By its name, this individual draft appears to propose a reference architecture for AI-agent accountability. The document page could not be opened, so no official abstract was available; the description is inferred from the title and is approximate. It probably outlines architectural roles and mechanisms for attributing and recording agent actions across systems. Specific claims, components and scope should be confirmed against the draft itself; it will be grounded on the next run.
Specifies Explicit Congestion Notification (ECN) and congestion-feedback support within a Service Function Chaining (SFC) enabled domain. ECN lets a forwarding element signal the onset of congestion without dropping packets, and coupling it with feedback to upstream nodes can improve congestion control and network efficiency. The document uses the Network Service Header (NSH, RFC 8300) together with IP Flow Information Export (IPFIX, RFC 7011) to carry ECN and feed congestion information back within the SFC domain.
Addresses distributed systems where one component acts on a decision produced by another (authorization server, policy engine, risk service, attestation Verifier, safety controller). The risk is not only forged credentials: an intermediary can claim an external check passed, replay a prior decision, substitute evidence, suppress a required DENY, or keep evidence only for audit. It introduces an architectural role, External Decision Evidence (EDE), not a new wire format. The invariant: a Candidate Act stays non-effective until the Finality Sink independently establishes that every required external authority issued an applicable, fresh, audience-bound decision for the concrete act. It complements OAuth introspection, HTTP Message Signatures, RATS, Transaction Tokens and SCITT.
Presents a state- and policy-continuity model for execution finality, addressing security decisions made against mutable state (policy bundles, mapping tables, reference values, ownership records, revocation state). A cryptographically authentic permit can stay valid as an object while becoming stale as authority. A Candidate Act stays non-effective until a protected Finality Sink verifies the concrete act, the identity of the evaluated policy/mapping content, protected generations/epochs, relevant mutable state, freshness and use constraints immediately before effectuation. Revision identity is treated as content-bound, so a policy revision change requires re-evaluation unless applicability is explicitly established. It complements RATS, EAT, SUIT anti-rollback, OAuth fine-grained authorization and sender-constrained tokens.
Defines a jurisdiction-bound execution-finality invariant for cloud, AI, financial and telecom systems spanning regions, sovereign clouds and multi-cloud chains. A high-consequence authorization can be valid under one jurisdictional context (J1) yet become effective under a different one (J2) through workload migration, DR failover, cross-region queues, rerouting or remote administration, with no token forgery required. A Candidate Act stays non-effective until a Finality Sink establishes a current Jurisdiction Execution Context for the exact act and verifies the present environment satisfies the deployment's jurisdiction policy. It complements OAuth RAR/Resource Indicators, WIMSE, RATS and SCITT and industry sovereignty controls; prevention is claimed only where the policy and path coverage are load-bearing and non-bypassable, not from GeoIP or region labels.
Describes a finality-bound revocation model for consequence-bearing systems, where an authorization legitimate at issue can become unsafe before the operation becomes externally effective. A Candidate Act remains non-effective after upstream authorization and is bound to an act-specific revocation basis (generation, epoch, status root). Immediately before commit, a Finality Sink checks that no applicable revocation, suspension, narrowing, or superseding state has become load-bearing. With authoritative state, atomic check-and-commit, and complete path mediation this is a prevention property; bounded staleness yields only mitigation. It complements OAuth revocation/introspection, Entra CAE, Verified Permissions/Cedar and Google Cloud IAM, focusing on ordering between revocation state and the exact commit including queues, delegation and TOCTOU races.
Introduces a consequence-oriented execution-finality model targeting a coverage failure: a correctly implemented authorization gate cannot prevent a protected effect if the same effect stays reachable through another path. The contribution combines defining the Protected Consequence explicitly, bounding the Effectuation Domain, establishing a Finality Cut Set across heterogeneous paths, and binding coverage to a protected Path-Set Generation so topology changes cannot silently inherit prior completeness claims. It applies to cloud authorization, service meshes, financial commits, device actions and industrial control. Where path discovery is incomplete, enforcement bypassable, or topology stale, the mechanism yields mitigation or detection rather than a prevention guarantee.
