IETF Daily Digest — Internet-Drafts & RFCs

Window: last 48 hours (2026-10-02 and the two preceding days) · generated 2026-10-02 05:19 UTC · all groups (100% coverage)
66 drafts 0 RFCs 61/66 drafts with official abstract Published at https://ietf-drafts-ok.pages.dev

Newly published RFCs

The ietf-announce archive shows no RFC announcements after 2026-09-19; no items in the 48-hour window.

Drafts

2026-10-01 23 drafts

Profiles the RFC 9068 JWT access token so that the same JWT is simultaneously a W3C Verifiable Credential secured with JOSE. The authorization server acts as the credential issuer, and the token is bound to the client's key with DPoP (RFC 9449). A resource server consumes it as an ordinary DPoP-bound access token with no changes, while a verifier named as the audience can process the same object as a Verifiable Credential. The profile defines no new headers, claims, or registrations; it states which existing headers and claims are used, how the two data models' claims correspond, and the conditions under which one object can safely serve both roles.

draft-ietf-jmap-calendars-31 WG JMAP rev -31 abstract

Specifies a JMAP data model for synchronizing calendar data with a server. Clients can efficiently read, write, and share calendars and events, receive push notifications for changes or event reminders, and track changes made by others in a multi-user environment.

draft-ietf-bier-source-protection-11 WG BIER rev -11 abstract

Describes a failover mechanism in the Bit Index Explicit Replication (BIER) domain using a redundant ingress router, so multicast delivery can survive the loss of a source/ingress node.

draft-prz-lsr-ash-packets-06 Individual rev -06 abstract

Introduces an optional new database-synchronization packet called an Aggregated SNP Hash (ASH). When feasible, it compresses traditional SNP exchanges into a dynamic Merkle-tree-like structure, speeding up synchronization of large databases and adjacencies while reducing the load of regular CSNP exchanges in steady state. Like CSNPs and PSNPs, ASH packets come in two forms: Complete ASH (CASH) and Partial ASH (PASH).

IKEv2 can run over unreliable (UDP) or reliable (TCP) transport, and with TCP the resulting IPsec tunnels also use TCP. This document decouples the IKEv2 and IPsec transports so IKEv2 can run over TCP while IPsec tunnels use unreliable transport. That lets IKEv2 exchange large payloads (for example, when post-quantum algorithms are used) while avoiding the performance problems that arise when IPsec itself runs over TCP.

draft-das-interim-effectuation-validation-00 Individual new -00 abstract

Specifies an experimental architecture for controlling consequential external effects produced by agentic, autonomous, and conventional systems, aimed at operators of AI machines and frontier model providers. It separates a proposed act from the authority to make it effective: a bounded real effect is allowed, protected evidence of what actually happened is collected, and an Interim Effectuation Validator (IEV) independently evaluates that evidence before any later effect is permitted. The validator never relays the original command, and if trustworthy evidence is missing the act is held or quarantined rather than retried. It supports single-, two-, and multi-phase operation and defines an abstract protocol and conformance model rather than one mandatory transport. (The document notes a pending patent application.)

draft-das-receipt-gated-iev-00 Individual new -00 abstract

An experimental execution-control design for autonomous and AI systems that separates proposed actions from the authority that makes them consequential. It enables single-phase protected execution, a bounded initial effect followed by receipt-gated continuation, and arbitrary multi-phase progression. In the Interim Effectuation Validator (IEV) framework, validated evidence of earlier real effects acts as a structural dependency, evaluated independently before later steps are unlocked, rather than a mere log. It also covers taint/provenance tracking, credential surrogation, privilege separation, crash reconciliation, and anti-bypass protections across software, OS, mobile, network, hardware, and distributed realizations.

draft-das-safety-first-execution-finality-00 Individual new -00 abstract

Argues that authority to cause a real-world effect should be earned step by step from the real execution path, not granted session-wide. A full-consequence command is held in a non-executable state; a deliberately bounded real effect is produced on the exact operational path, the destination returns an Effect Confirmation Receipt, and an Interim Effectuation Validator checks that receipt out of band before releasing the key/credential for the next phase. Two properties are central: the validator never relays the original command (so compromising an inline proxy does not yield the keys), and uncertainty is a first-class state that quarantines rather than retries. It consolidates 35 workflow profiles across communications, payments, databases, cloud/model deployment, AI tool invocation, robotics, vehicles, UAVs, and industrial control, including a Safety-First Critical-System Profile.

