IETF — drafts and RFCs
Last 48 h · window 2026-08-14 → 2026-08-16 (UTC) · source: mailarchive indexes i-d-announce / ietf-announce
Newly published RFCs
2026-08-14
Network Time Protocol (NTP) over the Precision Time Protocol (PTP)
Defines how to carry Network Time Protocol (NTP) messages over a Precision Time Protocol (PTP, IEEE 1588) infrastructure. It lets networks that already deploy PTP — common in telecom, finance and industry — also serve NTP synchronization by reusing the same timing plane. It describes the encapsulation, the mapping between the clock models of both protocols, and the accuracy and security considerations when crossing the two worlds. The goal is interoperability and avoiding the need to run two separate timing infrastructures.
Media Access Control (MAC) Addresses in X.509 Certificates
Specifies how to include MAC addresses (IEEE 802) as an identity inside X.509 certificates, defining the name type and its encoding in the subjectAltName. It is used to authenticate devices by their hardware address in network-access scenarios (for example 802.1AR/DevID or IoT). It details the format, the textual representation and the matching rules, as well as the privacy implications of exposing a MAC address inside a long-lived credential.
Multiple Loss Ratio Search
Defines MLRsearch (Multiple Loss Ratio search), a performance measurement methodology that finds the throughput of a device or network by searching for several loss ratios simultaneously. It improves on the classic binary-search method of RFC 2544 by greatly reducing test time and producing more repeatable results. It describes the algorithm, the stopping criteria and how to report rates for different loss thresholds. It underpins data-plane benchmarking test beds such as those of FD.io/TRex.
Drafts
2026-08-16 · 13 drafts
Specifies (Informational) how independently-verifiable accountability profiles for autonomous agents compose via a shared action-digest, so a regulator, auditor or counterparty who does not trust the operator can answer: was the agent permitted to act (CAN), which accountable human authorized the specific action (WHO), what it actually did (WHAT), and did the runtime enforce correctly (AUDIT). It defines a shared conformance-vector suite any profile can be tested against and reuses existing signing, transport and transparency mechanisms. Its focus is an assurance tier above today's self-attested records: an anchored, third-party-verifiable record registered to a SCITT transparency service, verifiable by a party who trusts neither agent nor operator.
Updates RFC 9970. The baseline PASSporT of RFC 8224 does not bind the SIP request method, CSeq, Call-ID or dialog tags, so a valid PASSporT can stay valid when a signed in-dialog request is transformed into a different SIP request whose authenticated identity fields are unchanged. This document defines the 'sipctx' PASSporT type, which binds the SIP method and dialog/sequence context to the PASSporT, so implementations relying on PASSporT validation can authenticate mid-dialog requests.
Specifies a format for action receipts: compact, individually signed JSON records stating that a specific AI agent attempted a specific action at a specific time, under a specific policy decision, and what the outcome was. Receipts are linked into an append-only hash chain so deletion, insertion, reordering or modification is detectable by a verifier holding only the records and the signer's public key. Verification needs no network access and no producer-run service — just the records and an out-of-band trust anchor. It defines the record fields, the signed canonical bytes, the chain-linkage rule, the verification procedure and test vectors.
Specifies the FAF Agent Format (.fafa): a declarative, YAML-based format that describes an agent's identity, the capabilities it exposes and the endpoints through which it is reached (it describes an agent, it never instructs one). Registered in the IANA vendor tree (application/vnd.fafa+yaml, June 2026), it is the agent member of the FAF family alongside .faf (project context) and .fafm (agent memory). It acts as a portable 'passport' answering four questions: who the agent is, what it may do, where it is reached and what it must never do. It complements, rather than replaces, protocol-native cards (A2A Agent Cards, MCP Server Cards) and repo files like AGENTS.md, as a house-neutral source of truth.
Individual proposal on AI governance. It raises considerations, terminology or mechanisms to govern the behavior of artificial-intelligence systems in the context of Internet protocols. It aligns with the IETF's growing interest in control, auditability and accountability of AI-based agents and services.
