IETF Internet-Drafts & RFCs — Daily Digest

All working groups · rolling 48-hour window · generated 2026-09-23 05:17 UTC · as of 2026-09-23

66 draft announcements 56 unique documents 0 newly published RFCs 20/56 unique drafts with official abstract Published: https://ietf-drafts-ok.pages.dev

Newly published RFCs

Drafts

2026-09-23 — 4 announcements

By its name this individual submission appears to define “claim boundaries” — likely the scoping or delimiting of claims (assertions/attestations) exchanged between parties, plausibly in an attestation, identity or agent-authorization context. The exact mechanism could not be confirmed without the official abstract this run.

By its title, this draft defines “Succession Receipts” — portable, signed evidence of authority succession between autonomous agents, i.e. verifiable records that authority was handed from one agent to another. Written from the document title; specifics are approximate pending its abstract.

By its name, an Agent Registry Protocol (ARPA) — probably a protocol for registering, publishing and discovering autonomous agents and their capabilities. Details are approximate pending the official abstract.

By its title (“BGP Neighbor Discovery”, formerly “BGP Neighbor Autodiscovery”), this IDR-area individual draft describes a mechanism for BGP speakers to automatically discover neighbours rather than relying on manual peer configuration. Written from the title; specifics approximate.

2026-09-22 — 27 announcements
draft-intra-handshake-fail-40 Individual rev -40

By its name this individual submission concerns handling of handshake failures. The unusually high revision numbers announced within a single window (‑37 through ‑40) suggest rapid successive resubmissions. Content could not be confirmed without the official abstract.

draft-intra-handshake-fail-39 Individual rev -39

By its name this individual submission concerns handling of handshake failures. The unusually high revision numbers announced within a single window (‑37 through ‑40) suggest rapid successive resubmissions. Content could not be confirmed without the official abstract.

Describes a zero-configuration protocol for dynamically assigning IPv6 multicast addresses. Applications pick multicast group IDs at random from a reserved range and avoid collisions by publishing records over Multicast DNS (mDNS) in a new “eth-addr.arpa” special-use domain. The goal is address assignment without a central allocator or manual configuration.

draft-dogru-cedulon-core-01 Individual rev -01

By its name and associated project material, the “Cedulon” core specification appears to define an audit layer for agent-to-agent commerce — signed trade manifests, a default-deny spend policy, COSE_Sign1 receipts and epoch checkpoints. Written from project naming; specifics approximate.

draft-ietf-openpgp-external-secrets-00 WG OPENPGP new -00 abstract

Defines a standard wire format for signalling that the secret component of an OpenPGP asymmetric key is stored externally rather than inside the OpenPGP key material itself — for example on a hardware security device or a comparable subsystem. This lets implementations reason about keys whose private half never leaves the external module. (Abstract reflects the adopted specification, previously published as draft-dkg-openpgp-external-secrets.)

draft-tt-netmod-yang-config-templates-04 Individual rev -04 abstract

NETCONF and RESTCONF give programmatic access to configuration data modelled in YANG. This document defines a YANG-based configuration-template mechanism in which configuration data is declared once in one or more templates and then applied repeatedly. This avoids redundant, identical configuration, improves consistency, and lets devices be managed more conveniently and efficiently.

By its title, “Workload Authorization Grant” — likely an OAuth-style authorization grant tailored to workloads (in the WIMSE/OAuth workload-identity space), letting a workload obtain access tokens. Details approximate pending the official abstract.

draft-salaheldin-bcnp-00 Individual new -00

A brand-new individual submission whose subject is not deducible from the acronym “BCNP” in the name alone. Its scope could not be determined without the official abstract this run.

By its name, this individual draft proposes reforms to the IETF/RFC document publication process. The specific changes proposed are approximate pending the official abstract.

By its name, a WIMSE-related draft; “connected flight” suggests a workload-identity use case in a connected-aviation or similar setting. Details approximate pending the official abstract.

By its name, this individual draft proposes reforms to the IETF/RFC document publication process. The specific changes proposed are approximate pending the official abstract.