draft-zambo-aer1-07 Individual rev -07

By its name, this individual submission ("aer1") appears to define a mechanism, format, or procedure abbreviated AER1. Its official Abstract could not be retrieved on this run (the document page returned HTTP 404), so this summary is approximate and will be grounded from the Abstract on the next run.

draft-ietf-jmap-calendars-30 WG JMAP rev -30 abstract

Specifies a JMAP data model for synchronizing calendar data with a server. Clients can efficiently read, write, and share calendars and events, receive push notifications for changes or event reminders, and track changes made by others in a multi-user environment.

Defines how to register and retrieve proxy-ETR (pETR) mapping information in LISP when the destination is not registered or known to the local site and its mapping system, for example an external/Internet destination or a scale-out/scale-across endpoint in the back-end networks of AI infrastructure.

Profiles the RFC 9068 JWT access token so that the same JWT is simultaneously a W3C Verifiable Credential secured with JOSE. The authorization server acts as the credential issuer, and the token is bound to the client's key with DPoP (RFC 9449). A resource server consumes it as an ordinary DPoP-bound access token with no changes, while a verifier named as the audience can process the same object as a Verifiable Credential. The profile defines no new headers, claims, or registrations; it states which existing headers and claims are used, how the two data models' claims correspond, and the conditions under which one object can safely serve both roles.

draft-ni-wimse-ai-agent-identity-03 Individual rev -03 abstract

Discusses applying WIMSE to agentic AI so that AI agents can have independent identities and credential-management mechanisms. It also discusses mechanisms for cryptographically binding an AI agent's identity to an accountable user or organization.

draft-morrison-ot-command-authority-03 Individual rev -03 abstract

Specifies a binding profile under which a control action sent to an operational-technology (OT) / industrial control system on the authority of a software agent is refused unless it carries a verifiable statement of the agent's identity, the human principal it acts for, whether that principal authorized this specific action on this specific asset, any required human sign-off, and an append-only attribution record. It composes existing primitives (DNSSEC-rooted agent discovery, a scoped revocable grant, a human-authorization receipt, and a transparency record) into a single Command Authority Envelope that an enforcement point evaluates and, on any missing or invalid binding, refuses. It is availability-first, fails closed on authority but never on safety, and maps onto IEC 62443 and NERC CIP requirements.

draft-ietf-bmwg-powerbench-03 WG BMWG rev -03 abstract

Defines a standard mechanism to measure, report, and compare the power usage of different networking devices under different network configurations and conditions.

Describes a generic architecture for intra-domain Source Address Validation (SAV), giving a common framework for developing new intra-domain SAV mechanisms and the conditions under which this architecture can improve SAV accuracy and operational efficiency relative to existing mechanisms.

draft-sriram-savnet-intrasav-solution-00 Individual new -00 abstract

Specifies IntraSAV, a solution for intra-domain source address validation that addresses the problem stated in the savnet intra-domain problem-statement (RFC-to-be). It updates BCP 38 (RFC 2827) and BCP 84 (RFC 3704, RFC 8704) by providing a more comprehensive methodology and accommodating prefixes that are not routed but are used to source traffic originating from an AS.

Presents an operator-perspective framework for building and running IPv6-only core networks spanning multiple domains (interconnected ASes). To carry residual IPv4 traffic, it proposes stateless IPv4/IPv6 address mapping as the basis for IPv4-as-a-Service (IPv4aaS), translating IPv4 at the network edge and forwarding across the IPv6-only core without per-flow state or gateways on the data path. It is intended as a problem statement, guidance, and requirements rather than a protocol spec, covering applicability, trust boundaries, mapping-prefix allocation, and operational, manageability, and security considerations.

draft-gondwana-dkim2-debug-header-01 Individual rev -01 abstract

Adds extra debug information useful to implementations of DomainKeys Identified Mail Signatures v2 (DKIM2) during early deployment. The document is intended to help testers and is explicitly unlikely to be published as an RFC.