Work of the IPPM (performance metrics) working group on version 2, encrypted, of the IPv6 Performance and Diagnostic Metrics (PDM) Destination Option. PDM inserts metrics (sequences and timestamps) into the extension header for fine-grained diagnosis of latency and loss. This revision adds encryption to protect that telemetry from on-path observers, balancing diagnostics and privacy. It is an advanced revision (-16), close to maturity.
Audit receipts for automated data access attest to what a gateway recorded but leave two gaps: what was changed in the data before disclosure, and whether the receipt set is complete against the source's own accounting. This draft defines two evidence structures — Transformation Evidence (a per-disclosure statement of which classes of values were transformed and how, carrying counts and class names but never values) and Coverage Reconciliation (comparing a source's own activity counters against a receipt set over a window and reporting activity with no receipt). Both are registerable as SCITT Signed Statements; it defines only the evidence payloads.
Defines an Extended CONNECT protocol for relaying UDP between two clients authenticated by the same proxy. A Listener registers with the proxy and a Client uses the resulting Rendezvous ID to connect to it; no public UDP address is allocated. This enables peer-to-peer UDP connectivity through a MASQUE proxy without exposing a public endpoint.
Specifies the Erik Synchronization Protocol for RPKI: a data-replication system using Merkle trees, a content-addressable naming scheme, concurrency control via monotonically increasing sequence numbers, and HTTP transport. It talks to 'Erik Relays', a new intermediary layer between the Repository Publication Point and Relying Parties that improves scalability. Relying Parties can combine Erik-synchronized data with other RPKI transport protocols. The design aims to be efficient, fast, easy to implement and robust against network partitions or faults.
Defines ba64, a text encoding for binary data that is never larger than standard base64. The encoder races DEFLATE compression against plain base64 and emits whichever result is shorter; compressed output is marked by a leading '=' (inside the base64 alphabet but never a valid start), so the two forms are unambiguous. A CRC-32 over the decoded bytes ensures a ba64 decoder never silently returns wrong data. The plain form is byte-identical to base64, so ba64 is a drop-in replacement wherever base64 is read today, with an optional padding method to decouple output length from input compressibility.
Defines implementation-neutral requirements for persistent node identity, declared state and governed lifecycle in 'Web4-class' federations. It covers admission, suspension, revocation, re-admission and succession of nodes, so that a federation can manage which nodes belong, in what state, and how they are removed or replaced. It stays neutral about implementation, specifying the requirements rather than a concrete protocol.
Defines a SCITT profile for Physical-Site Engagement Receipts (PSER): tamper-evident, signed, offline-verifiable COSE records describing an autonomous or human-directed physical engagement at a specific real-world site under a defined operating envelope, using a five-artifact vocabulary (Site; Operator/Actor; Engagement Window/Envelope; TEE attestation evidence; Adapter Write-In). Each is a SCITT Signed Statement registerable in any Transparency Service. It makes a deliberately narrow, checkable claim — that a specific engagement occurred at a specific site under a specific envelope, sealed by a specific TEE — and rests on a three-party trust model (site owner, TEE silicon vendor, issuer) that implementations must not collapse.
QUIC endpoints commonly use 1200-byte datagrams during the handshake and only start Path MTU Discovery afterward, so freshly established connections cannot immediately use larger datagrams — especially limiting for MASQUE and WebTransport. This document defines Parallel Probing DPLPMTUD (PPDPLPMTUD), which probes several packet sizes early during the QUIC handshake so a larger discovered size is usable in later handshake phases and especially after completion. The same discovery process is also used for path migration.
2026-08-15 · 15 drafts
Provides technical evidence (tied to CVE-2026-33697 / EUVD-2026-16488) of how intra-handshake attestation fails in practice, even without physical access, and argues that since continuous attestation is generally required anyway, intra-handshake attestation adds unnecessary complexity. The results are backed by ProVerif models and artifacts released under Apache-2.0 for reproducibility, and have been acknowledged by the relevant stakeholders.
Defines a quantum network architecture: a set of planes giving different views of the network with different responsibilities and modes of operation; a set of device, node and link types; some topologies, deployment scenarios and their relationship to applications; and the key design decisions that result from the corresponding requirements. Research-group work laying conceptual foundations for a future quantum Internet.
