Run date 2026-09-04 · window 2026-09-02 .. 2026-09-04 (UTC) · all working groups (100% coverage)
The ietf-announce archive shows no RFC/BCP announcements after 2026-08-31; there are no newly published RFCs in the 48-hour window.
Describes a lightweight, decentralized multicast group address allocation protocol named GAAP ("Group Address Allocation Protocol", pronounced "gap"). GAAP requires no configuration and no centralized services. The protocol runs directly among group participants that need a unique multicast group address in order to send and receive multicast packets, letting them agree on addresses cooperatively without a central allocator.
By its title, a BGP-LS Extension for Inter-AS Topology Retrieval. It probably extends BGP Link-State (BGP-LS) so that topology information spanning autonomous system (AS) boundaries can be collected and retrieved, helping controllers build an inter-AS view of the network. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Specifies extensions to the Path Computation Element Communication Protocol (PCEP) for Segment Routing point-to-multipoint (P2MP) policies. SR P2MP policies are a set of policies that enable an architecture for P2MP service delivery. The extensions allow a stateful PCE to compute and initiate P2MP paths from a Root to a set of Leaves, supporting SR-based tree building for multicast-style distribution.
By its name, this individual draft appears to concern a simplified approach to RFC/registry handling ("rfcregsimples"). Details are approximate because the official abstract could not be retrieved this run; it will be grounded next run.
By its name, an individual draft on silent-host detection for LISP (Locator/ID Separation Protocol) — probably mechanisms for a LISP system to detect hosts that have not yet sent traffic. Description approximate; to be grounded from the abstract next run.
By its name, an overview of the core of a protocol abbreviated "PSHMP". The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
By its name, an individual draft on advertising "creative" signaling for Media over QUIC (MoQ) — probably how ad creatives are signaled within MoQ media delivery. Description approximate; to be grounded from the abstract next run.
Titled the Reilly Banking Integrity Protocol (RBIP). By its title it likely proposes a framework for tamper-evident integrity of banking records. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Titled "Intra-handshake (aka Early) Attestation Considered Harmful" (referencing CVE-2026-33697 and further CVEs). By its title it argues against performing attestation inside the handshake and documents associated security vulnerabilities. Description approximate (from the title); to be grounded from the abstract next run.
By its name, an individual draft on a delegation chain for agents within WIMSE (Workload Identity in Multi-System Environments) — probably how authority is delegated along a chain of agents/workloads. Description approximate; to be grounded from the abstract next run.
By its name, a SCITT (Supply Chain Integrity, Transparency and Trust) draft about receipts for physical-site engagement — probably transparency receipts recording physical-site interactions. Description approximate; to be grounded from the abstract next run.
Many workloads face restrictions on the geography in which they may operate, often due to regulation requiring computation to occur within a particular jurisdiction. This document defines how to encode a variety of geographical conclusions inside an Attestation Result, so that a relying party can reason about where an attested workload is running.
Titled "Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems." By its title it proposes a standardized logging/audit-trail format for actions taken by autonomous AI agents. Description approximate (from the title); to be grounded from the abstract next run.
Titled "LISP YANG Model." By its title it defines a YANG data model for configuring and managing the Locator/ID Separation Protocol (LISP). Description approximate (from the title); it will be grounded in the official abstract on the next run.
Titled "External Temporal Anchoring for Transparency Services." By its title, a SCITT-related draft on anchoring transparency-service timestamps to an external time source. Description approximate (from the title); to be grounded from the abstract next run.
By its name, an LSR (Link State Routing) draft on advertising capabilities in IGP Hello messages — probably a way for routers to signal capabilities during IS-IS/OSPF neighbor discovery. Description approximate; to be grounded from the abstract next run.
By its name, an individual draft concerning "QR trust residuals." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Titled "YANG Data Model for RPKI to Router Protocol." By its title it defines a YANG model for configuring and monitoring the RPKI-to-Router (RTR) protocol used in BGP origin validation. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Titled "Extensible Provisioning Protocol (EPP) Transport over HTTPS." By its title it specifies how to carry EPP over HTTPS as a transport. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Titled "The Governance Audit Record (GAR) for Agentic AI Systems." By its title it defines an audit-record format for governance of agentic AI systems. Description approximate (from the title); to be grounded from the abstract next run.
A companion to RFC 7925 that defines TLS/DTLS 1.3 profiles for Internet of Things (IoT) devices. It adapts the (D)TLS 1.3 handshake and options to the constraints of embedded and constrained devices and updates RFC 7925 with respect to the X.509 certificate profile, giving implementers a concrete, interoperable security baseline for IoT deployments.