draft-ietf-ippm-stamp-ext-hdr-15 WG IPPM rev -15 abstract

Extends the Simple Two-Way Active Measurement Protocol (STAMP), used for edge-to-edge active measurements, to reflect IPv4/IPv6 headers and IPv6 extension headers for hop-by-hop and end-to-end measurements, for example to carry In-situ OAM (IOAM) data fields for recording and collecting operational and telemetry information.

draft-ietf-vcon-overview-02 WG VCON rev -02 abstract

Introduces the vCon, a container for information about a real-time human conversation, analogous to a vCard for contact information. A vCon can hold data derived from phone calls, video conferences, SMS/MMS, webchat, or email threads, including CDRs, metadata, participant identity (e.g., STIR PASSporT), the conversational media itself, analysis, and attachments. A standardized container enables many applications and a common method of storage and interchange while supporting identity, privacy, and security efforts.

draft-krausz-verification-state-03 Individual rev -03 abstract

Specifies the verification.* constraint family, a pre-action, fail-closed gate primitive for AI-agent decisions, as a sibling to the environment.* family used in Verifiable Intent work. A verification.* receipt is a JWS-signed artifact carrying a canonical input, a derived act/halt output, and a versioned mapping identifier; the relying party recomputes the gate locally and never trusts the issuer's runtime. This revision replaces the earlier verdict vocabulary with verified / contradicted / indeterminate / not_evaluated plus reason codes and an admissibility gate, and adds evidence pinning so a verdict can be recomputed offline from the receipt and pinned bytes. It aligns with EU AI Act Article 12 record-keeping and a 2026 Zero-Trust-for-AI-Agents framework, and remains forward-compatible across mapping revisions.

draft-ietf-pim-multicast-over-srv6-01 WG PIM rev -01 abstract

Presents solutions for deploying multicast in SRv6 networks, using the native IPv6 multicast data plane for distribution. It discusses distributed control-plane mechanisms including PIM and its integration with IGP Flex-Algo to optimize delivery, and addresses overlay multicast for both Global Table Multicast (GTM) and Multicast VPNs (MVPNs) using IP-in-IPv6 encapsulation without additional shim layers.

2026-09-30 43 drafts

draft-zambo-aer1-06 Individual rev -06

By its name, this individual submission ("aer1") appears to define a mechanism, format, or procedure abbreviated AER1. Its official Abstract could not be retrieved on this run (the document page returned HTTP 404), so this summary is approximate and will be grounded from the Abstract on the next run.

draft-dogru-cedulon-core-02 Individual rev -02 abstract

Addresses auditable payments for AI agents, building on HTTP 402, AP2, and credit-card systems. It specifies a cryptographically secured payment-reconciliation protocol using a Trade Manifest (a signed offer before payment), a Policy Decision Point with default-deny, a Spend Receipt (a COSE/CWT claim set issued after a gated payment), and rail-extract reconciliation.

draft-acee-lsr-ospfv3-deprecate-ah-00 Individual new -00 abstract

RFC 4552 specified using the IPsec Authentication Header (AH) and ESP to authenticate and protect OSPFv3. This document deprecates the use of AH for OSPFv3 and updates RFC 4552 accordingly, encouraging operators to use either ESP with NULL encryption (RFC 4552) or the OSPFv3 Authentication Trailer (RFC 7166).

draft-birkholz-did-x509-03 Individual rev -03 abstract

Defines the did:x509 decentralized identifier method, a flexible issuer-identifier format for messages that carry or refer to X.509 certificates, including COSE messages (RFC 9360). A did:x509 identifier binds the fingerprint of a CA certificate in the chain with one or more predicates on the leaf certificate (subject name, SANs, EKU, or Fulcio issuer), and can be carried as an issuer value in COSE/CWT, JOSE/JWT (e.g., the iss claim), or other protocol-specific mechanisms. It lets existing X.509 deployments and DID-based systems interoperate where a full transition to DIDs is not feasible. This Informational, Independent Submission describes the method as implemented by Microsoft and is not an IETF product.