Audit receipts for automated data access attest to what a gateway recorded but leave two gaps: what was changed in the data before disclosure, and whether the receipt set is complete against the source's own accounting. This draft defines two evidence structures — Transformation Evidence (a per-disclosure statement of which classes of values were transformed and how, carrying counts and class names but never values) and Coverage Reconciliation (comparing a source's own activity counters against a receipt set over a window and reporting activity with no receipt). Both are registerable as SCITT Signed Statements; it defines only the evidence payloads.
Audit receipts for automated data access attest to what a gateway recorded but leave two gaps: what was changed in the data before disclosure, and whether the receipt set is complete against the source's own accounting. This draft defines two evidence structures — Transformation Evidence (a per-disclosure statement of which classes of values were transformed and how, carrying counts and class names but never values) and Coverage Reconciliation (comparing a source's own activity counters against a receipt set over a window and reporting activity with no receipt). Both are registerable as SCITT Signed Statements; it defines only the evidence payloads.
Covers using BFD (Bidirectional Forwarding Detection) to detect MPLS LSP data-plane failures. LSP Ping can detect failures and verify the data plane against the control plane; BFD does the former with much lighter control-plane processing, so a combination of LSP Ping and BFD gives faster detection and/or covers more LSPs. The document describes BFD's applicability relative to LSP Ping and the procedures for using it in this environment. It obsoletes RFC 5884 and RFC 7726.
Defines 'action_ref', a deterministic, content-addressed identifier for autonomous-agent actions. Any party holding the four preimage fields (agent_id, action_type, scope, timestamp) can independently compute and verify the identifier without trusting the emitting system. It specifies the derivation algorithm, canonical serialization via RFC 8785 JSON Canonicalization Scheme (JCS), timestamp requirements, a canonical receipt envelope, optional fields for revocation and policy-rotation auditability, scope conventions, and how it composes with existing exactly-once execution guarantees.
Proposes a DID-based framework for service discovery, authentication and authorization of MCP (Model Context Protocol) agents, based on the W3C Decentralized Identifier standard. It uses the did:web and did:key methods to give verifiable, decentralized identifiers to MCP clients and servers, and defines DID method selection, DID Document extensions, service-discovery mechanisms (URL derivation, DNS-based, directory-based capability queries) and a challenge-response mutual-authentication protocol. It also describes coexistence with OAuth 2.0 and enables trust establishment, dynamic capability-based discovery and fine-grained authorization with portable identities.
Without out-of-band knowledge, a QUIC endpoint knows nothing about its network situation — neither its external IP address and port nor whether it is directly connected to the Internet or behind a NAT. This QUIC extension lets nodes determine their reflexive IP address and port for any QUIC path, useful for NAT traversal and peer-to-peer connectivity.
Defines metadata tags for describing aspects of Contra, Square and other traditional called folk dances. The tags are aimed at archivists as well as at present-day callers of traditional dances, giving a common vocabulary to catalog and describe dance material. A niche, non-networking individual draft.
Profiles the enforcement of OASNT tokens at the point of execution. It defines the OASNT-Token HTTP field, the rules by which an enforcement point derives the observed request from the octets it forwards, a verification procedure for relying parties that hold no request-to-action mapping, uniform refusal behavior, and the refusals a conforming enforcement point must produce. It adds an optional 'grp' claim and an exclusivity ledger so that tokens from one human confirmation are spendable only once between them. The result makes a human approval a precondition of execution without changing the protected service.
Defines the OASNT token, a compact JWS-based credential in which a hardware-bound device key attests that a specific human, on a device whose runtime integrity was assessed, authorized one specific action. The human-readable disclosure of that action is cryptographically bound to the token, implementing 'What You See Is What You Sign' (WYSIWYS). Tokens are single-use, short-lived, and may additionally be bound to one concrete HTTP request, strongly tying a human's approval to exactly what gets executed.
