality, enabling automatic configuration of DNS64 resolution and improving deployability in IPv6 transition scenarios.

draft-ma-v6ops-pe-ipv6only-reqs-01 Individual rev -01 abstract

Defines functional, protocol and operational requirements for Provider Edge (PE) devices operating in a multi-domain network environment where the underlay is exclusively IPv6.

draft-rosomakho-httpbis-h3-unbound-data-02 Individual rev -02 abstract

Defines a new HTTP/3 frame type, UNBOUND_DATA, and a corresponding SETTINGS parameter to negotiate its use. Sending an UNBOUND_DATA frame on a CONNECT request or response stream indicates that all subsequent octets on that stream are tunneled bytes, removing the need to wrap each portion in DATA frames. This reduces framing overhead and simplifies long-lived CONNECT tunnels.

draft-das-payment-execution-finality-00 Individual new -00 abstract

Argues that payment rails move money but do not know whether a given generated instruction (amount, beneficiary, rail, purpose, agent) is the one authorized to move; a signed ISO 20022 message or OAuth token authenticates a channel, not a Candidate Act at the settlement sink. Specifies a payment-side execution-finality profile: an instruction stays a Payment Candidate Act while a Protected Enforcement Domain binds principal, wallet, amount, currency, beneficiary, rail, purpose, policy epoch and settlement sink, then commits evidence before issuing scoped non-bearer authority that the posting sink verifies and consumes.

draft-das-agentic-tool-binding-00 Individual new -00 abstract

Notes that frontier runtimes standardized the dangerous moment (Claude tool_use, OpenAI tool_calls, MCP tools/call) and that alignment, allowlists and OAuth sit around it rather than on it, so prompt-injected mail, poisoned retrieval or a stolen seat can become an external act with a 200 from the tool. Binds the Agent Candidate Act profile onto those three existing interfaces: the model may emit the block, but it stays non-effective until a local enforcer builds the act, binds the argument digest and refuses invoke() until scoped authority is verified at the dispatch sink.

draft-das-ot-actuation-finality-00 Individual new -00 abstract

Argues that industrial systems know how to move a breaker, valve or setpoint but not whether a given write (tag, value, device, session or agent) is the one authorized to become motion; a signed OPC UA, DNP3, IEC 61850 or MQTT command authenticates a channel, not a Candidate Act at the actuation sink. Specifies an OT-side execution-finality profile: a write stays an Actuation Candidate Act while a Protected Enforcement Domain binds principal, zone, device, tag, value envelope, mode, interlock state, policy epoch and actuation sink, then the I/O-driving sink verifies and consumes scoped authority. A setpoint write is not actuation.

draft-ietf-v6ops-nat64-wkp-1918-08 WG V6OPS rev -08 abstract

Modifies the RFC 6052 Section 3.1 requirement that IPv4/IPv6 translators MUST NOT use the Well-Known Prefix 64:ff9b::/96 for non-globally-reachable IPv4 addresses such as RFC 1918 space. The change lets IPv6-only nodes reach IPv4-only services at specific non-globally reachable addresses via the Well-Known Prefix, updating RFC 6052 to allow translation of such packets.

draft-das-enterprise-ai-output-finality-00 Individual new -00 abstract

Warns that a frontier enterprise assistant able to see mail, tickets, code, finance and memory can join fragments into meaning never stored as one record and then act, and that IAM, DLP, clean rooms, TEEs and output filters answer who may touch a store but not whether lawful fragments may be joined into new protected meaning or leave via an assistant or MCP tool. Keeps identity, content and association under independent vaults, joins them only under a session-bound Reconstruction Authorization Object, seals the Candidate Output, commits a receipt before release authority exists, and completes send/write/store/invoke only at an Output Release Boundary.

draft-correctover-ccs-08 Individual rev -08 abstract

Defines the Correctover Conformance Shape (CCS), a runtime verification framework for AI agent tool calls. CCS establishes seven verification dimensions and specifies receipt formats with Ed25519 signatures, three verdict values and four executor lifecycle states. This revision promotes AEB and CAID to normative references, clarifies Ed25519 signature construction using RFC 8785 canonical JSON, and documents two independent interoperable implementations.

draft-ietf-lamps-pq-composite-kem-20 WG LAMPS rev -20 abstract

Defines combinations of NIST ML-KEM in hybrid with traditional algorithms RSA-OAEP, ECDH, X25519 and X448, tailored to security best practices and regulatory guidelines. Composite ML-KEM applies to any application using X.509 or PKIX structures that accept ML-KEM but where the operator wants extra protection against breaks or catastrophic bugs in ML-KEM.