Proposes an actuation-bound execution-finality invariant for cyber-physical and industrial systems that accept commands from cloud services, AI agents, or remote operators. Even when identity, authorization, integrity and attestation are individually correct, a digitally valid command can still cause an unsafe physical effect (drive energization, robotic motion, valve actuation) if the target actuator, machine mode, or safety state has changed. A Candidate Act stays in a Non-Effective State until a protected Actuation Finality Boundary (AFB) verifies the exact command, current authority, actuator identity, freshness, and required safety predicates immediately before or atomically with the physical output. The AFB is an architectural role an existing safety PLC, drive, or SIS can fill; it complements IEC 61508/61511, IEC 62443 and OPC UA Safety and must never convert a safety DENY into ALLOW.
Describes a YANG data model to support performance monitoring for client signals in transport networks. A transport network is a server-layer network providing connectivity to its client; once a client signal is configured, follow-up performance monitoring such as latency and bit error rate is needed for network operation. The model provides the structures to support those performance-monitoring functionalities.
Defines a new DNS resource record type, AGENT, which is SVCB-compatible, and specifies its mapping rules. With the growth of intelligent agent communication and interaction protocols, the current DNS is seen as inadequate for agent service resolution; the AGENT RR provides a way to resolve agent services within the DNS.
Describes how to implement passwordless authentication in Web Authentication (WebAuthn) using the Module-Lattice-Based Digital Signature Standard (ML-DSA), a post-quantum cryptography signature scheme defined in FIPS 204. It brings a quantum-resistant signature scheme into the WebAuthn passwordless authentication flow.
Describes how the Stream Control Transmission Protocol (SCTP) can use multiple paths simultaneously to transmit user messages. SCTP already supports multi-homing for network fault tolerance, but mainly one path is used for data transmission and only timer-based retransmissions are carried over other paths. This document specifies concurrent multipath transmission of user messages.
States that the Automatic Extended Route Optimization (AERO) and Overlay Multilink Network (OMNI) Interface functional specifications have reached a maturity level ready for advancement in the RFC publication process. Updates to the base specifications are documented in this first amendment, with any additional amendments to follow as necessary.
Defines optional hop-by-hop cache signaling for Media over QUIC Transport (MOQT). A subscriber can query the cache status of a finite Track range or request the cache status of a FETCH. Responses report a hit, miss, or partial hit and can identify the locally cached ranges, helping relays and subscribers reason about what content is already cached along the path.
Defines a Media over QUIC Transport (MOQT) extension for atomically changing the Forward State of a set of established subscriptions. It lets a subscriber replace one set of Tracks with another without an intermediate, partially switched state appearing at its peer, ensuring the subscription change is applied as a single unit.
By its name, this individual draft probably defines an audit-trail mechanism for AI-agent actions. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It likely covers how agent operations are recorded for accountability and later verification. Details, formats and scope should be confirmed against the draft; it will be grounded on the next run.
Defines a composition profile for preserving an agent operation when its executor fails or is replaced after a consequential provider request may have crossed an effect boundary but before the outcome is known. Native authorization, succession, evidence-boundary and bounded-capability mechanisms cover parts of this interval but do not by themselves define how a replacement executor preserves the same provider operation and its unresolved evidence. The profile preserves stable operation-occurrence identity, immutable provider bindings, authority accounting, uncertain evidence, and stale-executor fences across replacement, within one authoritative coordination domain. It defines no new receipt, identity, authority, provider, or ledger-migration format.
Defines a new WLAN-Security-Profile RADIUS attribute. Because IEEE 802.11 security profiles can share the same AKM suite and pairwise cipher, the existing WLAN-AKM-Suite and WLAN-Pairwise-Cipher attributes no longer tell a RADIUS server which profile is in effect. The new attribute reports the security profile the responder accepted; a Network Access Server includes it in Access-Requests generated for IEEE 802.1X authentication so the server can make policy decisions on that value. It complements the IEEE 802 attributes defined in RFC 7268.