Defines an Entity Attestation Token (EAT) profile and a new EAT claim that convey the subject public key and its protection properties within attestation evidence. Combined with protocol-level proof of possession, this establishes a cryptographic binding between a private key and an attested execution environment. The subject key uses the EAT 'cnf' claim (RFC 8747/7800) and freshness the 'eat_nonce' claim (RFC 9711); because the EAT is signed by a hardware-backed Attestation Key, verifying its signature plus proof of possession binds the key to the attested platform state, addressing key-substitution attacks when attestation evidence and certificate keys are validated independently.
Defines requirements for establishing sessions between entities and for negotiating capabilities within such sessions, assuming the entities already know of each other (how they met is out of scope) and that at least one party is an agent. It is intended as a contribution to the agentproto working group's use-cases, gap-analysis and requirements deliverable.
Autonomous agents increasingly initiate payments on behalf of principals, but existing mechanisms authenticate the human, the operator or possession of a key — none establishes that the software authorized to spend is the software that was reviewed. This draft defines a payment-authorization scope bound to a key whose protection properties are hardware-attested, registered as a Signed Statement on a SCITT Transparency Service. It reuses the EAT confirmation and key-attributes claims and contributes the authorization scope, the executor's pre-settlement verification procedure, an auditable transparency record, and an execution-record mechanism auditable on challenge.
Profiles the IETF SCITT architecture for AI-agent action receipts: tamper-evident, signed, offline-verifiable records of what an autonomous agent was recorded doing at the governed boundary, under which recorded principal class, with what verdict and (where recorded) policy identity. Each receipt is a signed canonical-JSON record, hash-chained, presented bare or in a COSE_Sign1. This revision specifies carrying it as a SCITT Signed Statement so it can be registered, obtaining the log's signed proof of registration (which a self-signed chain cannot give); it notes registration alone does not provide offline non-equivocation. It keeps a deliberately narrow claim and separates 'an approver authorized this exact action', 'a downstream controller succeeded' and 'a physical effect occurred' as distinct claims.
2026-08-14 · 36 drafts
Describes GAAP (pronounced 'gap'), a lightweight decentralized multicast group-address allocation protocol. The base protocol requires no centralized service and minimal configuration (deployments using encryption or administrative scoping may need some), running among group participants that need a unique group address to send and receive multicast packets. Tailored for IPv4 and IPv6, it offers a simple, lightweight option rather than extending an existing protocol.
Defines how MOQT (Media over QUIC Transport) clients discover server endpoints using DNS and Multicast DNS (mDNS). It specifies SVCB and HTTPS DNS record mappings for the 'moqt' URI scheme, SRV records as a fallback mechanism, and DNS-SD over mDNS for local-network discovery.
Defines a YANG data model for configuring and managing BGP — including protocol, policy and operational aspects such as the RIB — based on data-center, carrier and content-provider operational requirements. It provides a standardized, programmatic representation of BGP for NETCONF/RESTCONF-based network automation.
Specifies the State Graph Cryptographic Protocol (SGCP), a communication-security framework in which client and server establish a protected session and keep a synchronized 'state graph' for its whole lifetime. It combines device identity, port/socket context, session identity, ECDH shared-secret establishment, key derivation, epochs, packet sequence numbers, authenticated state transitions, state-dependent packet transformation, replay protection, continuous context verification, controlled reauthentication and session recovery. The core idea: both endpoints independently derive the same cryptographic state from a common authenticated secret and deterministic state info, with the graph defining valid states and permitted transitions. It includes a worked full-duplex binary file-transfer example.
Presents a MANET internetworking problem statement and gap analysis. Building on RFC 2501's definition of a MANET as an autonomous system of mobile nodes that may operate in isolation or interface with a fixed network (such as the global Internet), it identifies what is missing in current protocols to integrate mobile ad hoc networks with the fixed Internet.
Specifies Ceramic Immutable Storage (CIS), a write-once archival format in which data is impressed into plastic clay by a pin-configurable roller, made permanent by kiln firing, and kept on a shelved rack. It is motivated by data loss to an authenticated software process acting outside its operator's intent: since every 'immutable' tier is immutable by policy (enforced by software that can be overridden), CIS relocates immutability from policy to physics — the commit is an irreversible mineralogical phase change with no inverse. It defines the substrate, encoding geometry, frame format, forward error correction, the firing profile that constitutes commit, rack addressing and the optical read path (and, at length, the costs). Effectively a pointed thought-experiment draft.