draft-das-ntn-rf-execution-finality-00 Individual new -00 abstract

Argues that a LEO constellation computer can compute a transmit burst, beam command, inter-satellite forward or terminal PA enable faster than any ground reviewer can see it, and that authenticating TT&C, NTN registration or allowlists decides who may talk to the vehicle, not whether this burst may leave the aperture. Specifies a radio-side execution-finality profile: a proposed RF, ISL, beam, gateway or payload act stays a Candidate Act while a Protected Enforcement Domain binds vehicle, beam, frequency class, duration, next hop, overflight epoch and sink; the Finality Sink at the PA enable or ISL switch verifies authority just before energy leaves.

draft-das-agentic-execution-finality-01 Individual rev -01 abstract

Notes that an agentic model can emit a tool call today's runtimes treat as something to execute, and that allowlists, OAuth, MCP auth, sandboxes, filters and human approval decide whether an agent may reach a tool, not whether this generated call may take effect now. Specifies a dispatch-time gate: the call stays a Candidate Act while a Protected Enforcement Domain binds agent, tool, arguments, purpose, destination, provenance and policy epochs, then a Tool-Dispatch Finality Sink verifies scoped authority against the actual invocation just before the tool runs. Applies to support, coding, payments, clinical, SOC, browser-use and multi-agent MCP deployments.

draft-das-precision-bounded-egress-01 Individual rev -01 abstract

Argues that a device may legitimately hold an exact location while an app, SDK, AI agent, analytics library or foreign endpoint is entitled only to a coarser, delayed, randomized or no representation, and OS permission to read a fix does not decide whether it may leave the device at that precision. Defines a precision-bounded egress profile on top of execution finality: a proposed release is a Location-Release Candidate Act evaluated for purpose, requester, recipient, jurisdiction, required precision and cumulative disclosure, and the egress sink verifies scoped authority against the actual outbound payload, permitting exact data, a reduced representation or denial.

draft-das-ai-native-6g-execution-finality-01 Individual rev -01 abstract

Argues that authenticating a network function or AI controller does not establish authority for every routing, signaling, session, resource-allocation, sensing or subscriber-specific consequence it can generate. Defines an informational execution-finality profile for AI-native 5G, 5G-Advanced, IMT-2030/6G, O-RAN and AI-RAN: a proposed operation is a Network Candidate Act that stays non-effective while a Protected Enforcement Domain validates act-specific predicates and commits evidence before scoped non-bearer authority, which a Network Finality Sink verifies just before live state changes. This revision adds a JSON interoperability profile.

draft-ietf-mpls-stamp-pw-10 WG MPLS rev -10 abstract

Describes how to encapsulate the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) in MPLS networks. It covers LSPs and Pseudowires used for Layer 2 and Layer 3 services, with or without the Control Word and/or an IP/UDP header, and updates RFC 8972 by revising the STAMP Test Session Identifier for LSPs and PWs.

draft-lin-opsawg-ipfix-quic-header-05 Individual rev -05 abstract

Introduces new IP Flow Information Export (IPFIX) Information Elements to identify a set of QUIC-related information carried in the QUIC Header, QUIC Frame and Stream for traffic being forwarded.

Wednesday, August 26, 2026 · 36 drafts

draft-swhited-ogg-skeleton-02 Individual rev -02 abstract

Ogg Skeleton defines a logical bitstream providing structuring information for multitrack Ogg files. It gives clues for synchronization and content negotiation including language selection, and provides keypoint indices for optimal seeking over high-latency connections or in time-critical scenarios.

draft-yl-cats-data-model-08 Individual rev -08 abstract

Defines a YANG data model for the management of Computing-Aware Traffic Steering (CATS) systems.

draft-norton-sdlp-arch-04 Individual rev -04

By its name, this individual draft probably describes an SDLP architecture. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-fassbender-scitt-time-anchor-05 Individual rev -05 abstract

Defines a mechanism for temporal anchoring of digital artifacts by committing cryptographic hashes to the Bitcoin blockchain via the OpenTimestamps protocol. The resulting proof is independently verifiable by any party with access to validated Bitcoin chain data, without contacting the anchoring service. SCITT is used as the primary integration example, and no changes to the SCITT architecture are required.

