IETF Daily Digest — New Internet-Drafts & RFCs

Coverage window: last 48 hours (2026-08-31 to 2026-09-02, UTC) · all working groups · generated 2026-09-02

103 drafts1 RFC0/103 drafts with official abstractPublished: https://ietf-drafts-ok.pages.dev

Newly published RFCs

2026-08-31
RFC 10042RFC streampublished
Post-Quantum/Traditional Hybrid Key Exchange with the Module-Lattice-Based Key-Encapsulation Mechanism for Use in SSH

This RFC specifies a post-quantum/traditional hybrid key exchange for the Secure Shell (SSH) protocol, combining a Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM, FIPS 203) with a traditional key-exchange method. The hybrid construction ensures the session remains secure as long as either component remains unbroken, providing resistance to future quantum attacks while retaining today's classical security. It defines the negotiated key-exchange method name(s), how the ML-KEM and classical shared secrets are combined into the SSH exchange hash and session keys, and the message flow between client and server. The summary here is grounded in the official RFC title; the full official Abstract could not be retrieved on this run.

Drafts

2026-09-02
draft-cmcc-asrp-07Individualrev -07

By its name this Individual submission defines 'ASRP', an application- or service-level routing/relay protocol. At revision 07 the specification is fairly mature. Without the official abstract the exact acronym expansion and scope cannot be confirmed; treat the mechanism, message set and target deployment as unverified until grounded on the next run.

A first (-00) Individual draft that appears to define a URI scheme for identifying software 'agents' together with a credential/enrolment notion ('creduent'). It likely specifies the URI syntax and how an agent's credentials or identity are referenced. Details of resolution, authentication and registration are not confirmed here and should be read from the document itself.

LAMPS working-group document on composite post-quantum Key-Encapsulation Mechanisms: combining a post-quantum KEM (such as ML-KEM) with a traditional algorithm into a single composite KEM for use in PKIX/CMS. At -21 it is well advanced. This run could not read the official abstract, so exact algorithm combinations and OIDs are unverified.

2026-09-01

A new (-00) Individual draft that, by its name, describes a 'card' data structure for a bot-centric identity or directory service ('botcentral'). It probably defines fields describing an automated client/bot. The concrete schema and use cases are approximate pending the official abstract.

draft-feria-sas-01Individualrev -01

Individual draft using the short handle 'SAS'. The acronym is ambiguous (could be a Spectrum Access System, a Simple Authentication Scheme, etc.), so no confident summary is possible from the name alone. Read the document for the actual definition; treated here as approximate.

LSR working-group draft defining a YANG data model for configuring and managing OSPF extensions that support SRv6 (Segment Routing over IPv6). It complements the base OSPFv3 YANG model with SRv6 locators, SIDs and related state. At -10 it is a stable WG item; specific model contents are unverified without the abstract.

Individual draft in the NFSv4 space describing use of DANE (DNS-Based Authentication of Named Entities) to authenticate RPC-over-TLS connections. It probably explains how NFS clients/servers use TLSA records to validate peer certificates. Specifics of the profile are approximate here.

LAMPS working-group draft that updates RFC 6211 (the CMS Algorithm Identifier Protection Attribute), likely to cover newer algorithms such as post-quantum signatures/KEMs or to clarify processing rules. As a -00 it is an early WG revision; the precise changes are unverified pending the abstract.

Individual -00 draft that by its name applies TLS 1.3 to a 'STB' context (plausibly set-top boxes or a similar constrained device profile). It probably profiles TLS 1.3 usage for that environment. The exact scope and constraints are approximate.

Individual draft (author handle 'intra') concerning handshake-failure signalling, most likely in TLS or a similar security handshake. At -18 it is heavily iterated. Without the abstract the exact failure conditions and remediation it defines are not confirmed.

MPLS working-group draft on running STAMP (Simple Two-way Active Measurement Protocol) over pseudowires, enabling performance measurement (delay/loss) across PW services. Multiple revisions appeared in the window (up to -16). Exact encapsulation and TLVs are unverified pending the official abstract.

A new (-00) Individual draft addressing identity and conformance requirements for AI systems/agents. It probably lays out identity attributes and conformance criteria an AI actor must satisfy. Concrete requirements are approximate from the title.

