IETF Internet-Drafts & RFCs

Daily digest · 2026-10-03 · window: last 48h (Oct 1–3, 2026)

63 drafts · 0 RFCs · 0 of 63 drafts with official abstract · Published at https://ietf-drafts-ok.pages.dev

Newly published RFCs

No newly published RFCs in the window. The ietf-announce archive shows no "RFC NNNN on …" publication announcements dated within the 48-hour window (Oct 1–3, 2026). The most recent RFC publication announcement was RFC 10052 on 2026-09-30, just outside the window.

Drafts (63)

draft-palanisamy-scitt-aac-runtime-00 Individual new -00 2026-10-03

By its name this individual submission sits in the SCITT (Supply Chain Integrity, Transparency, and Trust) space and appears to describe an "AAC" runtime component — probably runtime attestation, authorization, or access-control behaviour for SCITT transparency services. As an initial -00 it most likely sets out the data structures and procedures for producing or checking runtime evidence inside a SCITT architecture. The exact mechanisms, formats, and scope cannot be confirmed from the name alone and will be grounded against the official Abstract on the next run.

draft-palanisamy-scitt-aac-otel-00 Individual new -00 2026-10-03

A companion individual draft in the SCITT (Supply Chain Integrity, Transparency, and Trust) area whose name points to integration with OpenTelemetry ("otel") — probably mapping SCITT transparency or attestation data onto OpenTelemetry traces, metrics, or logs so that supply-chain evidence can be observed through standard telemetry pipelines. As a -00 it likely defines the correlation model and any required conventions. Details are inferred from the name and will be grounded against the Abstract next run.

draft-hoffman-pq-dnssec-considerations-02 Individual rev -02 2026-10-02

By its name this individual draft collects considerations for post-quantum (PQ) cryptography in DNSSEC. It probably surveys the operational and protocol challenges of introducing PQ signature algorithms into DNSSEC — large signature and key sizes, response-size and fragmentation limits, rollover and algorithm-agility concerns — rather than specifying a new algorithm. At revision -02 it is a maturing analysis document. Specific recommendations are not asserted here and will be grounded against the official Abstract on the next run.

draft-cel-nfsv4-rpc-tls-dane-01 Individual rev -01 2026-10-02

The name indicates an individual draft on using DANE (DNS-Based Authentication of Named Entities) with RPC-over-TLS for NFSv4. It likely describes how NFSv4 clients and servers can authenticate TLS peers for RPC transport using DANE TLSA records, as an alternative or complement to PKIX certificate validation. At -01 it is early work. The precise procedures and record profiles are inferred from the name and will be confirmed against the Abstract next run.

draft-ietf-ediint-rfc4130bis-05 WG EDIINT rev -05 2026-10-02

A working-group document that, by its name, revises RFC 4130 ("bis"), the EDIINT AS2 specification for MIME-based secure business-data exchange (EDI over HTTP/S). It probably updates AS2 to modern cryptographic practice, clarifies ambiguities, and folds in errata and interoperability experience accumulated since RFC 4130. At revision -05 it is well advanced. The exact set of changes is not asserted from the name alone and will be grounded against the official Abstract on the next run.

draft-acee-lsr-ospfv3-deprecate-ah-01 Individual rev -01 2026-10-02

By its name this individual LSR-area draft proposes deprecating use of the IPsec Authentication Header (AH) for securing OSPFv3. It most likely recommends moving away from AH-based protection toward other mechanisms (for example OSPFv3 authentication trailers) and updates the relevant specifications accordingly. At -01 it is early. The precise normative changes are inferred from the name and will be grounded against the Abstract next run.

draft-ietf-spring-srv6-security-17 WG SPRING rev -17 2026-10-02

A SPRING working-group document on security considerations for SRv6 (Segment Routing over IPv6). It probably analyses the threat model of SRv6 domains — source-routing abuse, spoofed SIDs, domain-boundary filtering, and protection of the SR Header — and gives deployment guidance for keeping an SRv6 domain trusted. At revision -17 it is a mature, much-iterated document. Specific recommendations are not asserted from the name and will be grounded against the official Abstract on the next run.