draft-ietf-radext-radiusdtls-bis-18 WG RADEXT rev -18 abstract

Defines transport profiles for running RADIUS over TLS and DTLS (collectively RadSec), allowing secure and reliable transport of RADIUS messages. It obsoletes RFC 6614 and RFC 7360, which specified the experimental versions of RADIUS over TLS and DTLS.

draft-many-teas-rsvp-power-00 Individual new -00 abstract

Traffic-engineered networks are usually provisioned for peak demand, leaving resources lightly used off-peak and consuming unnecessary power. This document defines a generic power-management framework for coordinating power-sleep and wakeup transitions between adjacent nodes (roles, resource scope, procedures, collision handling, failure behavior, and TE-state preservation) and specifies an RSVP-TE signaling extension to support it.

draft-ietf-masque-connect-ethernet-15 WG MASQUE rev -15 abstract

Specifies how to proxy Ethernet frames in HTTP, similar to IP proxying in HTTP but at Layer 2 instead of Layer 3. It defines a protocol that lets an HTTP client create a tunnel to exchange Layer 2 Ethernet frames through an HTTP server attached to a physical or virtual Ethernet segment.

draft-intra-handshake-fail-51 Individual rev -51 abstract

Aims to document, with technical detail, how early (handshake-time) attestation fails in practice, citing several CVEs and GitHub Security Advisories and arguing that because continuous attestation is generally required, early attestation adds unnecessary complexity. Results are said to be backed by ProVerif artifacts (Apache-2.0), and the draft reports that most affected implementations have since been archived, withdrawn, or moved to post-handshake attestation, while naming two it describes as remaining vulnerable.

draft-ietf-bier-bfd-12 WG BIER rev -12 abstract

Point-to-multipoint (P2MP) BFD verifies multipoint connectivity. This document specifies the application of P2MP BFD within a BIER (Bit Index Explicit Replication) network.

draft-many-lsr-power-group-04 Individual rev -04 abstract

PCPPS concentrates traffic onto a small set of network resources so other resources can be powered down until needed, conserving energy. It relies on information distributed by an IGP, and this document specifies the IS-IS encoding for that information.

draft-ietf-tls-trust-anchor-ids-06 WG TLS rev -06 abstract

Defines the TLS Trust Anchors extension, a mechanism for a TLS client or server to select which certificate to present based on the peer's trusted certification authorities. It describes CAs more succinctly than the existing TLS Certificate Authorities extension.

draft-zambo-aer1-05 Individual rev -05

By its name, this individual submission ("aer1") appears to define a mechanism, format, or procedure abbreviated AER1. Its official Abstract could not be retrieved on this run (the document page returned HTTP 404), so this summary is approximate and will be grounded from the Abstract on the next run.

draft-ietf-netconf-error-registries-00 WG NETCONF new -00 abstract

Defines IANA registries for the YANG Protocol Error List and the YANG Protocol Error Identities.

draft-smyslov-ipsecme-ikev2-psp-02 Individual rev -02 abstract

Specifies how IKEv2 can be used to supply keys for the PSP Security Protocol (PSP).

draft-geng-grow-bmp-rr-sync-00 Individual new -00 abstract

The BGP Monitoring Protocol (BMP) gives collectors visibility into BGP RIB state, but transient faults, process restarts, or buffer overflows can cause inconsistencies between a sender's authoritative RIB and the collector's view, and existing recovery requires disruptive session teardown or full re-export. This document defines a new BMP Route-Refresh message that encapsulates standard and Enhanced Route-Refresh semantics within BMP to enable fine-grained, non-disruptive, targeted per-peer or per-AFI/SAFI RIB re-synchronization.

draft-geng-grow-bmp-monitor-options-00 Individual new -00 abstract

BMP lets routers export BGP RIB data and statistics, but dynamic changes to monitoring configuration (such as disabling address families or counters) are not signaled, so collectors cannot distinguish a quiescent BGP state from a disabled feed, causing staleness and database pollution. This document defines a new BMP Monitoring Options (MO) message that lets a sender explicitly notify collectors of active, disabled, or dynamically altered reporting configurations across RIB types and statistics streams.