draft-fu-memdns-pivoting-00 Individual new -00 abstract

Heterogeneous memory networks (CXL pools, HBM/DDR/SRAM hierarchies, processing-in-memory arrays) form a big memory system that exposes fragmented addressing to ML inference runtimes. Describes Memory DNS (MemDNS), a semantic-addressing framework applying DNS principles (domain names, hierarchical delegation, caching, TTL, authoritative records) to tensor data placement, deployed as limited domains (RFC 8799). It focuses on automated pivoting for replica selection, placement migration and failover driven by closed-form decision models, and specifies record semantics, resolution flow, cache/TTL behavior, delegation and pivot decision models.

draft-correctover-ccs-07 Individual rev -07 abstract

Defines the Correctover Conformance Shape (CCS), a runtime verification framework for AI agent tool calls. CCS establishes seven verification dimensions and specifies receipt formats with Ed25519 signatures, three verdict values and four executor lifecycle states. This revision promotes AEB and CAID to normative references, clarifies Ed25519 signature construction using RFC 8785 canonical JSON, and documents two independent interoperable implementations.

draft-ietf-v6ops-ipv6-app-testing-02 WG V6OPS rev -02 abstract

Provides guidance for application developers and SaaS providers on approaching IPv6 testing in dual-stack, IPv6-only and "IPv6-only-strict" scenarios without any IPv4 connectivity. It discusses common misconceptions about how far operating systems and libraries can abstract IPv6 issues away and explains common regressions to avoid when deploying IPv6 support.

Describes a profile by which an autonomous agent with no human or organisational principal at the root of its delegation chain registers itself as an economic principal in a transparency service, with that registration making it eligible to be paid for later reads of its own identity record. Admission of the agent's Signed Statement is gated on settling an HTTP 402 payment challenge, expressed as operator Registration Policy so admission stays a deterministic, replayable function of committed inputs. Informational; it occupies the owner-less seam left undefined by current agent-identity drafts.

draft-morrison-compute-location-gate-01 Individual rev -01 abstract

Specifies the compute-location gate, by which a client and an identity-inference server negotiate, at the wire layer and before any inference, where an identity inference computes, as a deterministic function of the provenance class of the input signal. Three classes are distinguished: active inference (initiated by the inferred-about principal) may compute server-side; passive aggregate observation over a minimum cohort may compute server-side but yields only population-level results; passive individual observation is local-only and never transmitted. The gate is enforced by consent-class matching and a wire-layer refusal; Informational.

draft-morrison-reviewed-by-trailer-02 Individual rev -02 abstract

Defines a trailer grammar for sovereign-portable peer review extending an identity-attributed commit grammar. It introduces one required trailer (Reviewed-By:) and three optional companions (Review-Stance:, Review-Of:, Witnessed-By:) that bind a Sovereign-tier handle to a specific review act over a specific content artefact, Ed25519-signed. It applies to git commits, document manifests, pre-prints and patent disclosures, accrues reviewer reputation on the portable sovereign handle, and supports pseudonymous review; positioned as complementary to CRediT, ORCID and DOI.

draft-morrison-identity-accord-02 Individual rev -02 abstract

Specifies the Identity Accord Protocol, a peer ceremony by which two principals, each represented by an organisational identity substrate and acting under a recorded delegation from a legal entity, execute a bilateral agreement as a portable, self-verifying COSE-signed CBOR document. It composes DNS-based substrate discovery, Ed25519 signatures, an append-only identity log and a tamper-evidence descriptor quorum into one third-party-verifiable artefact needing no central registry or designated verifier. The canonical target is a mutual NDA, generalizing to any bilateral consent envelope; Informational.

Specifies a wire-level annotation grammar by which an LLM output may carry, at emission and at the granularity of an individual assertion, a provenance label from a closed enumerated vocabulary of substrate-class identifiers. It defines the vocabulary, the per-assertion attachment form, the admissibility discipline a relying party may apply, and two terminal states, UNVERIFIED-INFERENCE and DECAYED-TO-UNCERTAINTY. It does not specify what an inference system must do, only the wire grammar to inspect what it did with the substrates it consulted; Informational.

draft-li-cats-idn-01 Individual rev -01 abstract

Introduces the Intelligence Delivery Network (IDN), a network architecture that treats intelligence capabilities as network services that can be described, placed, routed to, reused and secured across distributed heterogeneous computing nodes, to support scalable, latency-aware and privacy-enhanced AI inference. It describes motivation, deployment assumptions, system model, architectural components, terminology and security considerations, leaving protocol details to future documents.