draft-schrock-canonical-action-identifier-05 Individual rev -05 2026-10-02

The name suggests an individual draft defining a "canonical action identifier" — a normalized, stable way to name or reference actions, likely in an API, authorization, or agent context. It probably specifies the identifier syntax and canonicalization rules so that the same action is referred to consistently across systems. At revision -05 it is somewhat developed. The exact scope and format are inferred from the name and will be grounded against the Abstract next run.

draft-dogru-cedulon-core-03 Individual rev -03 2026-10-02

An individual draft whose name ("cedulon-core") does not map to a well-known protocol, so its purpose is uncertain; "core" suggests it defines the base model or framework for a system named Cedulon. At revision -03 it has seen some iteration. Because the name is not self-explanatory, no technical claims are made here; the purpose will be grounded against the official Abstract on the next run.

draft-levine-dnsextlang-15 Individual rev -15 2026-10-02

By its name this individual draft specifies "DNS extended language" (dnsextlang) — a descriptive syntax for defining DNS resource-record types in a machine-readable way, so that tools can parse and generate RR types without hard-coded knowledge of each one. At revisions -14/-15 it is a long-running, mature specification. The exact grammar and tooling model are inferred from the name and will be grounded against the Abstract next run.

draft-sparysh-pala-audit-01 Individual rev -01 2026-10-02

The name points to an individual draft about auditing in a system called "PALA." Without a well-known referent the exact subject is uncertain, but "audit" suggests it defines logging, evidence, or verifiable audit-trail mechanisms for that system. At -01 it is early work. No specific mechanisms are asserted from the name; the purpose will be grounded against the official Abstract on the next run.

draft-fane-opena2a-aap-02 Individual rev -02 2026-10-02

An individual draft in what its name calls the "OpenA2A" (agent-to-agent) family, with "aap" likely an agent authorization/authentication or agreement protocol. It probably defines how autonomous agents establish identity and permission to interact. At revision -02 it is early-to-mid stage. The exact protocol and message set are inferred from the name and will be grounded against the Abstract next run.

draft-khandelwal-bmwg-agent-memory-integrity-01 Individual rev -01 2026-10-02

By its name this individual draft, aligned with the Benchmarking Methodology work (bmwg), concerns measuring or verifying the memory integrity of an "agent." It probably defines a methodology or metrics for assessing whether an agent's runtime memory has been tampered with, possibly for benchmarking attestation mechanisms. At -01 it is early. Specifics are inferred from the name and will be grounded against the official Abstract on the next run.

The name places this individual draft in the RATS (Remote ATtestation procedureS) area, addressing attestation of individual hardware components. It likely specifies how evidence about a hardware component's identity and integrity is produced and conveyed within the RATS architecture. At -01 it is early work. The exact claims and formats are inferred from the name and will be grounded against the Abstract next run.

draft-sharif-x509-agent-identity-profile-04 Individual rev -04 2026-10-02

By its name this individual draft defines an X.509 certificate profile for "agent identity" — probably a set of certificate fields, extensions, and conventions for identifying autonomous or AI agents using PKIX certificates. At revision -04 it has seen iteration. The precise profile is inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-nmop-simap-concept-14 WG NMOP rev -14 2026-10-02

An NMOP (Network Management Operations) working-group document presenting the concept of "SIMAP." The name suggests a conceptual framework for a service/infrastructure map or model used in network management and operations. At revision -14 it is a mature, much-discussed concept document. The exact definition and data model are inferred from the name and will be grounded against the Abstract next run.