Titled "The Human Escalation Mechanism (HEM) for Agentic AI Systems." By its title it defines a mechanism for escalating decisions from an autonomous AI system to a human. Description approximate (from the title); to be grounded from the abstract next run.
Provides simple guidance for users of common Authenticated Encryption with Associated Data (AEAD) algorithms, which offer confidentiality and integrity. Because excessive use of the same key gives an attacker an advantage in breaking these properties, the document explains how to bound key usage to limit that advantage. It considers limits in both single-key and multi-key settings. An IRTF CFRG research-group document.
Addresses a problem with Route Target Constraints (RTC) in networks that use hierarchical Route Reflectors (RRs). RTC builds a VPN route-distribution graph so routers receive only the VPN routes for route-targets they care about, but with hierarchical RRs this can cause incorrect VPN route distribution and loss of connectivity. The draft proposes modifications to the RTC RFC to solve the hierarchical-RR RTC problem efficiently. (Grounded in the abstract of the predecessor individual draft.)
Describes using resource-aware Segment Identifiers (SIDs) to build Segment Routing (SR) based Virtual Transport Networks (VTNs) for Enhanced VPN. A resource-aware segment is associated with a set of reserved network resources; a group of such SIDs can build SR-based virtual underlay networks with the customized topology and resource attributes required by particular customers or services. These virtual networks are the SR instantiation of VTNs.
Defines an extension to OAuth 2 that lets a client instance include a key-bound attestation when interacting with an Authorization Server or Resource Server. The mechanism enables client instances that are traditionally viewed as public clients to use a key-bound attestation to authenticate, strengthening client authentication for deployments that could not otherwise hold a confidential credential.
Titled "IGP Reverse Prefix Metric." By its title it defines a way to advertise a reverse-direction metric for prefixes in link-state IGPs (IS-IS/OSPF). Description approximate (from the title); to be grounded from the abstract next run.
By its name, an ANIMA (Autonomic Networking) individual draft related to "OTP CASA." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
By its title, a BGP-LS Extension for Inter-AS Topology Retrieval. It probably extends BGP Link-State (BGP-LS) so that topology information spanning autonomous system (AS) boundaries can be collected and retrieved, helping controllers build an inter-AS view of the network. Description approximate (from the title); it will be grounded in the official abstract on the next run.
By its name, an individual draft concerning auditing for "PALA." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
By its name, an individual draft on a "single stack 100/50" approach — likely an IPv6 single-stack transition/deployment topic. Description approximate; to be grounded from the abstract next run.
By its title, a BGP-LS Extension for Inter-AS Topology Retrieval. It probably extends BGP Link-State (BGP-LS) so that topology information spanning autonomous system (AS) boundaries can be collected and retrieved, helping controllers build an inter-AS view of the network. Description approximate (from the title); it will be grounded in the official abstract on the next run.
The OAuth 2.1 Authorization Framework. Lets an application obtain limited access to a protected resource, either on behalf of a resource owner (by orchestrating an approval interaction between the owner and an authorization service) or on its own behalf. This specification consolidates and obsoletes the OAuth 2.0 framework of RFC 6749 and the Bearer Token Usage of RFC 6750, folding years of security best current practice into a single document.
Describes a lightweight, decentralized multicast group address allocation protocol named GAAP ("Group Address Allocation Protocol", pronounced "gap"). GAAP requires no configuration and no centralized services. The protocol runs directly among group participants that need a unique multicast group address in order to send and receive multicast packets, letting them agree on addresses cooperatively without a central allocator.
By its name, a REGEXT draft on the RDAP status set (probably status-value mapping/handling for the Registration Data Access Protocol). Description approximate; to be grounded from the abstract next run.
By its name, a REGEXT draft on the EPP status set (probably status-value mapping/handling for the Extensible Provisioning Protocol). Description approximate; to be grounded from the abstract next run.
By its name, an individual draft on a protocol abbreviated "AICP." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Defines a TLS extension letting clients indicate one or more workload identifier scopes in the ClientHello. Each scope pairs a URI scheme with a trust-domain component, representing the administrative domain and identifier namespace in which the client operates. These hints help the server decide whether client authentication is required and which policies or trust anchors apply, improving mutual-TLS efficiency while minimizing exposure of sensitive identifiers; it can be combined with Encrypted Client Hello (ECH).
By its name, an OAuth draft on X.509-based bearer credentials — probably using X.509 certificates as bearer tokens or credentials in OAuth. Description approximate; to be grounded from the abstract next run.