draft-morrison-consent-settlement-05 Individual rev -05 abstract

Specifies an extension to HTTP-native agent payment protocols by which the disclosure of an identity attribute about a human subject is bound to that subject's recorded consent and settled, in part, to that subject.

draft-eastlake-dnsop-rfc2930bis-tkey-06 Individual rev -06 abstract

RFC 8945 authenticates DNS messages with shared secret keys and the TSIG resource record but offers no way to set up such keys other than by configuration. Specifies the Transaction Key (TKEY) RR to establish shared secret keys between a DNS resolver and server, obsoleting RFC 2930.

draft-kushwaha-scim-tenant-resource-00 Individual new -00 abstract

Defines a SCIM extension for tenant-aware identity provisioning. It introduces a "Tenant" resource type, tenant-membership extensions for User and Group resources, a lifecycle state machine for tenants and memberships, tenant-scoped uniqueness discovery, a normative tenant-context resolution rule, concurrency requirements, tenant-aware filtering and an optional region-aware metadata profile. It is backward compatible with SCIM 2.0 and aimed at multi-tenant SaaS, cloud identity, B2B identity and multi-region deployments.

draft-reddy-seat-expat-transport-02 Individual rev -02 abstract

Defines a binary, application-layer transport protocol for exchanging Exported Authenticator messages between two peers over TLS, providing the signaling to initiate and complete post-handshake authentication at the application layer without modifying TLS. Primarily intended for attestation exchange but generic, it specifies conveying messages as Capsules over HTTP using Extended CONNECT (HTTP/2 and HTTP/3), and a "Shim Mode" operating directly over TLS or DTLS 1.3 without an HTTP binding.

draft-agentic-ai-usecases-requirements-02 Individual rev -02 abstract

Describes use cases for agentic AI communication systems and derives protocol requirements from them, intended to guide IETF standardization on agent-to-agent and agent-to-tool communication, with focus on multimodal communication, session management, discovery, communication security, and agent identity and authentication.

Defines the Identity Continuation Assertion, a short-lived, sender-constrained JWT used as an OAuth 2.0 Token Exchange subject token. It lets an IdP Authorization Server issue an onward Identity Assertion JWT Authorization Grant (ID-JAG) when a user's request crosses service boundaries after the user is no longer present, targeting deployments where several Resource Authorization Servers trust one IdP and use audience-local subject identifiers only the IdP can resolve.

BGP FlowSpec distributes traffic filtering and steering rules across BGP networks. Specifies FlowSpec procedures to steer matching flows into Segment Routing Policies, defining mechanisms that combine FlowSpec NLRIs with specific BGP Extended Communities for transport-policy steering in SR-MPLS and SRv6 (Mode 1), and optionally with the BGP Prefix-SID Attribute when egress service-action execution is required in SRv6 (Mode 2).

By its name, this SPRING working-group draft probably concerns grouping of Segment Routing (SR) Policies. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-dogru-cedulon-01 Individual rev -01 abstract

Defines the Cedulon Protocol, an audit layer for agent-to-agent commerce. Payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2) already move value but do not by themselves produce a fail-closed policy check and a signed spend receipt reconcilable against a rail extract. Cedulon specifies a signed Trade Manifest, a default-deny Policy Decision Point, a COSE/CWT Spend Receipt, epoch checkpoints and rail-extract reconciliation, plus a Dispute Evidence Bundle and optional SCITT anchoring. It sits above x402 and AP2 rather than competing with them.

draft-ietf-emailcore-as-30 WG EMAILCORE rev -30 abstract

Electronic mail is one of the oldest Internet applications still in active use. This Applicability Statement describes the relationship among the many protocols that have supplemented the core mail transport and message-format protocols over the years, and provides guidance and recommendations for using features of the core protocols.

draft-ietf-mpls-mna-ioam-12 WG MPLS rev -12 abstract

Uses MPLS Network Actions (MNA) mechanisms to collect and transport operational state and telemetry with In situ OAM (IOAM) data-fields, including IOAM Direct Export (IOAM-DEX, RFC 9326). It builds on IOAM (RFC 9197) Option-Types such as Pre-allocated Trace, Proof of Transit, Edge-to-Edge and Incremental Trace, letting MPLS carry the actions and data needed to compute performance metrics.