An individual submission tied to the IRTF NMRG (Network Management Research Group) theme, on "agentic" network optimization — probably exploring how autonomous AI agents could drive network optimization and management decisions. At revision -02 it is early research work. The specific architecture and techniques are inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-lisp-rfc6831bis-09 WG LISP rev -09 2026-10-02

A LISP working-group document revising RFC 6831 ("bis"), which covers LISP for multicast (interworking LISP with multicast routing). It probably updates the original specification with clarifications, errata, and deployment experience. At revision -09 it is well advanced. The exact set of changes is inferred from the name and will be grounded against the Abstract next run.

draft-intra-handshake-fail-53 Individual rev -53 2026-10-02

An individual draft whose name suggests it concerns handling or signalling of a failed handshake ("handshake-fail"), likely within a protocol referred to as "intra." The very high revision numbers (-52/-53) are unusual and may reflect frequent automated resubmission. Because the name is not self-explanatory, no technical claims are made here; the subject will be grounded against the official Abstract on the next run.

draft-ietf-grow-routing-ops-sec-inform-03 WG GROW rev -03 2026-10-02

A GROW (Global Routing Operations) working-group document whose name points to informing routing-operations security — probably guidance or an informational framework for communicating routing security information among operators. At revision -03 it is maturing. The precise scope is inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-grow-routing-ops-terms-03 WG GROW rev -03 2026-10-02

A companion GROW working-group document defining routing-operations terminology. It most likely establishes a common vocabulary for routing-security and operations work so that other documents can reference consistent definitions. At revision -03 it is maturing. The exact term set is inferred from the name and will be grounded against the Abstract next run.

draft-fane-opena2a-aip-03 Individual rev -03 2026-10-02

Another individual draft in the "OpenA2A" (agent-to-agent) family, with "aip" likely an agent interaction or identity protocol complementary to the AAP draft by the same author. It probably specifies part of the agent-to-agent communication framework. At revision -03 it is early-to-mid stage. Details are inferred from the name and will be grounded against the official Abstract on the next run.

draft-wei-aic-jwt-02 Individual rev -02 2026-10-02

By its name this individual draft defines a JWT (JSON Web Token) profile or usage for "AIC" — probably an agent/AI identity or credential framework. It likely specifies claims and validation rules for representing such identities as JWTs. At revision -02 it is early. The exact claim set is inferred from the name and will be grounded against the Abstract next run.

draft-wei-aic-identity-cert-02 Individual rev -02 2026-10-02

A companion individual draft defining an identity certificate for "AIC" — likely a certificate format or profile for the same agent/AI identity framework addressed by the author's JWT draft. At revision -02 it is early. The precise certificate profile is inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-calext-jscalendarbis-21 WG CALEXT rev -21 2026-10-02

A CALEXT working-group document revising JSCalendar ("bis"), the JSON representation of calendar data originally defined in RFC 8984. It probably folds in errata, clarifications, and new properties learned from deployment. At revision -21 it is a mature, heavily iterated specification. The exact changes are inferred from the name and will be grounded against the Abstract next run.

draft-mih-agent-settlement-records-00 Individual new -00 2026-10-02

The name suggests an individual draft about "settlement records" for agents — probably a data structure for recording the settlement of transactions or obligations between autonomous agents. As a -00 it likely defines the record format and lifecycle. Specifics are inferred from the name and will be grounded against the official Abstract on the next run.

draft-skyfire-oauth-kyapay-token-02 Individual rev -02 2026-10-02

An individual OAuth-related draft from the "skyfire" family, whose name points to a "KYAPay" token — probably an OAuth token type tied to a know-your-agent / payment flow. It likely defines the token's format and issuance/validation rules. At revision -02 it is early. Details are inferred from the name and will be grounded against the Abstract next run.

draft-skyfire-oauth-using-kyapay-tokens-01 Individual rev -01 2026-10-02

A companion individual OAuth draft describing how to use the "KYAPay" tokens defined in the related skyfire drafts — probably the client/resource-server behaviour for presenting and consuming such tokens. At -01 it is early. The exact usage model is inferred from the name and will be grounded against the official Abstract on the next run.

draft-skyfire-oauth-aml-methods-01 Individual rev -01 2026-10-02

An individual OAuth draft in the skyfire family whose name points to AML (anti-money-laundering) methods — probably a way to express or convey AML-related checks or method identifiers within an OAuth flow. At -01 it is early work. The precise mechanism is inferred from the name and will be grounded against the Abstract next run.