draft-jackson-wimse-evaluation-03 Individual rev -03 abstract

Delegation-chain specifications describe conveyed authority but leave the verifier's half underdetermined, so two verifiers can both accept the same chain yet enforce different policy. This document states what a verifier must do: the explicit inputs evaluation depends on, how those inputs behave when stale or unavailable, and four rules that keep evaluation fail-closed. The rules are drawn from the Grant & Autonomy Lifecycle (GAL) and Provenance & Trust Context (PTC) specifications and a public reference implementation.

draft-ietf-idr-bgp-rpki-yang-02 WG IDR rev -02 abstract

Defines YANG data models for managing BGP information related to the Resource Public Key Infrastructure (RPKI).

draft-wang-jep-conformance-02 Individual rev -02 abstract

Defines conformance classes, validation-result structure, schema requirements, test-vector categories, conformance assertions, reference-validator behavior, implementation disclosure, and interoperability-testing guidance for the Judgment Event Protocol (JEP). A companion to JEP-Core 0.7, it does not redefine JEP-Core semantics; its purpose is to make implementations testable and interoperable across languages, platforms, trust profiles, and deployment environments.

draft-bokovoy-kitten-pkinit-pqc-02 Individual rev -02 abstract

Specifies extensions to the Kerberos PKINIT pre-authentication mechanism (RFC 4556, RFC 8636) to support post-quantum key establishment using the Module-Lattice-Based KEM (ML-KEM) from FIPS 203. It defines a new kemInfo arm in PA-PK-AS-REP, a KDC-signed KDCKEMInfo structure, HKDF-based AS reply-key derivation (HKDF-SHA-512 for ML-KEM), and downgrade-prevention rules, with a framework supporting ML-KEM, composite ML-KEM, and future KEM standards.

draft-morrison-compute-location-gate-02 Individual rev -02 abstract

Specifies the compute-location gate: a client and an identity-inference server negotiate, at the wire layer and before any inference runs, where an identity inference will compute, as a deterministic function of the input signal's provenance class. Active inference (initiated by the subject) may compute server-side; passive aggregate observation over a cohort no smaller than a declared minimum may compute server-side but yields only population-level results; passive individual observation is local-only and never transmitted. Enforcement is by consent-class matching and a wire-layer refusal when a provenance class is not consented. Informational; composes with MCP DNS discovery, the ~handle namespace, and the organizational policy-provision substrate.

draft-morrison-mcp-dns-discovery-07 Individual rev -07 abstract

Defines a DNS-based mechanism for discovering Model Context Protocol (MCP) servers, the identity of the organizations operating them, and a cryptographic identity envelope bound to an individual ~handle in the same zone. Three TXT records are defined: _mcp advertises an MCP endpoint, protocol family, transport binding, identity, and capability profile; _org-alter advertises the operator's canonical organizational identity; and _alter publishes an Ed25519-signed envelope binding a ~handle to a public key, an IdentityLog root, and a revocation commitment. DNSSEC is required for the envelope and a DANE TLSA pin is required when envelope resolution and MCP session setup are one transaction. It complements HTTPS-based discovery and follows the DKIM/SPF/DMARC/MTA-STS precedent.

Describes a mechanism to allocate network resources to one or a set of Segment Routing IDs (SIDs), called resource-aware SIDs. These SIDs keep their original forwarding semantics but add semantics identifying the set of network resources available for packet processing and forwarding. The mechanism applies to both SR-MPLS and SRv6 data planes.

draft-sharma-oepb-binding-ble-01 Individual rev -01 abstract

Defines the Bluetooth Low Energy (BLE) transport binding profile for the Offline Emergency Peer-to-Peer Broadcast Protocol (OEPB). It specifies the advertising mode, fragmentation and reassembly scheme, service and characteristic UUIDs, and channel-access rules needed to carry OEPB packets over BLE 4.x and 5.x physical layers.

draft-sharma-oepb-01 Individual rev -01 abstract

Specifies the Offline Emergency Peer-to-Peer Broadcast Protocol (OEPB), an experimental protocol for disseminating authenticated emergency alerts among unprovisioned devices over short-range peer-to-peer radios when network infrastructure is unavailable. It defines a compact 256-byte packet with Ed25519 signatures, a transport abstraction over radios such as BLE, Wi-Fi Direct, and LoRa, per-message Trickle dissemination with bounded retransmissions, a five-class weighted fair queuing scheme reflecting triage priorities, and a trust model where relays forward without verifying signatures so distress messages still propagate while receivers authenticate authority alerts. A companion document defines the BLE binding.