By its name, an individual draft named "Cedulon." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Titled "Intra-handshake (aka Early) Attestation Considered Harmful" (referencing CVE-2026-33697 and further CVEs). By its title it argues against performing attestation inside the handshake and documents associated security vulnerabilities. Description approximate (from the title); to be grounded from the abstract next run.
Defines version "2.0" of JSCalendar, a data model and JSON representation of calendar data for storage and data exchange in calendaring and scheduling environments. It obsoletes RFC 8984 (version "1.0"). Version 2.0 aims to improve interoperability with existing iCalendar-based systems and aligns its definitions with JSContact, including the IANA registry policy, validation requirements, and versioning scheme.
Titled "JSCalendar: Converting from and to iCalendar." By its title it specifies how to convert calendar data between the JSCalendar JSON format and iCalendar. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Defines ML-KEM-512, ML-KEM-768, and ML-KEM-1024 as TLS NamedGroups and registers IANA values in the TLS Supported Groups registry for use in TLS 1.3. This provides standalone (non-hybrid) post-quantum key establishment in TLS based on the NIST-standardized Module-Lattice Key-Encapsulation Mechanism.
Second edition of the CDNI Control Interface / Triggers specification; obsoletes RFC 8007. Describes the part of the Content Delivery Network Interconnection (CDNI) Control interface that lets one CDN trigger activity in an interconnected CDN delivering content on its behalf. An upstream CDN can request that the downstream CDN preposition metadata or content, invalidate or purge it, and monitor the status of the triggered activity.
Titled "Merkle Tree Certificates Deployment Use Cases." By its title it collects deployment scenarios for Merkle Tree Certificates (MTC). Description approximate (from the title); to be grounded from the abstract next run.
Titled "CBOR: Generating Numeric Map Labels from Textual EDN." By its title it describes producing numeric map keys from textual CBOR Extended Diagnostic Notation (EDN). Description approximate (from the title); to be grounded from the abstract next run.
Describes how to encode Evidence produced by an Attester for inclusion in Certificate Signing Requests (CSRs), together with any certificates needed to validate it. A client requesting a certificate can thereby offer believable claims about how the corresponding private key is protected (for example, residing in a hardware security module). Such Evidence improves a CA's assessment of the key's security posture and can convey manufacturer, firmware and software versions, and hardware protection capabilities.
Titled "Structural Vulnerabilities in ASRank under Adversarial Conditions." By its title it analyzes weaknesses of the ASRank AS-ranking approach when facing adversarial manipulation. Description approximate (from the title); to be grounded from the abstract next run.
Describes how to encapsulate the Simple Two-Way Active Measurement Protocol (STAMP, RFC 8762) and its optional extensions (RFC 8972) for Pseudowires (PWs) and Label Switched Paths (LSPs) in MPLS networks. The procedure uses the Generic Associated Channel (G-ACh) to carry STAMP test packets, with or without an added IP/UDP header, enabling performance measurement of PWs and LSPs.
Recommends improved DNS resolver behavior for processing NS record sets during iterative resolution. When following a referral to a child zone, resolvers should explicitly query the authoritative NS RRset at the child apex and cache it in preference to the parent-side NS RRset; associated address records should likewise be re-queried to replace lower-trust cache entries. Resolvers should also periodically revalidate the delegation by re-querying the parent when the parent-side NS TTL expires.
By its name, an individual draft related to "video surfing." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Titled "The Vaara Receipt: A Recomputable Receipt Format for Decisions About Autonomous Actions." By its title it defines a recomputable receipt format recording decisions about autonomous actions. Description approximate (from the title); to be grounded from the abstract next run.
Titled "BFD Path Consistency over SR." By its title it addresses keeping Bidirectional Forwarding Detection (BFD) sessions consistent with the forwarding path in Segment Routing networks. Description approximate (from the title); to be grounded from the abstract next run.
By its name, an OAuth draft on agent delegation — probably delegating authorization to (AI) agents acting on a user's behalf. Description approximate; to be grounded from the abstract next run.
Specifies the In-Network Inference Protocol (INIP), a lightweight protocol for high-speed in-network inference within data-center internal networks. INIP uses a two-tier design: a control plane that manages inference models and uses CDN-like scheduling to push model rules to data-plane devices, and a data plane that performs packet parsing and match-action-table-based inference. It covers packet format, model expression, dynamic model replacement, and execution procedures.
By its name, an individual draft named "Cedulon." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Titled "Definition of Service Intent in Autonomic Networks." By its title it defines the notion of "service intent" for ANIMA autonomic networking. Description approximate (from the title); to be grounded from the abstract next run.