draft-skyfire-oauth-id-verification-02 Individual rev -02 2026-10-02

A skyfire-family individual OAuth draft on identity verification — probably defining how identity-verification results or levels are represented and conveyed in an OAuth context. At revision -02 it is early. The exact claims and flow are inferred from the name and will be grounded against the official Abstract on the next run.

draft-skyfire-oauth-amr-values-02 Individual rev -02 2026-10-02

A skyfire-family individual OAuth draft defining AMR (Authentication Methods References) values — probably registering or specifying additional AMR string values for use in tokens that describe how authentication was performed. At revision -02 it is early. The exact value set is inferred from the name and will be grounded against the Abstract next run.

draft-newbold-atp-aturi-00 Individual new -00 2026-10-01

An individual draft whose name suggests it defines an "at-uri" (AT URI) within an "ATP" context — possibly related to the AT Protocol's URI scheme for addressing records. As a -00 it likely specifies the URI syntax and resolution. Because the referent is uncertain, no firm claims are made; the purpose will be grounded against the official Abstract on the next run.

draft-ietf-moq-transport-22 WG MOQ rev -22 2026-10-01

A Media Over QUIC (MOQ) working-group document specifying MOQ Transport — the core protocol for low-latency media delivery over QUIC, covering the publish/subscribe model, object/track model, and how media is sent over QUIC streams. At revision -22 it is a mature, central WG specification. The exact wire details are inferred from the name and will be grounded against the official Abstract on the next run.

draft-nirvanai-nbtp-behavioral-trust-01 Individual rev -01 2026-10-01

An individual draft whose name points to a "behavioral trust" protocol ("nbtp") — probably a scheme for establishing trust between parties (likely agents) based on observed behaviour rather than static credentials. At -01 it is early work. The specific model is inferred from the name and will be grounded against the Abstract next run.

draft-zambo-aer1-09 Individual rev -09 2026-10-01

An individual draft with a non-descriptive name ("aer1"), submitted in rapid succession (-07 through -09 within the window). Its subject cannot be inferred reliably from the name. No technical claims are made here; the purpose will be grounded against the official Abstract on the next run.

draft-levine-dnsextlang-14 Individual rev -14 2026-10-01

By its name this individual draft specifies "DNS extended language" (dnsextlang) — a descriptive syntax for defining DNS resource-record types in a machine-readable way, so that tools can parse and generate RR types without hard-coded knowledge of each one. At revisions -14/-15 it is a long-running, mature specification. The exact grammar and tooling model are inferred from the name and will be grounded against the Abstract next run.

draft-ietf-tcpm-tcp-ao-algs-08 WG TCPM rev -08 2026-10-01

A TCPM working-group document on cryptographic algorithms for TCP-AO (the TCP Authentication Option, RFC 5925). It probably defines or updates the set of MAC/KDF algorithms registered for use with TCP-AO, modernizing the original algorithm choices. At revision -08 it is well advanced. The exact algorithm set is inferred from the name and will be grounded against the Abstract next run.

draft-seymour-wimse-connected-flight-06 Individual rev -06 2026-10-01

An individual draft aligned with WIMSE (Workload Identity in Multi-System Environments) whose name adds "connected-flight" — possibly a use case or profile for workload identity in connected-aircraft or similar connected environments. At revision -06 it has iterated. The precise scope is inferred from the name and will be grounded against the official Abstract on the next run.

draft-zambo-aer1-08 Individual rev -08 2026-10-01

An individual draft with a non-descriptive name ("aer1"), submitted in rapid succession (-07 through -09 within the window). Its subject cannot be inferred reliably from the name. No technical claims are made here; the purpose will be grounded against the official Abstract on the next run.

draft-intra-handshake-fail-52 Individual rev -52 2026-10-01

An individual draft whose name suggests it concerns handling or signalling of a failed handshake ("handshake-fail"), likely within a protocol referred to as "intra." The very high revision numbers (-52/-53) are unusual and may reflect frequent automated resubmission. Because the name is not self-explanatory, no technical claims are made here; the subject will be grounded against the official Abstract on the next run.