Presents an optional new type of link-state database synchronization packet, the Aggregated SNP Hash (ASH). When feasible it compresses traditional SNP exchanges into a dynamic Merkle-tree-like structure, speeding up synchronization of large databases and adjacencies while reducing the load from regular CSNP exchanges during normal operation. Like CSNPs and PSNPs, ASH packets come in two flavors: Complete ASH (CASH) and Partial ASH (PASH).
Defines Contestability Binding Application Profile 1 (CBAP-1), a closed application profile that binds an Authorization Artifact to signed contestation terms before execution. Signed authorization records can show an action was authorized but do not by themselves provide a stable, verifiable path for an affected party to contest it. CBAP-1 specifies deterministic CBOR and COSE encoding, fixed artifact formats, executor-verification and execution records, by-value policy material, a half-open filing window, a closed structured result, and deterministic first-failure reason codes. It does not define contestation notices, execution-state effects, reachability or freshness checks, dispute adjudication or remedy, and asserts no forum independence, legal validity or fairness.
Updates RFC 6724 with three improvements to IPv6 destination address selection. The updates let recent IPv6 connection or service failures influence IPv6/IPv4 ordering, incorporate likely source/destination address pairs when sorting candidates, and let ISP and enterprise operators preserve DNS load-balancing order where Rule 9 would otherwise override it. The changes are intended to be implementable inside getaddrinfo() or an equivalent system mechanism without requiring changes to existing application-facing socket APIs.
Provides a practical guide to deploying 464XLAT-based IPv6-only technology on the user plane in 3GPP 5G networks. It covers key 5G concepts and architectures, configuration methods, and operational challenges, helping operators run IPv6-only user planes while retaining IPv4 service through 464XLAT.
Requests that IANA allocate address space specifically for use in space environments and manage suballocations from that block for and within celestial bodies. Without a structured allocation plan, early space missions risk an unaggregated patchwork of prefixes, repeating the scaling problems seen in terrestrial networks. The Number Resource Organization (NRO) would determine how to allocate and assign resources for and within celestial bodies, with topological aggregation treated as critical for routing scalability and operational efficiency.
Proposes best practices for authentication and authorization of AI-agent interactions, leveraging existing standards such as the Workload Identity in Multi-System Environments (WIMSE) architecture and the OAuth 2.0 family. Rather than defining new protocols, it describes how existing, widely deployed standards can be applied or extended to establish agent authentication and authorization, providing a framework, identifying gaps, and guiding future standardization work for agents.
Defines the TLS Trust Anchors extension, a mechanism for a TLS client or server to select which certificate to present based on the peer's trusted certification authorities. It describes certification authorities more succinctly than the existing TLS Certificate Authorities extension, helping endpoints choose an acceptable certificate chain during the handshake.
Describes best current practices for operating an RFC 8181 publication engine for the Resource Public Key Infrastructure (RPKI) and its associated publicly accessible repositories, including rsync (RFC 5781) and the RPKI Repository Delta Protocol (RRDP, RFC 8182). It gives operational guidance for running RPKI publication servers reliably.
Outlines desirable security goals and use cases for integrating remote attestation (RA) with secure channel establishment protocols such as TLS and DTLS. Peer authentication establishes trust in a peer's network identifiers but gives no assurance about the integrity of its software and hardware stack; remote attestation fills that gap with verifiable evidence about the Target Environment. The document sets essential security goals (cryptographic binding to the connection, evidence freshness, flexibility across attestation models) and explores use cases such as confidential data collaboration and secure secrets provisioning, as input to the SEAT working group's design.
By its name, this working-group draft defines the architecture for SATP (the Secure Asset Transfer Protocol), used to move assets between distinct networks or ledgers. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It likely describes the roles, gateways and trust model involved in cross-network asset transfer. Specific components and requirements should be confirmed against the draft; it will be grounded on the next run.
