Extends BGP Flow Specification (RFC 8955/8956) so that matching traffic flows can be steered into Segment Routing Policies (RFC 9256). It defines normative procedures for combining FlowSpec NLRI with the BGP Prefix-SID Attribute (RFC 8669/9252) and specific BGP Extended Communities (RFC 9012) to signal both SR-MPLS and SRv6 policy steering pathways, giving operators a BGP-native way to bind filtered flows to explicit SR paths.
Specifies how two composite post-quantum signature schemes are integrated into the Secure Shell (SSH) protocol. Each scheme pairs the Module-Lattice Digital Signature Algorithm (ML-DSA) with an elliptic-curve algorithm (Ed25519 and ECDSA respectively) so that SSH host and user authentication resists both quantum and classical adversaries during the migration period, rather than relying on a single algorithm family.
The official Abstract could not be retrieved (the ietf.org/archive/id page returned 404 at run time), so this summary is approximate and drawn from the draft name only. This is an individual submission ('reilly-mws'); by its name it probably defines an 'mws' mechanism or service, but the specific scope, protocol, and technical content cannot be stated reliably here. It will be grounded from the Abstract on the next run once the page is reachable.
Describes EAP-PPT version 1, an Extensible Authentication Protocol method that uses a Privacy Pass token (RFC 9576) for client authentication within EAP (RFC 3748). Privacy Pass is a privacy-preserving authentication and authorization mechanism, and the draft requires EAP-PPT to run only inside a tunnel-based EAP method, so the token exchange is protected by an outer TLS tunnel.
Specifies a Best Current Practice for how IETF Working Groups make decisions, updating Section 3.3 of RFC 2418. It is a process document aimed at clarifying and codifying the rules groups follow when reaching decisions, rather than defining any on-the-wire protocol.
Defines a protocol by which on-path network elements can communicate their view of the maximum sustainable throughput for QUIC flows to the endpoints. This throughput advice suggests an upper bound on long-term average throughput and is explicitly independent of, and complementary to, real-time congestion-control signals, letting the network hint at a sustainable rate without interfering with existing congestion control.
States that the AERO (Automatic Extended Route Optimization) and OMNI (Overlay Multilink Network Interface) functional specifications are mature enough to advance in the RFC publication process. This draft is the first amendment documenting updates to the base specifications, with additional amendments to follow as needed. (Two revisions, -11 and -12, were both announced on 2026-08-20 and share this Abstract.)
Updates RFC 9111 to keep HTTP integrity fields correct across cache operations. Because caches update stored fields, combine partial responses, and synthesize responses, an Integrity field value can end up attached to different content than it originally covered. The draft defines field-specific maintenance for Content-Digest, Repr-Digest and Unencoded-Digest across 304/HEAD freshening, partial-response combination, cache-generated 304/HEAD/206 responses, and content-coding transformations. It adds no new fields, status codes, cache directives, validators, or digest algorithms.
Defines the Coverage Attestation Profile (CAP-1): a tool-agnostic vocabulary for stating what an examination did and did not examine, and why. A conforming document declares one or more populations, a declared denominator for each, and an individual accounting for every unit not examined, drawn from a closed set of dispositions; a remainder that reconciles only by arithmetic is refused. The goal is to distinguish 'nothing was observed in this bounded, stated-depth population' from an unqualified claim about the world.
Defines 'domain-set', a mechanism for a domain owner to declare, in a machine-readable and verifiable way, which domains belong to the same organization. A DNS TXT record is the discovery point and either lists members directly or references an HTTPS-retrieved Domain Set Manifest. Links require mutual attestation (both domains must name each other) over an authenticated channel via DNSSEC or the Web PKI, letting browsers, security tooling and AI systems answer 'are these two domains run by the same organization?' from owner-published data rather than inference.
States that the AERO (Automatic Extended Route Optimization) and OMNI (Overlay Multilink Network Interface) functional specifications are mature enough to advance in the RFC publication process. This draft is the first amendment documenting updates to the base specifications, with additional amendments to follow as needed. (Two revisions, -11 and -12, were both announced on 2026-08-20 and share this Abstract.)
Provides recommendations for formatting SRv6 locators. It introduces the concepts of Blocks, Sets, and Node IDs and explains how summarization boundaries and flexible-algorithm support can be implemented for both small and large networks, giving operators a structured approach to SRv6 address plan design.
Defines two evidence structures for automated data-access auditing under the SCITT architecture. Transformation Evidence records which data classes were transformed during disclosure (actions and counts, without revealing values); Coverage Reconciliation compares a data source's own activity counters against gateway receipts over a time window, classifying each item as matched, unreceipted, receipted-without-observation, excluded, or indeterminate. Both are meant to be registered as Signed Statements on a Transparency Service; the draft defines only the evidence payloads, not receipt or signature formats.