Specifies a framework for mapping service-flow characteristics onto network “modal” resources in multi-modal intelligent computing networks. It uses the ALTO protocol for data collection and an SDN architecture to separate control and data planes, enabling dynamic resource allocation through flow characteristic identification, intelligent mapping and continuous optimization for scalable, efficient and secure operation under complex, diverse loads.

draft-ietf-bmwg-sr-bench-meth-09 WG BMWG rev -09 abstract

Defines a methodology for benchmarking Segment Routing (SR) performance, covering both Segment Routing over IPv6 (SRv6) and SR-MPLS. It builds on the existing benchmarking framework of RFC 2544, RFC 5180 and RFC 5695 together with the SR architecture of RFC 8402, giving a consistent way to measure SR data-plane behaviour.

Part of a series on “execution finality” — the principle that a command being accepted is not the same as it being actuated or settled — applied to agentic AI, payments and industrial control. This member appears to address deployment aspects. Written from the series naming; specifics approximate.

Describes current industry practices for issuing secure identities to workloads running in container orchestration systems, cloud platforms and other workload environments. It explains how workloads obtain credentials for authenticating to external systems without having to manage long-lived secrets directly, informing the WIMSE working group's wider identity work.

draft-ietf-avtcore-rtp-jpegxs-3ed-08 WG AVTCORE rev -08 abstract

Specifies an RTP payload format for transporting video encoded with JPEG XS (ISO/IEC 21122), a low-latency compression system with sub-frame encode/decode latency. This third-edition update to RFC 9134 adds support for features introduced in JPEG XS 3rd edition — notably the Temporal Differential Coding mode — while remaining backward compatible with existing RFC 9134 implementations and folding in previously reported errata.

draft-helmprotocol-deepspace-01 Individual rev -01

A brand-new individual submission in what appears to be a “Helm protocol” family; “deepspace” likely names a specific profile or component. Its scope could not be confirmed without the official abstract.

A brand-new individual submission in the apparent “Helm protocol” family, this one relating to a “confidence” aspect. Its scope could not be confirmed without the official abstract.

draft-helmprotocol-tttps-11 Individual rev -11

An individual submission in the apparent “Helm protocol” family; the “tttps” component is not deducible from the name alone. Its scope could not be confirmed without the official abstract.

draft-xu-idr-fare-in-sun-00 Individual new -00

By its name and sibling drafts (“Fully Adaptive Routing Ethernet in Scale-Up Networks”), this appears to describe BGP/IDR extensions for fully adaptive routing Ethernet (FARE) in scale-up (SUN) network fabrics. Written from the name; specifics approximate.

draft-ramakrishna-satp-data-sharing-06 Individual rev -06 abstract

As distributed-ledger (DLT) and blockchain systems are increasingly used for virtual assets, asset-related data and metadata need to cross system boundaries and link business workflows. This document describes how distributed systems can project asset “views” externally while protecting them with access controls, letting external parties address those views globally through gateway nodes using a DLT-neutral request/response protocol that respects each network's native consensus.

draft-ietf-rats-endorsements-11 WG RATS rev -11 abstract

In the IETF Remote Attestation Procedures (RATS) architecture a Verifier accepts Evidence and, using an Appraisal Policy plus Endorsements and Reference Values, produces Attestation Results for Relying Parties. This document explains the purpose and role of Endorsements and discusses considerations in choosing a message format for Endorsements within the RATS architecture.

draft-ramakrishna-satp-views-addresses-08 Individual rev -08 abstract

Defines views and view addresses for secure asset transfer across DLT systems. A view denotes complete or partial asset state, or the output of a computed function; systems must guard views with access-control policies while external parties must independently verify authenticity, finality and freshness. The end-to-end protocol is DLT-neutral and masks interior system complexity, with view generation and verification obeying each system's native consensus logic.

draft-ietf-idr-performance-routing-07 WG IDR rev -07 abstract

The current BGP specification does not use network performance metrics such as latency in route selection. This document describes a performance-based BGP routing mechanism that takes a network latency metric as one of the route-selection criteria, aimed at global-reach service providers who want to deliver low-latency connectivity services to their customers.