Informational document describing a mobile routing service for the Aeronautical Telecommunications Network with Internet Protocol Services (ATN/IPS), which ICAO is investigating to support pervasive Air Traffic Management worldwide. The ATN/IPS will augment existing communication services with an IP-based service for air traffic controllers, airline operations controllers and commercial aircraft. The described service is a simple, extensible mobile routing approach based on the industry-standard Border Gateway Protocol (BGP) and the Domain Name System (DNS) to meet ATN/IPS requirements.
Defines a new packet and algorithm for OpenPGP (RFC 9580) to support persistent symmetric keys, for message encryption using authenticated encryption with additional data (AEAD) and for message authentication using AEAD authentication tags. This enables symmetric cryptography for data storage and other contexts that do not require asymmetric cryptography, offering improved performance, smaller keys, and improved resistance to quantum computing.
Introduces a new file-data caching attribute for NFSv4.2. Clients commonly perform client-side caching of file data for performance, and while applications may influence caching on some systems, there is no standardized way for a server or administrator to indicate that particular file data should not be cached for performance or correctness reasons. Files marked with the new attribute are intended to be accessed with client-side data caching suppressed, supporting workloads that require predictable data visibility. This document extends NFSv4.2.
Informational document describing the NFS_ACL protocol, a legacy member of the Network File System family. NFS_ACL is used by NFS clients to view and update Access Control Lists stored on an NFS version 2 or version 3 server. The document records the protocol for reference.
Defines a YANG module that extends the YANG-Push Subscription mechanism to enforce that particular revisions or semantic versions are used when configuring or establishing a Subscription. It also extends the YANG-Push Subscription state-change Notifications to include additional context about the YANG schema associated with the Subscription, improving version awareness for telemetry subscriptions.
Defines a new extensible Notification structure in YANG for use in YANG-Push Notification messages over both NETCONF and RESTCONF, enabling YANG-compatible encodings such as XML, JSON, or CBOR. It also defines two essential extensions to this structure: support for a hostname and sequence number, and support for a timestamp characterizing the moment when the data was observed.
Specifies the IGP protocol extensions needed to support SRv6 path egress protection using the Mirror SID (End.M) mechanism. It reuses the existing SRv6 End SID sub-TLV in IS-IS and OSPFv3 with the End.M endpoint behavior to advertise the Mirror SID and the set of protected locators, and defines a new Protected Locators sub-(sub-)TLV so a backup egress node (protector) can signal its capability to protect a primary egress node within a single link-state IGP area. It is a companion to the specification of the overall SRv6 egress-protection mechanism and End.M behavior.
Specifies the design for inter-domain multicast overlays using the Locator/ID Separation Protocol (LISP) architecture and protocols, describing how LISP multicast overlays operate over both multicast and unicast underlays. A signal-based approach using PIM programs LISP encapsulators with a replication list in a locator-set, where that list can mix multicast and unicast locators. When approved, the document obsoletes RFC 6831.
A short update to RFC 6211 that corrects an error in the definition of the id-aa-CMSAlgorithmProtect ASN.1 object identifier. The document notes that the corresponding IANA registry entry has always been correct, so the fix aligns the specification text with the registry.
Extends the JMAP base protocol (RFC 8620) with the ability to retrieve historical versions of objects. The base protocol synchronizes the current state of data objects between client and server; this extension adds retrieval of past versions, including objects that have been destroyed, by extending the standard Foo/get method.
Adds finer-grained conditional operations to JMAP. The base Foo/set method offers only the ifInState concurrency control, which guards an entire object type and rejects the whole method if any object of that type changed. This extension lets a client require that an individual update or destroy proceed only if the target object still matches expected property values, expressed via the existing JMAP PatchObject, giving per-object optimistic concurrency equivalent to an HTTP If-Match precondition. It also defines an optional atomic argument so an entire Foo/set applies as a single unit (all changes take effect or none), enabling safe multi-object changes such as an atomic rename that exchanges two names.
By its name, this IPPM working-group draft probably provides deployment guidance and considerations for the Alternate-Marking method of performance measurement. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It likely covers operational aspects of applying alternate-marking (loss and delay measurement) in real networks. Specifics should be confirmed against the draft; it will be grounded on the next run.