By its name, an individual draft related to "DAWN AID." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
By its name and related mailing-list discussion, this draft concerns "execution-finality" and act-bound authorization for AI-agent interoperability — probably binding an authorization to a specific, final action an agent may take. Description approximate; to be grounded from the abstract next run.
Describes how a CoAP endpoint can discover OSCORE security groups and acquire the information needed to join them via the respective Group Manager, using resource descriptions and links registered at the CoRE Resource Directory. Group communication over CoAP can be secured with Group OSCORE, but devices may not know in advance which groups to join or which Group Manager to use. A single security group may protect multiple application groups, and the approach is consistent with the ACE framework.
Defines "Modern Network Unicode" (MNU), a form of RFC 5198 Network Unicode for specifications that exchange plain text over networks where simply mandating UTF-8 is not enough, but the full baggage of RFC 5198 (with its Telnet legacy) is undesirable. MNU comes in a one-dimensional variant for identifiers and labels and a two-dimensional variant for line-structured text such as plain-text documents or Markdown, with room for further tailored variants.
Updates the Authentication and Authorization for Constrained Environments (ACE) framework by defining a method to enforce bidirectional access control using a single access token. This lets both directions of an interaction be authorized from one token rather than requiring separate credentials. The document updates RFC 9200.
Defines a backward- and forward-compatible module structure for the Concise Data Definition Language (CDDL). CDDL is currently defined by RFC 8610 and RFC 9165, the latter using the single "control operator" extension point of RFC 8610. As CDDL is adopted in larger projects, corrections and features are needed that cannot be mapped onto that single extension point, so the base specification itself must evolve; this document adds modularity to enable that.
Titled "Proxy Operations in Group Communication for the Constrained Application Protocol (CoAP)." By its title it specifies how proxies operate in CoAP group communication. Description approximate (from the title); it will be grounded in the official abstract on the next run.
Describes prominent scenarios in which enterprise systems and networks that hold digital assets need to transfer those assets or data securely to one another. It sets out Secure Asset Transfer (SAT) use cases that motivate the SATP protocol work, framing the requirements for gateway-to-gateway asset transfer across independent systems.
A "feature freezer" collecting nice-to-have features for the Concise Data Definition Language (CDDL) that did not make it into the first CDDL RFC (RFC 8610) or the specifications that exercise its extension points (such as RFC 9165). Significant parts have since moved to the CDDL 2.0 project (draft-bormann-cbor-cddl-2-draft); the remaining items here are not directly related to that CDDL 2.0 effort.
By its name, an individual draft on a "single stack 100/50" approach — likely an IPv6 single-stack transition/deployment topic. Description approximate; to be grounded from the abstract next run.
By its name, a Transport Area (TSVWG) individual draft abbreviated "CAMP." The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Defines a YANG data model to configure and manage IPv6 Neighbor Discovery (ND) and related functions. Coverage includes IPv6 address resolution, the redirect function, proxy Neighbor Advertisement, Neighbor Unreachability Detection (NUD), Duplicate Address Detection (DAD), and Enhanced DAD, giving operators a standard model for managing IPv6 ND behavior.
Titled "AuthZEN Binding for OAuth 2.0 Token Exchange." By its title it binds the AuthZEN authorization model to OAuth 2.0 Token Exchange. Description approximate (from the title); to be grounded from the abstract next run.
By its name, an OAuth draft on AuthZEN authorization claims — probably how an Authorization Server obtains or represents authorization claims via AuthZEN. Description approximate; to be grounded from the abstract next run.
By its name, an OAuth draft on AuthZEN token issuance — probably externalizing the token-issuance decision to a policy decision point via AuthZEN. Description approximate; to be grounded from the abstract next run.
Describes an experimental protocol, the Available Session Recovery Protocol (ASRP), for optimizing high-availability network cluster architectures for stateful services such as load balancing and NAT. Its key idea is to distribute session state to clients or servers rather than holding it centrally, which improves elastic scaling, supports rapid failure recovery, reduces resource redundancy, and simplifies cluster implementation for large-scale elastic clusters.
By its name, an individual draft on an agent URI scheme ("creduent agent uri"). The specifics are approximate because the official abstract was not retrieved this run; it will be grounded next run.
Defines combinations of ML-KEM in hybrid with traditional algorithms (RSA-OAEP, ECDH, X25519, and X448), tailored to meet security best practices and regulatory guidelines. Composite ML-KEM applies to any application using X.509 or PKIX data structures that accept ML-KEM but where the operator wants extra protection against breaks or catastrophic bugs in ML-KEM alone.