draft-morrison-org-alter-policy-provision-04 Individual rev -04 abstract

Specifies how an AI agent runtime, bound at instantiation to a principal identity handle, resolves a target organizational identity substrate at session start and retrieves a typed policy stack (a handbook artifact, an SOP registry pointer, an enforcement-gate specification, and an audit-signal endpoint). The policy stack is applied as runtime constraints on subsequent tool invocations, with audit signals emitted back to the same substrate, so policy provisioning happens in the same act as principal identification rather than as a separate ceremony. A principal bound to multiple substrates runs under a deterministic composition of policy stacks, with residual conflicts routed to the Identity Accord ceremony. Informational; relies on the DNS discovery and handle namespace of the companion drafts.

draft-morrison-identity-pronouns-03 Individual rev -03 abstract

Defines an identity-pronoun grammar as a reference axis orthogonal to the ~handle identity-tier taxonomy of the companion drafts. A pronoun is a session-scoped reference that resolves client-side to a concrete handle using local session state before any cryptographic, DNS, or federation operation. The entity-class taxonomy (Sovereign, Bot, Instrument) is unchanged; Absolute vs Pronoun is introduced as an orthogonal axis. A pronoun must not appear in a capability token, DNS record, Accord signature, or inter-organizational payload. The reference implementation defines one Wave-1 pronoun, ~org, resolving to the organization bound to the caller's current session, and an appendix sketches a relative-path pronoun grammar for future work.

draft-morrison-binding-moment-envelope-03 Individual rev -03 abstract

Specifies the briefing-and-binding envelope: a delivery contract for how an AI agent surfaces a consequential decision to the human principal it acts for, and how the principal commits, declines, amends, or rejects it. The envelope carries eight named slots (synopsis, findings, recommendations, an offer of detail, a question stem, options each with its own reasoning, a single recommended option, and a pair of escape hatches) and is emitted as a structured field of an MCP tool result. Its central element is a dual-veto handshake: one escape hatch lets the principal revise the answer space while accepting the question; the other lets them reject the question itself. It defines a JCS-canonicalized, SHA-256 content digest so a resolution names the exact envelope it resolves. Informational.

draft-helmprotocol-tttps-12 Individual rev -12

By its name, this individual submission relates to a protocol referred to as "tttps" (apparently a secure transport/protocol variant). Its official Abstract could not be retrieved on this run (the document page returned HTTP 404), so this summary is approximate and will be grounded from the Abstract on the next run.

draft-wolf-dialogue-txt-00 Individual new -00 abstract

Defines dialogue.txt, a small text file a person or organization publishes at a well-known location on its own domain. It is the publisher's standing, talk-only consent to be contacted by any reader (including software systems) with which it has no prior relationship. A first message only proposes a conversation; the publisher's reply creates the channel. The file grants talk and nothing else (no action, advertising, access, or representation), and the publisher may name the topics it can be asked about.

draft-ietf-emu-eap-ppt-04 WG EMU rev -04 abstract

Describes EAP using a Privacy Pass token (EAP-PPT) Version 1, specifying the use of a Privacy Pass token for client authentication within EAP (RFC 3748). Privacy Pass (RFC 9576) is a privacy-preserving authentication mechanism used for authorization, and EAP-PPT must be performed only within a tunnel-based EAP method.

draft-tiloca-lake-private-use-ranges-01 Individual rev -01 abstract

Adds Private Use ranges to IANA registries related to the Lightweight Authenticated Key Exchange (LAKE) protocol.

draft-ietf-ccamp-fgotn-yang-02 WG CCAMP rev -02 abstract

Fine-grain Optical Transport Network (fgOTN), specified in ITU-T G.709/Y.1331 (2020) Amd. 3, complements existing OTN with bandwidth-efficient support for sub-1 Gbit/s services. This document defines YANG data models describing the topology and tunnel information of an fgOTN network.