Specifies BGP mechanisms for SD-WAN (Software-Defined Wide Area Network) edge node attribute discovery. It defines a new tunnel type with associated Sub-TLVs for the BGP Tunnel Encapsulation Attribute, and a new Subsequent Address Family Identifier (SAFI) carrying a typed NLRI for advertising SD-WAN underlay tunnel information, so edge nodes can discover each other's attributes over BGP.
Defines a collection of common YANG data types, identities, and groupings intended to be imported by modules that model Layer 1 configuration and state. The Layer 1 types represent Layer 1 client signals applicable to transport networks such as Optical Transport Networks (OTN), and OTN data structures are included among the defined Layer 1 types, providing shared building blocks for Layer 1 YANG models.
Defines how to convert calendaring information between the JSCalendar and iCalendar data formats, considering every JSCalendar and iCalendar element registered at IANA at time of publication. It gives conversion rules for all elements common to both formats and describes how to convert arbitrary or unknown elements. It updates RFC 5545 (iCalendar) and jscalendarbis (JSCalendar) by defining new properties and parameters for conversion between the two formats.
Defines protocol mapping extensions for the Semantic Definition Format (SDF) so that protocol-agnostic SDF affordances can be mapped to protocol-specific operations. The mechanism lets SDF models specify how properties, actions and events are accessed over a given protocol. It defines mappings for Bluetooth Low Energy and Zigbee and can be extended to protocols such as HTTP and CoAP, and it also describes a method to extend SCIM with an SDF model mapping.
Extends the Semantic Definition Format (SDF) to represent non-affordance information of Things, such as physical, contextual, and descriptive metadata. It introduces a new class keyword, sdfContext, that enables more comprehensive modeling of Things and improves semantic clarity, complementing SDF's existing affordance-oriented constructs.
Describes an API that lets applications perform operations against a gateway serving one or more devices described by a Semantic Definition Format (SDF) model. The API consists of a RESTful application-layer interface for operations on those devices plus a CBOR-based publish-subscribe interface for streaming data, giving applications a uniform way to interact with SDF-modeled devices through a gateway.
By its name, this individual draft probably defines a framework for time-scheduled color in SPRING/segment routing, describing how color attributes are associated with time windows for traffic steering. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It seems to provide the framework companion to the behavior and IDR encoding drafts in the same set. Details should be confirmed against the draft; it will be grounded on the next run.
By its name, this individual draft probably specifies SRv6/SPRING forwarding behavior for time-scheduled color, i.e. how color-based steering changes according to a schedule. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It appears to pair with a companion framework draft and an IDR color-time-schedule draft. Specifics should be confirmed against the draft; it will be grounded on the next run.
By its name, this individual draft probably defines BGP/IDR signaling for time-scheduled color values, associating a route's color attribute with a time schedule. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It likely relates to time-based traffic steering using color, complementing the companion SPRING time-scheduled color drafts. Details should be confirmed against the draft; it will be grounded on the next run.
Explains how a DNS recursive resolver can securely receive the full root zone and put it into its cache, so it can answer from a local copy and reduce the number of queries sent to the root servers, preventing third-party snooping of those requests. This document obsoletes RFC 8806.
Defines policy for representing mathematical content in RFCXML and relevant publication formats, and allows new technology for that purpose. After the policy is implemented, the chosen mathematical notation format is to be used in RFCXML and in the HTML publication format, giving RFC authors a consistent way to include mathematics.
Defines Multi-Sheet Tab-Separated Values (MTSV), a text format carrying one or more sheets of tab-separated values in a single file. MTSV is TSV with one additional dimension: sheets are separated by the ASCII form feed (FF) character, and a TSV file with no FF (and no CR other than in CRLF line breaks) is already a valid MTSV file. The document also registers the text/prs.mtsv media type.