Extends BGP SR Policy so that an individual segment list within an SR Policy candidate path can carry its own identifier. Segment Routing indicates the forwarding path at the ingress node, and an SR Policy is a set of candidate paths each made of one or more segment lists; this draft defines the BGP extensions to signal a segment-list identifier, aiding correlation and operational tracking of individual lists.
Defines requirements for session-based and sessionless interactions between entities (in an agent-protocol context). For session-based interactions it covers transport-independent interaction binding, endpoint authentication, capability negotiation, session establishment, authorization, and lifecycle management. It frames a session as a bilateral association and places third-party coordination and management functions outside the scope of these base requirements.
Defines the Agent Action Decision Protocol (AADP), which separates per-action authorization from an agent's identity and standing capabilities. It answers whether a specific proposed action, with specific argument values, may run now given mutable state such as budgets, live reservations, approval lifecycle, and a kill switch. AADP specifies a two-phase wire contract between a Policy Decision Point and Policy Enforcement Points: machine-readable verdicts, fail-closed obligations, atomic budget reservation, an approval lifecycle, idempotency, re-derivable evidence, and invariants including that irreversible actions are never executed autonomously. It is transport-agnostic.
The official Abstract could not be retrieved (the ietf.org/archive/id page returned 404 at run time), so this summary is approximate and based on the draft name only. This is an individual submission from 'helmprotocol' describing something named 'tttps'; by its name it probably defines a transport or transfer protocol, but the precise scope and mechanisms cannot be stated reliably here and no specifics are invented. It will be grounded from the Abstract on the next run once the page is reachable.
Defines an OAuth 2.0 extension that lets Authorization Servers take Attestation Results presented by native applications into account when issuing access grants. By factoring in the security characteristics of the application and its execution environment, the mechanism supports authorization policies tailored to how trustworthy the native app is, tightening access decisions for mobile and desktop clients.
Defines a Cryptographic Message Syntax (CMS) profile for Discard Origin Authorizations (DOAs) in the RPKI. A DOA is a signed object letting an IP address-block holder authorize an Autonomous System to originate routes to prefixes tagged with a specific set of BGP Communities, signalling a request to discard traffic destined to the tagged prefix. It gives a verifiable, RPKI-anchored way to express discard/blackhole intent.
Defines metadata tags for describing aspects of Contra, Square, and other traditional called folk dances. The tags are intended for archivists as well as present-day callers of traditional dances, providing a shared vocabulary for cataloguing and retrieving dance material.
Defines a multi-track profile of the Matroska container format for distributing audio 'stems' for live DJ mixing. It targets DJ applications, Digital Audio Workstations, and multi-track recorders while remaining backwards-compatible with existing media players, so multi-stem content can be shipped in one file without breaking ordinary playback.
Defines a YANG module file-name convention. The convention extends the module file name with the revision date and a YANG semantic-version extension, allowing an informative version to be associated with a particular module revision. The draft updates RFC 6020, RFC 7950, and RFC 9907.
Proposes updating the AUTH48 (or equivalent) process by introducing deterministic state-integrity constraints within the IETF Datatracker architecture. It establishes automated validation milestones and explicit access controls to prevent late technical modifications after Working Group Last Call, aiming to safeguard rough consensus. The draft updates RFC 7841.
Defines an opt-in counterpart to EDNS Client Subnet (ECS). ECS lets a recursive resolver forward part of a client's network address to authoritative servers for tailored answers; RFC 7871 offers only an opt-out, and asking for a shorter prefix requires an address the client behind NAT/VPN may not know. Here a client adds an EDNS(0) option to ask the resolver to forward its address and to cap how many bits are forwarded. A conforming resolver forwards nothing for clients that send no option, so one resolver address can serve both tailored and privacy-preserving clients.
Introduces new IPFIX Information Elements to identify the Segment Routing Path Segment Identifier (PSID) for SR-MPLS and SRv6 paths. This lets IPFIX flow records carry the SR path identity, improving visibility and correlation of traffic to specific SR paths in flow telemetry.
Describes a scheduling framework for an agent service-discovery node that must process two competing workloads: agent registration/state updates and discovery queries. Delayed updates cause stale information while delayed queries raise selection latency. The framework estimates each workload's demand from queued work, waiting time, deadline pressure, recent load, state freshness and expected freshness gain, then divides worker capacity between two always-active queues. It also adds update merging/dedup, freshness-aware dependencies, hysteresis-based reallocation, minimum holding time, and intra-queue prioritization, all tunable via weights without changing the structure.
Reports experiments with post-quantum signature algorithms and analyzes migration approaches for the RPKI. It compares classical, post-quantum and composite candidates; generates and validates RPKI-profiled certificate, CRL, manifest and ROA test objects; and evaluates Parallel Publication versus Mixed Tree migration plus the impact of larger objects on rsync, RRDP and Erik Synchronization. It identifies implementation, interoperability, repository-distribution and operational questions to resolve first. Informational: it does not update RFC 7935 or RFC 6916, define a new algorithm profile, or authorize the evaluated algorithms in production.