draft-ietf-opsawg-ipfix-ecn-00 WG OPSAWG new -00 abstract

Defines a set of IPFIX Information Elements for monitoring Explicit Congestion Notification (ECN), specifically in the context of the Low Latency, Low Loss, and Scalable Throughput (L4S) service. These elements let operators observe ECN codepoint usage within L4S deployments and evaluate the corresponding traffic performance.

draft-besleaga-agentic-knowledge-wellknown-00 Individual new -00 abstract

Defines the knowledge-linkset well-known URI, at which a web origin publishes one link set describing the knowledge artifacts it offers: graph serializations, a JSON-LD context, an agent-facing text file, a chunk export, a change ledger, and related resources. Each artifact link may carry a SHA-256 digest (using HTTP digest-field syntax) so a client can verify a retrieved artifact matches what the publisher described, and a profile URI identifies the conventions followed. It defines no new media type or link relation (using the existing describedby relation) and requests one well-known URI registration.

draft-wang-sidrops-fcbgp-protocol-06 Individual rev -06 abstract

Defines Forwarding Commitment BGP (FC-BGP), a BGP extension that secures the AS path a BGP UPDATE traverses. A Forwarding Commitment (FC) is a cryptographically signed segment certifying an AS's routing intent on its directly connected hops; based on FCs, FC-BGP builds a secure inter-domain system that authenticates the AS_PATH attribute and mitigates route leaks. The extension is backward compatible, so a supporting router can interoperate with one that does not support it.

draft-song-emu-eapaka-pqc-sack-01 Individual rev -01 abstract

Specifies an extension to EAP-AKA' that introduces a bitmap-based Selective Acknowledgment (SACK) mechanism to the AT_FRAGMENT attribute. This enables window-based transmission and precise recovery of lost fragments, optimizing fragment delivery during post-quantum identity concealment and authentication exchanges.

draft-song-emu-eapaka-pqc-sack-00 Individual new -00 abstract

Specifies an extension to EAP-AKA' that introduces a bitmap-based Selective Acknowledgment (SACK) mechanism to the AT_FRAGMENT attribute. This enables window-based transmission and precise recovery of lost fragments, optimizing fragment delivery during post-quantum identity concealment and authentication exchanges.

By its name, this individual submission concerns a mapping for agent selection in the context of Computing-Aware Traffic Steering (CATS). Its official Abstract could not be retrieved on this run (the document page returned HTTP 404), so this summary is approximate and will be grounded from the Abstract on the next run.

draft-ietf-cats-metric-definition-13 WG CATS rev -13 abstract

Computing-Aware Traffic Steering (CATS) optimizes steering of traffic to a service instance by considering the dynamic state of computing and network resources. This document focuses on compute and communication metrics for CATS and defines a hierarchical abstraction of them to improve interoperability, scalability, and operational simplicity. It does not standardize raw infrastructure (Level 0) metrics; instead it specifies higher-level representations derived from raw measurements via aggregation and normalization.

draft-wu-idr-flowspec-dip-community-filter-02 Individual rev -02 abstract

BGP Flowspec (BGP-FS) propagates traffic flow specifications and filtering actions using BGP NLRI and Extended Community encodings. This document specifies a new BGP-FS component type for community-level filtering: the match field is the community of the destination IP address encoded in the Flowspec NLRI, applied within a single administrative domain.

draft-ietf-opsawg-scheduling-oam-tests-10 WG OPSAWG rev -10 abstract

Defines two YANG data models to support scheduled network diagnosis using OAM tests. The oam-unitary-test and oam-sequence-test modules manage the lifecycle of network-diagnosis procedures, intended for use by external management and orchestration systems (including SDN controllers and orchestrators) rather than by individual network nodes.

OAuth 2.0 access tokens are typically scoped to a session rather than a transaction. This document defines Transactional Access Tokens: a JWT access-token profile that carries a transaction identifier and authorization-server-asserted transaction context, has a very short lifetime, and is audienced to a single resource server. They align with OAuth Transaction Tokens so transaction context can flow from the AS to a resource server and onward into its trust domain; a primary use case is task-scoped authorization of AI agents, where the AS makes a fresh policy decision per transaction.