Describes a protected execution-finality architecture for AI-native and autonomous infrastructure that can generate, schedule, route, disclose, allocate, or initiate physical actions without a human in every step. Operations stay in a Non-Effective State until a Protected Enforcement Domain validates authority predicates and establishes protected state, and a Finality Sink at consequence boundaries performs final verification before an operation becomes externally effective. The core invariant: computation may produce a Candidate Act, but computation is not authority for consequence. It provides a large catalog of Enforcement Profiles spanning agentic AI, RAN control, ISAC, content delivery, cyber-physical actuation, network slicing, IoT, spectrum, cryptography, and hardware/silicon-layer operations.
Describes an execution-finality model for infrastructure where memory, accelerators, device interfaces and storage regions move dynamically between hosts, tenants, VMs and security domains. Existing mechanisms can authenticate devices, attest state, protect communication and authorize operations, but do not ensure the exact transition that becomes effective is still the one that was evaluated and authorized (for example, a reassigned memory extent exposed to a new tenant before sanitization completes). A proposed transition stays non-effective until a protected boundary verifies the concrete operation, bound to the exact resource, source, destination, generation, security state and freshness, with replay and alternate-path protections. It targets confidential multi-GPU (NVLink), Arm CCA/RME, UALink, and CXL pooled-memory systems.
Describes an execution-finality architecture for AI factories and AI-native network infrastructure, treated as heterogeneous hardware systems rather than isolated model-serving apps. Consequential hardware operations stay in a Non-Effective State until a Protected Enforcement Domain validates authority predicates and commits validation evidence, with operations bound to scoped non-bearer capabilities tied to specific descriptors, protected state, and a Finality Sink that has mandatory control over the consequence. The stated principle: computation may produce a Candidate Act, but computation is not authority for consequence. It provides Enforcement Profiles covering GPU egress, accelerator fabrics, memory systems, DPUs, SmartNICs, RDMA, CXL, optical interconnects, chiplets and physical infrastructure control.
Defines the Correctover Conformance Shape (CCS), a runtime verification framework for AI agent tool calls. CCS specifies seven verification dimensions (Structure, Schema, Latency, Cost, Identity, Integrity, Security) that tool calls and results must conform to at runtime, a receipt format with Ed25519 signatures, three verdict values (allow, deny, escalate), and four executor lifecycle states. This revision improves self-containment by reclassifying related AEB and CAID specs as informative while restating their normative requirements directly, corrects implementation descriptions, and clarifies connections to SCITT-based agent evidence efforts; the signature construction and receipt lifecycle are unchanged.
Defines a verifier-facing model for separating the distinct claims that agent communication protocols carry (user authority, agent instance identity, tool/resource identity, delegation state, session continuity, action evidence), which have different verifiers, freshness needs and failure modes. Collapsing them into one token or identifier can imply more authority than a receiver can verify. It provides a reusable matrix stating, per claim, which field carries it, who verifies it, what binding/freshness rule applies, required behavior when a claim is absent or stale, and what constrained result an application may consume. It is protocol-neutral and adds row-outcome semantics and dependency-closure rules so composite results never exceed their verified inputs.
Defines a SCITT profile for Physical-Site Engagement Receipts (PSER): tamper-evident, signed, offline-verifiable records describing an autonomous or human-directed physical engagement at a specific real-world site under a defined operating envelope. Each receipt is a SCITT Signed Statement encoded as a COSE Single Signer message carrying a JCS-canonicalized JSON payload with a five-artifact vocabulary (Site; Operator/Actor; Engagement Window and Envelope; TEE Attestation Evidence; Adapter Write-In). It makes a deliberately narrow, checkable claim and does not assert the engagement was safe or correct. A three-party trust model (Site Owner, TEE silicon vendor, Issuer) ensures no single party can forge or repudiate a receipt.
Defines AATR, a signed, non-bearer receipt that cryptographically binds an agent operation to the principal, policy, evidence set, decision, audience, validity interval, and predecessor authority state used for that decision. It targets autonomous agents acting across administrative and security domains using workload identities, OAuth credentials, delegated authorization, attestations and policy engines. The design separates evidence evaluation from authorization decisions and execution: required evidence must be present and valid, and missing or indeterminate evidence prevents authorization. AATR integrates with OAuth, workload identity systems, remote attestation and transparency services rather than replacing them.