draft-lee-oauth-dpop-credential-presentation-03 Individual rev -03 2026-10-01

An individual OAuth draft combining DPoP (Demonstrating Proof of Possession) with credential presentation — probably specifying how a client proves possession of a key while presenting a verifiable credential in an OAuth flow. At revisions -02/-03 it is early-to-mid stage. Details are inferred from the name and will be grounded against the Abstract next run.

draft-ietf-jmap-calendars-31 WG JMAP rev -31 2026-10-01

A JMAP working-group document specifying JMAP for Calendars — the JSON Meta Application Protocol methods for accessing and managing calendar data, building on JSCalendar. At revisions -30/-31 it is a mature, heavily iterated specification. The exact method set is inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-bier-source-protection-11 WG BIER rev -11 2026-10-01

A BIER (Bit Index Explicit Replication) working-group document on source protection — probably mechanisms for protecting against failures of a multicast source or ingress in a BIER domain. At revision -11 it is well advanced. The precise protection scheme is inferred from the name and will be grounded against the Abstract next run.

draft-prz-lsr-ash-packets-06 Individual rev -06 2026-10-01

An individual LSR-area draft whose name points to "ASH packets." Without a well-known referent the exact meaning is uncertain, though it likely defines a packet type or encoding used by a link-state routing extension. At revision -06 it has iterated. No firm claims are made from the name; the purpose will be grounded against the official Abstract on the next run.

draft-ietf-ipsecme-ikev2-reliable-transport-08 WG IPSECME rev -08 2026-10-01

An IPSECME working-group document adding a reliable transport mechanism to IKEv2 — probably to carry large payloads (such as post-quantum keys or big certificates) that exceed what the current IKEv2 message exchange handles well. At revision -08 it is well advanced. The exact mechanism is inferred from the name and will be grounded against the Abstract next run.

draft-das-interim-effectuation-validation-00 Individual new -00 2026-10-01

An individual draft whose name ("interim effectuation validation") does not map to a known protocol; it likely concerns validating that some interim action or state has taken effect, possibly in a transaction or settlement context. As a -00 it is initial work. Because the name is abstract, no technical claims are made; the purpose will be grounded against the official Abstract on the next run.

draft-das-receipt-gated-iev-00 Individual new -00 2026-10-01

A companion individual -00 draft whose name suggests "receipt-gated" behaviour tied to "IEV" — probably a mechanism where some step is gated on a cryptographic receipt. The exact referent is uncertain. No firm claims are made from the name; the purpose will be grounded against the official Abstract on the next run.

draft-das-safety-first-execution-finality-00 Individual new -00 2026-10-01

An individual -00 draft whose name points to "execution finality" with a "safety-first" approach — likely concerning how and when an executed transaction or action is considered final, prioritizing safety over liveness. The precise model is uncertain from the name. It will be grounded against the official Abstract on the next run.

draft-zambo-aer1-07 Individual rev -07 2026-10-01

An individual draft with a non-descriptive name ("aer1"), submitted in rapid succession (-07 through -09 within the window). Its subject cannot be inferred reliably from the name. No technical claims are made here; the purpose will be grounded against the official Abstract on the next run.

draft-ietf-jmap-calendars-30 WG JMAP rev -30 2026-10-01

A JMAP working-group document specifying JMAP for Calendars — the JSON Meta Application Protocol methods for accessing and managing calendar data, building on JSCalendar. At revisions -30/-31 it is a mature, heavily iterated specification. The exact method set is inferred from the name and will be grounded against the official Abstract on the next run.