Carsten Bormann Individual draft advancing CDDL 2.0 — the next generation of the Concise Data Definition Language used to describe CBOR/JSON data structures. At -09 it collects the 2.0 feature set. Specific new language features are unverified without the abstract.

draft-saha-aadp-02Individualrev -02

Individual draft using the acronym 'AADP'. The expansion is not derivable with confidence from the name, so no reliable summary is possible; treated as approximate pending the document text.

IDR working-group draft defining BGP-based discovery of SD-WAN edge devices, i.e. how edges advertise and learn reachability/attributes to establish overlay tunnels. At -30 it is highly mature. Exact NLRI/attribute encodings are unverified pending the abstract.

Bormann Individual draft applying CDDL (Concise Data Definition Language) to CSV-structured data, probably specifying how to describe/validate tabular CSV content with CDDL. Details of the mapping are approximate from the name.

ACME working-group -00 draft introducing a proof-of-possession ('pop') mechanism within the ACME certificate-issuance protocol, likely so a client can demonstrate control of a key or prior credential. Exact challenge/flow definitions are unverified pending the abstract.

Individual draft in the IVY (hardware inventory/asset YANG) problem space, describing how equipment capabilities are modelled and applied. It probably defines capability descriptors for network hardware. Concrete YANG/schema details are approximate.

Individual draft associated with NMOP (Network Management Operations) that lays out generalized principles for expressing device/service capabilities in management interfaces. The precise principles are unverified without the abstract.

NFSv4 working-group draft defining a mechanism to mark or handle files that must not be cached by clients, ensuring reads/writes go to the server. At -12 it is a stable WG item. Exact protocol attributes are unverified pending the abstract.

Individual CCAMP-related draft stating the problem of sharing optical-impairment information (e.g. for impairment-aware path computation in optical networks). As a problem statement it frames requirements rather than a solution. Details approximate from the title.

Individual CFRG (Crypto Forum) draft on strong existential unforgeability (SUF) of hybrid signatures that combine post-quantum and classical schemes. It likely analyses constructions that preserve SUF. Specific constructions/claims are unverified pending the abstract.

TEAS working-group draft defining a YANG data model for MPLS Traffic Engineering topology, augmenting the generic TE topology model with MPLS-specifics. At -05 it is a maturing WG item. Exact model contents are approximate without the abstract.

A new (-00) Individual draft concerning the admissibility of scientific/technical evidence (plausibly digital-forensics or attestation evidence). It probably sets criteria for evidence to be considered reliable. Scope is approximate from the title.

PIM working-group draft on zero-configuration assignment of IPv6 multicast addresses/related parameters. At -11 it is well developed. The exact assignment algorithm and scopes are unverified pending the abstract.

WEBBOTAUTH working-group -00 draft defining a protocol for authenticating web bots using HTTP Message Signatures, so servers can verify an automated client's identity. Exact signature parameters and directory mechanisms are unverified pending the abstract.

Individual draft in the OCM (Open Cloud Mesh) space describing federated groups built on MLS (Messaging Layer Security), i.e. cross-organization group membership/keying. Concrete federation and MLS integration details are approximate.

Individual OCM (Open Cloud Mesh) draft specifying an integration protocol between cloud/collaboration services for federated file sharing. The exact API and message flows are unverified pending the abstract.

OCM working-group draft defining the core Open Cloud Mesh protocol for federated sharing of resources between independent cloud platforms. At -07 it is an established WG document. Exact endpoints and payloads are approximate without the abstract.

A new (-00) Individual draft on Coordinated Vulnerability Disclosure (CVD) policy, likely describing how organizations publish/express a CVD or security-contact policy. Concrete format details are approximate from the name.

Individual CCAMP draft defining a YANG model for client-layer performance monitoring in transport networks. At -15 it is well iterated. Exact PM counters and structure are unverified pending the abstract.

CCAMP working-group draft defining a YANG data model to drive optical path computation (impairment-aware routing in WSON/optical networks). At -09 it is a maturing WG item. Specific model contents are approximate without the abstract.

Individual OAuth draft describing binding of a token or credential to a subject's key ('subject key binding'), likely to prevent token theft/replay by proving key possession. Exact binding mechanism is unverified pending the abstract.

Individual CCAMP draft revising RFC 8561 (a YANG data model for microwave radio-link interfaces), i.e. a '-bis' update to that model. Two revisions (-01, -02) appeared in the window. Exact model changes are unverified without the abstract.

Individual CCAMP draft revising RFC 8561 (a YANG data model for microwave radio-link interfaces), i.e. a '-bis' update to that model. Two revisions (-01, -02) appeared in the window. Exact model changes are unverified without the abstract.