Describes Verifiable Distributed Aggregation Functions (VDAFs), a family of multi-party protocols for computing aggregate statistics over user measurements. As long as at least one aggregation server is honest, individual measurements are never seen in the clear by any server, while the servers can still detect if a malicious or misconfigured client submitted an invalid measurement. It specifies two concrete VDAFs — Prio3 (general-purpose aggregation) and Poplar1 (heavy hitters). A product of the IRTF Crypto Forum Research Group (CFRG).
Defines an Extensible Provisioning Protocol (EPP) mapping for retrieving a registrar's account balance and other financial information from a domain registry.
RFC 9068 recommends that a JWT access token's group/role/entitlement claims be drawn from the SCIM user schema but does not say where the authorization server obtains them — today from a directory, database or vendor hook, i.e. an authorization question asked of something that is not the authorization system. This draft profiles the OpenID AuthZEN Resource Search API for that purpose: it binds each authorization claim to a search, defines how a result set becomes a claim value, and requires that a search result never influence whether a token is issued or what authority it conveys.
Revision (bis) in the DNSOP working group of RFC 9364, the umbrella document for DNSSEC (DNS Security Extensions). It updates and consolidates the DNSSEC reference, incorporating clarifications and operational experience. WG revision -01.
Individual proposal related to MKA (MACsec Key Agreement) and 'stems'. It would cover a mechanism associated with MACsec key management (802.1X/802.1AE). Advanced revision (-12). The detail is in the document.
Proposal in the DNSOP space on the handling of RRSIG when the response is REFUSED. It addresses how resolvers and signers behave regarding DNSSEC signature records in refusal scenarios, improving robustness and diagnostics. Initial draft.
Scenario and gap analysis for gateways in a DMSC context. It enumerates use cases and what is missing in current protocols to support them. Revision -04. It fits work on multi-cloud/distributed-service connectivity.
Proposal on authentication of ADS-B, the aviation surveillance system that broadcasts aircraft positions. ADS-B lacks native authentication; this document proposes adding mechanisms to verify the origin of those messages and mitigate spoofing. Revision -02.
TACACS+ extension for SSH public keys. It would let SSH public-key authentication be managed and authorized through the TACACS+ AAA service, common in network-device administration. Initial draft.
Integrates ML-DSA (the lattice-based post-quantum signature scheme, formerly Dilithium, FIPS 204) into the SSH protocol. It defines how to use ML-DSA for host and user authentication in SSH, preparing the protocol against the quantum threat. Revision -07, fairly consolidated work.
Proposes using ML-DSA (post-quantum signature) with MTL (Merkle Tree Ladder) trees in DNSSEC. It seeks viable post-quantum signatures in DNS, where signature size is critical; MTL helps amortize that cost. It fits DNSSEC's migration to quantum-resistant cryptography. Revision -01.
Work of the LSR working group on a flooding-reduction architecture in link-state protocols (IS-IS/OSPF). In highly meshed topologies, flooding of LSAs/LSPs is redundant and costly; this document defines an architecture to reduce it while preserving convergence. Revision -03.
Work of the V6OPS working group on the use of the NAT64 well-known prefix with RFC 1918 private addresses. It clarifies and gives operational guidance for NAT64 behavior when IPv4 private addresses are involved, avoiding ambiguities and failures. Advanced revision (-07).
Work of the LAMPS working group on post-quantum composite KEMs: it combines a post-quantum key-encapsulation mechanism (e.g. ML-KEM) with a traditional one into a single hybrid construction. That way, security holds if at least one of the two resists. It defines its use in X.509/CMS. Advanced revision (-19).
Work of the CELLAR working group (which standardizes Matroska/FFV1) on a codec specification. It formally documents the format for audiovisual preservation and interoperability. Advanced revision (-20), reflecting mature specification work.
In the NOA framework (related to agent actions), defines settlement evidence. It provides verifiable proof that a settlement or closing of a transaction between agents has occurred. Part of the set of drafts on autonomous-agent traceability.