A LISP working-group document on site external connectivity — probably how a LISP site connects to and exchanges traffic with non-LISP or external networks. At revision -05 it is maturing. The exact procedures are inferred from the name and will be grounded against the official Abstract on the next run.

draft-lee-oauth-dpop-credential-presentation-02 Individual rev -02 2026-10-01

An individual OAuth draft combining DPoP (Demonstrating Proof of Possession) with credential presentation — probably specifying how a client proves possession of a key while presenting a verifiable credential in an OAuth flow. At revisions -02/-03 it is early-to-mid stage. Details are inferred from the name and will be grounded against the Abstract next run.

draft-ni-wimse-ai-agent-identity-03 Individual rev -03 2026-10-01

An individual draft aligned with WIMSE (Workload Identity in Multi-System Environments) on AI agent identity — probably how AI agents obtain and present workload identities across systems. At revision -03 it has iterated. The specific model is inferred from the name and will be grounded against the Abstract next run.

draft-morrison-ot-command-authority-03 Individual rev -03 2026-10-01

An individual draft whose name points to "command authority" in an OT (operational technology) context — probably a scheme for authorizing commands issued to industrial/OT systems. At revision -03 it has iterated. The exact authorization model is inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-bmwg-powerbench-03 WG BMWG rev -03 2026-10-01

A BMWG (Benchmarking Methodology) working-group document on "powerbench" — probably a methodology for benchmarking the power/energy consumption of network devices under load. At revision -03 it is maturing. The precise methodology is inferred from the name and will be grounded against the Abstract next run.

draft-ietf-savnet-intra-domain-architecture-05 WG SAVNET rev -05 2026-10-01

A SAVNET working-group document describing an intra-domain architecture for Source Address Validation (SAV). It probably defines how SAV is performed within a single routing domain to prevent source-address spoofing. At revision -05 it is maturing. The exact architecture is inferred from the name and will be grounded against the official Abstract on the next run.

draft-sriram-savnet-intrasav-solution-00 Individual new -00 2026-10-01

An individual SAVNET-aligned -00 draft proposing an intra-domain SAV (Source Address Validation) solution — likely a concrete mechanism complementing the WG's intra-domain architecture work. As a -00 it is initial. The specific solution is inferred from the name and will be grounded against the Abstract next run.

A V6OPS working-group document presenting a framework for an IPv6-only underlay (with multi-domain "md" considerations) — probably operational guidance for running an IPv6-only underlay network. At revision -29 it is a mature, much-iterated document. The exact framework is inferred from the name and will be grounded against the official Abstract on the next run.

draft-gondwana-dkim2-debug-header-01 Individual rev -01 2026-10-01

An individual draft in the emerging "DKIM2" space defining a debug header — probably a header field to aid diagnosing DKIM2 signing/verification. At -01 it is early. The exact header semantics are inferred from the name and will be grounded against the Abstract next run.

draft-ietf-ippm-stamp-ext-hdr-15 WG IPPM rev -15 2026-10-01

An IPPM working-group document extending STAMP (Simple Two-Way Active Measurement Protocol) with extension headers — probably additional TLVs/fields carrying extra measurement information. At revision -15 it is well advanced and was recently in IETF Last Call. The exact extensions are inferred from the name and will be grounded against the official Abstract on the next run.

draft-ietf-vcon-overview-02 WG VCON rev -02 2026-10-01

A VCON working-group document giving an overview of the vCon (virtualized conversation) container — a standard format for capturing conversations (audio, transcripts, metadata) and their provenance. At revision -02 it is maturing. The exact scope is inferred from the name and will be grounded against the Abstract next run.

draft-krausz-verification-state-03 Individual rev -03 2026-10-01

An individual draft on "verification state" — probably a way to represent and convey the state or result of a verification process. At revision -03 it has iterated. Because the name is general, no firm technical claims are made; the purpose will be grounded against the official Abstract on the next run.

draft-ietf-pim-multicast-over-srv6-01 WG PIM rev -01 2026-10-01

A PIM working-group document on carrying multicast over SRv6 (Segment Routing over IPv6) — probably how PIM-signalled or SR-based multicast is delivered through an SRv6 data plane. At -01 it is early WG work. The exact mechanism is inferred from the name and will be grounded against the official Abstract on the next run.