Individual draft defining management of agents under 'SAMP'. The acronym is not confidently expandable from the name; it likely covers lifecycle/management operations for software agents. Scope treated as approximate.

Individual OPSAWG draft defining IPFIX Information Elements to export flow records for RoCEv2 (RDMA over Converged Ethernet v2) traffic, aiding visibility of RDMA flows. Exact IE definitions are unverified pending the abstract.

Individual draft describing how to carry L2VPN services over an SRv6 (Segment Routing over IPv6) data plane. Revisions -01 and -02 appeared in the window. Exact encapsulation/signalling details are approximate without the abstract.

A new (-00) Individual draft (one of several by this author on agent/AI communication) addressing discovery and 'communication finality' for a mapping/agent system. The concrete mechanism is not confirmable from the name; treated as approximate.

Individual TLS draft on using composite ML-DSA signatures (post-quantum ML-DSA combined with a classical signature) for authentication in TLS. At -12 it is well iterated. Exact code points and negotiation are unverified pending the abstract.

DMM working-group draft defining an architecture for mobility management using an SRv6 data plane (SRv6 for mobile user-plane / N3-N9 style forwarding). At -04 it is a developing WG item. Architectural specifics are approximate without the abstract.

draft-surampudi-wtx1-01Individualrev -01

Individual draft with the opaque handle 'wtx1'; the name gives no reliable indication of its subject. No confident summary is possible; read the document itself. Treated as approximate.

Individual IDR/BGP FlowSpec draft describing a community-based filter tied to 'SIP' (session/service identifier or SIP signalling) traffic, i.e. FlowSpec rules matched or scoped by a community. Exact FlowSpec component types are unverified pending the abstract.

A new (-00) Individual RATS draft on a composite Entity Attestation Token (EAT), combining multiple attestation claims/evidence into one token. Exact claim structure is approximate from the name.

Individual draft describing how to carry L2VPN services over an SRv6 (Segment Routing over IPv6) data plane. Revisions -01 and -02 appeared in the window. Exact encapsulation/signalling details are approximate without the abstract.

Individual draft (part of an 'ALTER/identity' suite by this author) on command authority in an operational-technology (OT) context, likely governing who may issue commands. Concrete mechanism is approximate.

Individual draft in the author's 'ALTER' framework covering organizational policy provisioning. It probably defines how policies are provisioned/altered for an organization. Specifics are unverified pending the abstract.

Individual draft defining a 'binding moment envelope' — plausibly a signed container binding an action to a point in time within the author's identity/authority framework. Exact envelope format is approximate.

Individual draft describing an 'identity accord', likely an agreement/framework for asserting and reconciling identities across parties. Concrete structure is approximate from the name.

Individual draft defining an 'alter' URI scheme used within the author's identity/authority framework to reference altered resources or policies. Exact syntax/resolution is unverified pending the abstract.

2026-08-31

Individual draft (agent/AI theme) defining an 'action-evidence boundary' — plausibly delimiting where evidence for an action is captured and trusted. At -05 it is iterated. Concrete definition is approximate.

PIM working-group draft; 'GAAP' denotes a specific PIM mechanism (a group-address assignment/advertisement protocol). At -21 it is a mature WG item. Exact message set and behaviour are unverified pending the abstract.

MPLS working-group draft on running STAMP (Simple Two-way Active Measurement Protocol) over pseudowires, enabling performance measurement (delay/loss) across PW services. Multiple revisions appeared in the window (up to -16). Exact encapsulation and TLVs are unverified pending the official abstract.

Individual RATS draft on composition of attestation ('AEP composition'), i.e. combining attestation results/evidence from multiple components. Exact composition rules are approximate without the abstract.

OAuth working-group draft defining SD-JWT-based Verifiable Credentials (SD-JWT VC): a data format for selectively-disclosable credentials built on Selective Disclosure JWTs. At -19 it is well advanced and widely referenced. Exact claim/format rules are unverified pending the abstract.

Individual RATS draft on conveying geographic information in attestation results, likely so a verifier can express or a relying party can consume location-related attestation output. Concrete claims are approximate.

Individual RATS draft describing composite attesters — devices/systems composed of multiple attesting subcomponents and how their evidence is combined. Exact model is unverified pending the abstract.

MOQ (Media Over QUIC) working-group draft specifying the MOQ Transport protocol for low-latency media delivery over QUIC, defining the publish/subscribe object model and control/data streams. At -20 it is a central, mature WG document. Exact wire details are approximate without the abstract.