In the NOA framework, defines an action digest: a compact, verifiable fingerprint of an agent's action. It allows referencing and integrating the action into audit records without exposing its full content. It complements the NOA evidence drafts.
In the NOA framework (related to agent actions), defines settlement evidence. It provides verifiable proof that a settlement or closing of a transaction between agents has occurred. Part of the set of drafts on autonomous-agent traceability.
In the NOA framework, defines an action digest: a compact, verifiable fingerprint of an agent's action. It allows referencing and integrating the action into audit records without exposing its full content. It complements the NOA evidence drafts.
In the IOTOPS area, analyzes the use of QUIC in IoT environments. It studies the benefits (fast connections, mobility, encryption) and the challenges (power, memory, footprint) of QUIC on constrained devices, and gives guidance for its application. Initial draft.
Collects requirements for intent-based routing in a DMSC context. It defines what a system that translates high-level intents into routing decisions must satisfy. Initial draft that lays groundwork for later work.
Proposal in OAuth on scope aggregation. It addresses how to combine or consolidate multiple authorization scopes coherently when a client needs permissions from several sources, improving management of complex authorizations. Revision -01.
Specifies PQ-SecChannel, a secure interactive channel made of a Transport Authentication Protocol and a Connection Protocol, providing confidentiality, integrity and mutual authentication against quantum threats. It incorporates standardized post-quantum algorithms — lattice-based KEMs and signatures (e.g. Kyber/Dilithium), Chinese PQ candidates (e.g. Aigis) and code-based KEMs (e.g. HQC) — together with SM4-GCM for AEAD and SM3 for hashing/key derivation. It is derived from a Chinese national cryptography standard draft, adapted to IETF Internet-Draft style for international review, and references the Secure Shell architecture.
Specifies PQ-SecTunnel, a UDP-based, quantum-resistant IP tunnel derived from the WireGuard architecture. Session keys come from a three-message Noise_IKpsk1kem handshake that replaces Diffie-Hellman with dual KEM operations (static and ephemeral); authentication is implicit, peers proving possession of long-term KEM private keys through interlocking encapsulations rather than signing the transcript. It is a multi-suite framework: implementations may pick ML-KEM-512 or ML-KEM-768 per role, with the recommended profile static=ML-KEM-512, ephemeral=ML-KEM-768, AEAD=SM4-GCM, Hash=SM3.
WebSocket extension relating to PMCE (Per-Message Compression Extensions) for state reset. It would allow resetting the per-message compression context, useful for memory control or recovery. Initial draft.
Specifies the Attestation Reconciliation Protocol (ARP), a deterministic, bilateral, minimum-disclosure mechanism to reconcile verification claims against multiple sovereign registers without raw register records leaving their jurisdiction. It extends SCITT to cross-sovereign reconciliation: a server canonicalizes a claim, binds the requester's identity (including a friend-or-foe check when the requester is an autonomous agent), projects the claim through register-specific functions, and aggregates partial attestations — which disclose only a verdict, an optional divergence axis and query binding — under a policy-defined 'verdict arithmetic', committing each contribution to a Merkle tree. An append-only cross-jurisdictional ledger records only digests and metadata. This revision adds a binding to the SCITT Reference APIs, register profiles (beneficial-ownership, corporate registry, customs, sanctions) and a post-quantum upgrade path.
Proposal on agent proxy modes. It defines different ways in which a proxy mediates AI-agent communication (for example transparent, inspecting or transforming), with their implications. Initial draft.
In the IOTOPS area, a security specification for Modbus over serial link. Serial Modbus lacks native security; the document defines mechanisms to authenticate and integrate protection into legacy industrial (OT/ICS) deployments. Advanced revision (-07).
Proposal in the IDR area on SR Policy (Segment Routing Policy) templates in BGP. It would allow defining Segment Routing policies in a parameterized, reusable way via templates, simplifying provisioning at scale. Advanced revision (-08).
Work of the AVTCORE working group to carry 'green' metadata (Green Metadata, from MPEG, for energy efficiency in decoding) via RTCP. It allows signaling information that helps reduce the receiver's power consumption in real-time video sessions. Advanced revision (-16).