IETF Daily — Internet-Drafts & RFCs

48-hour window · 2026-09-29 · generated 2026-09-29 05:19 UTC
8 drafts 0 RFCs 8/8 drafts with official abstract Published: https://ietf-drafts-ok.pages.dev

Newly published RFCs

No RFCs were announced in the last 48 hours. The ietf-announce archive shows no "RFC NNNN on..." announcements after 2026-09-19; no items in the window.

Drafts

draft-templeman-scitt-framing-space-01 Individual rev -01 abstract 2026-09-27

Reports a measurement of how CBOR encoding freedoms affect digest-based identification of COSE_Sign1 signed statements. Taking one 165-octet COSE_Sign1 object and re-emitting it under every combination of six CBOR encoding choices yields 64 distinct byte sequences, all carrying an identical, valid signature yet producing 64 distinct data-hash values with no collisions. A stock CBOR decoder accepted all of them, and 31 were silently repaired back into the original form simply by being read. The document specifies nothing and proposes no protocol text: it reports the measurement, publishes a reproduction recipe, and points to prior work that already addresses the framing problem it quantifies.

draft-templeman-scitt-measurement-capsule-00 Individual new -00 abstract 2026-09-27

Defines the 'measurement capsule', a small, deterministic JSON record in which a party that is neither the subject of a claim nor a participant in the action records what the subject declared, what the measuring party observed, and the difference between the two. A capsule carries digests of its evidence and a measurement state in which 'could not be checked' is a first-class outcome, and it contains no decision, approval, or authorisation. Capsules are identified by the SHA-256 of their JCS serialisation and batched under an RFC 9162 Merkle Tree Hash. The draft describes registration as SCITT Signed Statements (RFC 9943), how a capsule refers to rather than restates receipts issued under other profiles, and one implementation, including where it does not yet match the profile.

draft-mih-agent-disclosure-envelope-00 Individual new -00 abstract 2026-09-27

Defines the Disclosure Envelope, an out-of-band wrapper structure for revealing the raw content behind a digest-only field of an Agent Action Capsule to a verifier. The envelope lets a party disclose the underlying value without altering the Capsule's own bytes or recomputing its capsule_id, so the original commitment is preserved while selected evidence is made intelligible on demand.

draft-mih-zhang-agent-disclosure-bundle-00 Individual new -00 abstract 2026-09-27

Defines the AAC Evidence Bundle, a portable presentation and verification container for an Agent Action Capsule together with the records that make its evidentiary claim intelligible. The bundle packages the capsule and its supporting material so that a verifier can carry and check the full evidentiary context as a single unit.

draft-mih-agent-evidence-request-00 Individual new -00 abstract 2026-09-27

Defines a transport-agnostic request/response interaction for obtaining verifiable evidence from an untrusted counterparty - an audit trail, an interaction history, or an account of actions taken - that the requester can check rather than merely believe. Outcomes are constrained to exactly three possibilities: the evidence artifact itself, a signed refusal with machine-readable reasoning, or a recorded absence. Features include caller invariance (identical artifacts for the same subject and coverage anchor regardless of who asks), symmetric asking (either party may request evidence about a prior exchange), and optional retention commitments that make later absences attributable to the responder. The document deliberately does not define evidence formats, identity schemes, trust policies, authorization rules, or availability guarantees, leaving these as deployment-specific concerns.

draft-mih-scitt-agent-action-capsule-05 Individual rev -05 abstract 2026-09-27

Defines a SCITT statement profile for recording what an AI agent did: the Agent Action Capsule. A capsule is a digest-committed record of a single agent action carrying its verdict-level disposition (executed, blocked, denied, errored, or timed out), the deterministic constraints that were evaluated, and the effect that was committed - together with a confirmed-effect binding that distinguishes a dispatched attempt from an observed result - plus an honest human-in-the-loop flag.

draft-mih-scitt-checkpointed-local-log-01 Individual rev -01 abstract 2026-09-27

Specifies the Checkpointed Local Log (CLL), a producer-operated append-only log that turns a set of individually signed records (receipts, attestations, statements) into a stream with provable order, contemporaneity, and completeness. Individual records verify on their own, but a stored collection proves nothing, since records can be deleted, reordered, or created after the fact without detection. The CLL is built on the Merkle Mountain Range structure (whose COSE proof formats are specified in a companion draft) plus a small signed checkpoint that commits to the log's entire history; checkpoints are emitted on a declared cadence and may be registered with one or more independent Transparency Services or witnesses using existing SCITT registration. The draft defines the log discipline and checkpoint structure only - no new proof formats, transparency-service behaviour, or payload semantics - and states precisely and narrowly what such a log does and does not establish.

draft-seymour-wimse-connected-flight-05 Individual rev -05 abstract 2026-09-27

Extends the Zero Trust Fabric Layer (ZTFL), which verified a single autonomous agent issuing a single request, to the case where that agent delegates its authority to a second or third agent - a pattern already standard in multi-agent orchestration. Using an international-travel analogy, it introduces four credential types: an immutable Passport for identity, a Root Ticket binding all hops to one authorized chain, per-hop Boarding Passes derived from the Ticket, and Visas required only when crossing tenant boundaries. The model is formalized as a boundary-conditional evaluation function, validated against the Cedar policy language, and compared with OAuth Token Exchange, delegation logic, and relationship-based authorization. Its central aim is chain-wide traceability to a single origin together with containment at the boundary itself - properties the draft argues none of the existing approaches structurally enforce.