Defines two post-quantum hybrid key exchange groups for TLS 1.3 that combine ML-KEM-512 with ECDHE: MLKEM512X25519 and SecP256r1MLKEM512. These groups offer lower-overhead hybrid key exchange for deployments where ClientHello size, fragmentation risk, constrained-device performance, or compatibility with existing infrastructure matter. They are intended for TLS 1.3 and DTLS 1.3 and follow the hybrid construction used by ECDHE-MLKEM key agreement.
Proposes Flexicast QUIC, a simple extension to Multipath QUIC that enables a source to send the same information to a set of receivers using a combination of unicast paths and IP multicast distribution trees, blending unicast and multicast delivery within one QUIC-based mechanism.
Describes GAAP, a lightweight decentralized multicast group address allocation protocol (pronounced 'gap'). GAAP requires no centralized service or coordination for the address-allocation protocol itself, though it depends on ASM-capable multicast routing being provisioned and may need extra configuration where encryption or administrative scoping is used. It runs among group participants that need a unique group address to send and receive multicast, works for IPv4 and IPv6, and offers a simple lightweight option rather than extending an existing protocol. The document is Experimental and states the rationale and criteria for concluding the experiment.
Respecifies NFS version 4 minor version 1 (NFSv4.1), including features retained from the base protocol (NFSv4.0, RFC 7530) and the extensions that are part of minor version 1. The later minor version has no dependencies on NFSv4.0 and was previously documented as a completely separate protocol. This document obsoletes RFCs 8881 and 8434 and incorporates numerous corrections, clarifications and revisions to protocol extension, internationalization and security aspects that supersede descriptions in RFCs 5661 and 8881.
Part of the rfc8881bis respecification effort, this document describes the structure and function of NFSv4 Access Control Lists in NFSv4.0 and NFSv4.1, using an ACL structure derived from Windows ACLs. It focuses on the role of these ACLs in providing more flexible file-access authorization than the POSIX-derived attributes, while also covering other ACL-based security functionality. Because previous specifications did not describe the authorization semantics satisfactorily, it takes a different approach while maintaining compatibility, and when published will supersede ACL descriptions in existing NFSv4.0/4.1 documents, updating RFC 7530 and RFC 8881.
Proposes the Personal Data Portability Archive format (PDPA), a format suitable for import/export, backup/restore, and data-transfer scenarios for personal data. It aims to give a common structure for moving a person's data between services.
Describes an existential-forgery vulnerability in the Cryptographic Message Syntax (CMS) and protocols that use it, arising because CMS signature verification behaves differently depending on whether signed attributes are present. The document lists mitigations and best practices to avoid the issue and updates RFC 5652 by prohibiting the use of the id-data content type for new uses of the CMS SignedData type.
By its name, this IDR working-group draft probably specifies additional criteria or signaling for BGP best-path selection. The document page could not be opened, so no official abstract was available and this description is inferred from the title and is approximate. It likely refines how routers choose among candidate BGP paths. Specific criteria and mechanisms should be confirmed against the draft; it will be grounded on the next run.
Specifies version 2.0 of JSCalendar, a data model and JSON representation of calendar data for storage and data exchange in calendaring and scheduling environments. It obsoletes RFC 8984 (version 1.0) and aims to improve interoperability with existing iCalendar-based systems, aligning its definitions with JSContact including the IANA registry policy, validation requirements, and versioning scheme.
Defines methodologies for benchmarking the performance of intra-domain and inter-domain source address validation (SAV) mechanisms, which generate SAV rules that prevent source address spoofing. The methodology treats a SAV device as a black box and is therefore agnostic to the specific SAV mechanism and implementation. It defines test setups, performance indicators, and test cases covering SAV accuracy, control-plane and data-plane performance, and resource utilization.
Describes using EVPN Ethernet Segment Link Aggregation Group (ES-LAG) technology to provide multi-homing redundancy for Layer 3 services. The solution synchronizes ARP/ND, multicast state, and IGP routes between redundant PEs without requiring Layer 2 constructs or proprietary Inter-Chassis Communication protocols, enabling L3 multihoming over an EVPN fabric.