A new (-00) Individual SCITT (Supply Chain Integrity, Transparency and Trust) draft on a checkpointed local transparency log, likely enabling verifiable local logging with periodic checkpoints. Exact log/checkpoint format is approximate.

IPSECME working-group draft defining IKEv2 signalling/negotiation for EESP (the Enhanced Encapsulating Security Payload). It specifies how peers negotiate EESP via IKEv2. At -03 it is developing. Exact notify/transform details are unverified pending the abstract.

IPSECME working-group draft defining EESP, an Enhanced Encapsulating Security Payload that extends/updates the classic ESP with new features (e.g. more flexible headers). At -04 it is a maturing WG item. Exact header format is approximate without the abstract.

Individual draft on source privacy in a 'CFR' context, likely protecting the identity/address of a traffic source. The exact mechanism and 'CFR' expansion are not confidently derivable; treated as approximate.

A new (-00) Individual draft (agent theme) on evidence for control/delivery of agent actions, plausibly proving that a control instruction was delivered/executed. Concrete definition is approximate from the name.

IPSECME working-group draft defining an IKEv2 extension to negotiate 'Diet-ESP', a compressed/minimized ESP for constrained/IoT networks. At -08 it is iterated. Exact negotiation parameters are unverified pending the abstract.

Individual IPSECME draft addressing DSCP handling with a 'non-protected'/np notion in IPsec, i.e. how DiffServ code points are treated across the tunnel. Exact behaviour is approximate without the abstract.

CCAMP working-group draft defining a YANG data model for OTN (Optical Transport Network) slicing, enabling partition of OTN resources into slices. At -12 it is well developed. Exact model contents are approximate.

Individual draft (agent/6G theme) on query-scoped communication handles for a 6G/agent system, plausibly identifiers scoped to a particular query/interaction. Concrete semantics are approximate from the name.

IPSECME working-group draft defining Diet-ESP, a compressed variant of ESP that reduces per-packet overhead for constrained/IoT deployments while preserving security. At -11 it is a mature WG item. Exact compression rules are unverified pending the abstract.

draft-dogru-cedulon-06Individualrev -06

Individual draft with the coined term 'cedulon'; the name does not reliably indicate the subject. Revisions -05 and -06 appeared in the window. No confident summary is possible; treated as approximate.

Carsten Bormann Individual draft titled 'restatement', plausibly restating/consolidating an existing specification or set of conventions in a clearer form. Exact target is not confirmable from the name; approximate.

Individual draft (agent theme) on 'derived authority' carried in an 'agent envelope', likely a signed container conveying delegated authority to an agent. Concrete format is approximate without the abstract.

Individual REGEXT draft defining an RDAP extension for expressing a set of statuses on registration objects, refining how status values are conveyed. Exact JSON structures are unverified pending the abstract.

Individual REGEXT draft defining server-side validation behaviour/extension for RDAP, plausibly how a server validates or advertises validation of query parameters or objects. Exact rules are approximate.

MPLS working-group draft on running STAMP (Simple Two-way Active Measurement Protocol) over pseudowires, enabling performance measurement (delay/loss) across PW services. Multiple revisions appeared in the window (up to -16). Exact encapsulation and TLVs are unverified pending the official abstract.

A new (-00) Individual OAuth draft on delegation to software agents, likely defining how a user/service delegates OAuth authority to an autonomous agent. Exact grant/flow is approximate from the name.

A new (-00) Individual OAuth draft (parallel proposal) on agent delegation of OAuth authority, describing how delegated permissions are granted to and constrained for an agent. Concrete mechanism is unverified pending the abstract.

Individual WIMSE (Workload Identity in Multi-System Environments) draft on cross-organization delegation of workload identity/authority. It probably defines how delegated trust spans organizational boundaries. Specifics are approximate.

Individual draft on making agent-to-agent conversations verifiable, plausibly by signing/attesting exchanged messages so they can be audited. Exact evidence format is approximate without the abstract.

draft-cowles-ward-00Individualnew -00

Individual -00 draft with the short handle 'ward'; the name alone does not reliably indicate the subject. No confident summary is possible; treated as approximate pending the document text.

draft-cowles-volt-01Individualrev -01

Individual draft with the short handle 'volt'; subject not reliably derivable from the name. Treated as approximate; read the document for the actual definition.

draft-cowles-aocl-01Individualrev -01

Individual draft using the acronym 'AOCL', which is not confidently expandable from the name. No reliable summary is possible; treated as approximate.

draft-cowles-aee-01Individualrev -01

Individual draft using the acronym 'AEE', not confidently expandable from the name. No reliable summary is possible; treated as approximate pending the document.