draft-vmhosting-fi-nameservers-00 Individual new -00 abstract

Describes an operational framework for service providers that operate authoritative DNS services, domain name registration services, or both. It covers DNS zone provisioning, authoritative name-server operation, delegation management, service availability, DNSSEC, registration lifecycle operations, access control, monitoring, incident response, abuse handling and privacy, without defining any new DNS or registry protocol or registration policy.

draft-reilly-web4-00 Individual new -00

By its name, this individual draft probably sets out a "Web4" concept. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-kennedy-dnssd-data-block-01 Individual rev -01 abstract

The DNS-SD Data Block (DDB) is a compact TLV-encoded container for conveying DNS-SD service information over non-IP transports used by short-range peer-to-peer or proximity-based advertisement and discovery technologies, such as the Bluetooth Low Energy Transport Discovery Service or NFC Verb NDEF Records.

draft-kennedy-dnssd-data-block-00 Individual new -00 abstract

The DNS-SD Data Block (DDB) is a compact TLV-encoded container for conveying DNS-SD service information over non-IP transports used by short-range peer-to-peer or proximity-based advertisement and discovery technologies, such as the Bluetooth Low Energy Transport Discovery Service or NFC Verb NDEF Records.

Specifies a method of encoding quality of communication service (QoS) requirements in a DNS query by including the requirements in one or more labels of the queried name. This enables DNS responses with addressing and packet-labeling information dependent on those requirements, without changing the format of DNS protocol messages or DNS APIs.

By its name, this NMOP-related individual draft probably defines a BMP telemetry message. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-eastlake-dnsop-rrtype-srv6-10 Individual rev -10 abstract

Specifies a DNS Resource Record type for storing IPv6 Segment Routing (SRv6) information in the DNS.

By its name, this NMOP-related individual draft probably concerns scoping of telemetry identifiers. The official abstract page could not be opened this run (HTTP 404 on the fast source), so this description is approximate and will be grounded on the next run.

draft-das-child-safe-rendering-finality-00 Individual new -00 abstract

Notes that online child-safety controls usually operate before the final rendering boundary, and an upstream decision does not guarantee content cannot later be decrypted, composited, rendered, forwarded or mirrored through another path. Defines a protected rendering execution-finality architecture for age-restricted content: a proposed rendering is a Restricted Content Candidate Act that stays non-renderable until a Protected Enforcement Domain validates recipient, content, device, policy, eligibility, freshness and revocation predicates, then a Rendering Finality Sink verifies scoped authority right before content becomes perceptible. The principle: permission to deliver is not permission to render.

draft-das-agentic-execution-finality-00 Individual new -00 abstract

Notes that an agentic model can emit a tool call today's runtimes treat as something to execute, and that allowlists, OAuth, MCP auth, sandboxes, filters and human approval decide whether an agent may reach a tool, not whether this generated call may take effect now. Specifies a dispatch-time gate: the call stays a Candidate Act while a Protected Enforcement Domain binds agent, tool, arguments, purpose, destination, provenance and policy epochs, then a Tool-Dispatch Finality Sink verifies scoped authority against the actual invocation just before the tool runs. Applies to support, coding, payments, clinical, SOC, browser-use and multi-agent MCP deployments.

draft-das-precision-bounded-egress-00 Individual new -00 abstract

Argues that a device may legitimately hold an exact location while an app, SDK, AI agent, analytics library or foreign endpoint is entitled only to a coarser, delayed, randomized or no representation, and OS permission to read a fix does not decide whether it may leave the device at that precision. Defines a precision-bounded egress profile on top of execution finality: a proposed release is a Location-Release Candidate Act evaluated for purpose, requester, recipient, jurisdiction, required precision and cumulative disclosure, and the egress sink verifies scoped authority against the actual outbound payload, permitting exact data, a reduced representation or denial.

draft-das-ai-native-6g-execution-finality-00 Individual new -00 abstract

Argues that authenticating a network function or AI controller does not establish authority for every routing, signaling, session, resource-allocation, sensing or subscriber-specific consequence it can generate. Defines an informational execution-finality profile for AI-native 5G, 5G-Advanced, IMT-2030/6G, O-RAN and AI-RAN: a proposed operation is a Network Candidate Act that stays non-effective while a Protected Enforcement Domain validates act-specific predicates and commits evidence before scoped non-bearer authority, which a Network Finality Sink verifies just before live state changes. This revision adds a JSON interoperability profile.