Specifies an RTP payload format for a video signal encoded with JPEG XS (ISO/IEC 21122), a low-latency, low-complexity video coding system that keeps encoding-decoding latency to a fraction of a video frame. This revision updates RFC 9134 to support features in the third edition of JPEG XS, most notably the TDC coding mode. It obsoletes RFC 9134 while keeping existing conforming implementations valid, and consolidates the RFC 9134 errata with clarifications for implementers.
Specifies SDF modeling for digital twins, i.e. digital twin systems and their things. SDF is a format used to create and maintain data and interaction descriptions and to represent the various kinds of data exchanged for those interactions. The document shows how SDF can model the characteristics, behavior and interactions of physical objects in digital twins that contain those things as components.
Specifies the FideX Protocol (AS5), a modern application-layer protocol for secure business-to-business (B2B) message exchange. FideX provides cryptographic non-repudiation, data integrity and confidentiality using JOSE (JSON Object Signing and Encryption) over HTTPS, taking a REST-oriented approach meant to replace legacy AS2 and AS4. Following the 'AS' naming lineage (AS2 used S/MIME over HTTP, AS4 used SOAP/WS-Security), AS5 uses REST/JSON/JOSE over HTTPS. It defines message format, cryptographic operations, partner discovery, state management, acknowledgment receipts (J-MDN), and error handling.
Defines a non-transitive BGP attribute, the NLRI_KEY_LIST attribute, to improve error handling for BGP UPDATE messages. RFC 7606 reduced session resets via attribute discard and treat-as-withdraw, but treat-as-withdraw requires the entire NLRI field of MP_REACH_NLRI to parse successfully, so parse errors there often still force a session reset, worsened by non-key data in the NLRI. The new attribute encodes NLRIs in MP_UNREACH_NLRI format so treat-as-withdraw can be used when an error in MP_REACH_NLRI prevents parsing its NLRIs. It updates RFC 7606 by requiring the attribute to appear before MP_REACH_NLRI.
Describes an execution-finality architecture for satellite and non-terrestrial networks that are becoming programmable compute, routing, sensing, radio and AI infrastructures. Successful authentication, attestation, routing, scheduling or inference does not by itself establish authority for the resulting operation to become externally effective. A consequence-bearing operation is a Candidate Act that may remain in a Non-Effective State until a Protected Enforcement Domain validates act-bound predicates and a Finality Sink verifies authority before it becomes routing-, radiative-, storage-, control- or disclosure-effective. It provides many NTN enforcement profiles (orbital AI output, optical inter-satellite links, onboard gNB, maneuver/collision-avoidance, propulsion, sensing, decommissioning) and complements 3GPP NTN, IETF routing, DTN, RATS, ACE and SUIT rather than replacing them.
Addresses enterprise-AI systems connected to many organizational repositories, tools and memory systems, where a workload individually authorized to read several sources can combine them to reveal a sensitive relationship or future enterprise state no single repository contains. The mechanism separates not only protected data but also the authority to create protected semantic relationships among it, so access to components is not authority to join them, and completing a computation is not authority to make its consequence externally effective. A processing request establishes a bounded reconstruction authorization tied to workload, session, permitted fields, relationships and purpose, resolved inside a protected environment. It presents a large set of Enforcement Profiles and introduces Technical Non-Joinability as a separately enforceable property.
Defines the Session Recovery (SR) option for TCP, which lets connection endpoints exchange identifiers: during the handshake each endpoint carries its own identifier, and designated segments afterwards carry the peer's. This places knowledge of which endpoint a connection belongs to inside the TCP header, where on-path network functions such as load balancers, NAT gateways and firewalls can read it without per-flow state or payload inspection. The primary use is session recovery in SNAT and load-balancing clusters, with further uses in reduced-state forwarding, connection-tracking recovery and per-backend telemetry. It is carried in SYN, SYN-ACK and retransmitted segments (or all segments if configured) and adds no overhead to normal data by default.