A new (-00) Individual RATS-themed draft naming specific AI providers, apparently about extraction of attestation/evidence for frontier AI models. The concrete mechanism is speculative from the name and should be read directly; treated as approximate.

Individual RATS-themed draft on 'extraction' relating to frontier AI models — plausibly gathering attestation evidence about large models. Revisions -00 through -02 appeared in the window. Concrete definition is approximate.

Individual draft on binding agentic tools, likely how an AI agent's available tools are cryptographically or policy-bound to the agent. Exact binding mechanism is approximate without the abstract.

Individual RATS-themed draft on 'extraction' relating to frontier AI models — plausibly gathering attestation evidence about large models. Revisions -00 through -02 appeared in the window. Concrete definition is approximate.

Individual GROW draft on enhanced Autonomous System (AS) loop detection in BGP, improving on AS_PATH-based loop prevention. At -09 it is iterated. Exact detection algorithm is unverified pending the abstract.

Individual RATS-themed draft on 'extraction' relating to frontier AI models — plausibly gathering attestation evidence about large models. Revisions -00 through -02 appeared in the window. Concrete definition is approximate.

Individual draft on 'compliance receipts' under an 'ASQAV' framework, plausibly verifiable receipts attesting compliance of an action/process. The acronym is not confidently expandable; treated as approximate.

A new (-00) Individual draft defining 'JSOX', apparently a data serialization/format (JSON-adjacent). The exact grammar and goals are not derivable from the name; treated as approximate.

draft-dogru-cedulon-05Individualrev -05

Individual draft with the coined term 'cedulon'; the name does not reliably indicate the subject. Revisions -05 and -06 appeared in the window. No confident summary is possible; treated as approximate.

TEAS working-group draft on the applicability of ACTN (Abstraction and Control of TE Networks) to Packet Optical Integration (POI). At -20 it is a mature WG document giving deployment guidance. Exact scenarios are approximate without the abstract.

Individual BESS draft extending EVPN for 'EVN6' (an IPv6-based enhanced virtual network approach). It probably defines EVPN routes/attributes for that scheme. Exact encodings are unverified pending the abstract.

draft-xls-intarea-evn6-06Individualrev -06

Individual INTAREA draft on 'EVN6', an IPv6-based enhanced/virtual networking approach at the internet-area layer. Concrete architecture and headers are approximate from the name.

Individual draft (agent/safety theme) on 'child-safe rendering' with a 'finality' property, plausibly ensuring rendered content meets child-safety constraints irreversibly. Revisions -02/-03 appeared. Concrete mechanism is approximate.

Individual OPSAWG draft defining IPFIX Information Elements for Source Address Validation (SAV), enabling export of SAV-related flow information for anti-spoofing visibility. Exact IE definitions are unverified pending the abstract.

Individual draft (agent/safety theme) on 'child-safe rendering' with a 'finality' property, plausibly ensuring rendered content meets child-safety constraints irreversibly. Revisions -02/-03 appeared. Concrete mechanism is approximate.

Individual PCE draft extending PCEP to support Source Address Validation (SAV), plausibly signalling SAV rules/state via the Path Computation Element protocol. Exact objects/TLVs are approximate.

IDR working-group draft extending BGP-LS to advertise inter-AS topology information, improving cross-domain topology visibility for TE/controllers. At -40 it is very mature. Exact TLVs are unverified pending the abstract.

Individual SCIM draft defining cursor-based pagination for attribute/resource queries, an alternative to index-based paging for large SCIM result sets. Exact query parameters are approximate without the abstract.

A new (-00) Individual SIDROPS draft on exporting BGP 'point-of-view' (POV) data via IPFIX, plausibly to observe RPKI/route-origin validation state per flow. Concrete IEs are approximate.

Individual CATS (Computing-Aware Traffic Steering) draft on network scheduling among 'intelli-nodes' (compute-capable nodes), steering traffic based on compute/network metrics. Exact scheduling signals are approximate.

Individual CATS draft on an 'AI semantic contract' for computing-aware traffic steering, plausibly a semantic agreement describing service/compute requirements. Concrete contract format is approximate without the abstract.