By its name, a LAMPS-area post-quantum “composite” scheme using FrodoKEM — likely composite KEM/algorithm identifiers combining FrodoKEM with a classical algorithm for X.509/CMS use. Written from the name; specifics approximate.

By its title (“RDAP Extension for Structured Reliability Assessment Metadata”), this REGEXT-area individual draft defines an RDAP extension for conveying structured reliability-scoring metadata in responses. Written from the title; specifics approximate.

A brand-new WIMSE-related individual submission; by its name it appears to concern the evaluation of workload-identity approaches. Its scope could not be confirmed without the official abstract.

2026-09-21 — 35 announcements

By its name, a WIMSE-related draft covering the delegation aspects of an “SADP” (Secure Agent Delegation Protocol, by its acronym). Details approximate pending the official abstract.

draft-atakora-sadp-protocol-02 Individual rev -02

By its name, the “SADP” protocol specification — apparently a Secure Agent Delegation Protocol (by its acronym). Multiple early revisions were announced together. Details approximate pending the official abstract.

draft-atakora-sadp-protocol-01 Individual rev -01

By its name, the “SADP” protocol specification — apparently a Secure Agent Delegation Protocol (by its acronym). Multiple early revisions were announced together. Details approximate pending the official abstract.

A brand-new individual submission whose “ZTDS” protocol subject is not deducible from the acronym in the name alone. Its scope could not be confirmed without the official abstract.

By its name, a WIMSE-related draft covering the delegation aspects of an “SADP” (Secure Agent Delegation Protocol, by its acronym). Details approximate pending the official abstract.

draft-atakora-sadp-protocol-00 Individual new -00

By its name, the “SADP” protocol specification — apparently a Secure Agent Delegation Protocol (by its acronym). Multiple early revisions were announced together. Details approximate pending the official abstract.

draft-ietf-plants-merkle-tree-certs-06 WG PLANTS rev -06 abstract

Describes Merkle Tree certificates, a new form of X.509 certificate that integrates public logging of the certificate in the style of Certificate Transparency. The integrated design reduces logging overhead for both short-lived certificates and large post-quantum signatures while keeping comparable security to traditional X.509 plus CT. An optional size optimization can avoid signatures entirely, at the cost of only applying to up-to-date relying parties.

By its name, an Agent Registry Protocol (ARPA) — probably a protocol for registering, publishing and discovering autonomous agents and their capabilities. Details are approximate pending the official abstract.

A brand-new individual submission stating requirements for “ADKM” (by its acronym). The precise subject could not be confirmed without the official abstract; see the companion problem-statement draft.

By its name, this draft defines “compliance receipts” in an “ASQAV” context — likely signed, verifiable receipts attesting compliance (in an agent/audit setting). Written from the name; specifics approximate.

draft-garg-change-ext-01 Individual rev -01

By its name, an extension (“-ext”) to a “change” mechanism defined in the companion draft-garg-change. Its precise scope could not be confirmed without the official abstract.

draft-garg-change-01 Individual rev -01

A brand-new individual submission named simply “change”; its subject is not deducible from the name alone and could not be confirmed without the official abstract.

Describes postcard-based on-path telemetry with packet marking (PBT-M) using an MPLS Network Actions (MNA) flag to support OAM in MPLS networks. A single bit in the MNA header opcode is dedicated to the flag-based action, and the document gives solutions for applying PBT-M in MPLS networks. (Abstract reflects the specification as published in the individual draft-song-mpls-on-path-telemetry-flag version.)

draft-lcurley-moq-cluster-01 Individual rev -01

By its name, a Media over QUIC (MoQ) draft addressing “cluster” operation — likely clustering or relaying of MoQ nodes. Written from the name; specifics approximate.

A brand-new WIMSE-related individual submission; by its name it defines an “agent audit record” format for recording/auditing actions taken by agents. Details approximate pending the official abstract.

A newly adopted GROW working-group draft; by its title (previously draft-spaghetti-grow-downgrade-bgp-community) it defines a well-known “DOWNGRADE” BGP community. Written from the title; specifics approximate pending the official abstract.

Part of a series on “execution finality” — the principle that a command being accepted is not the same as it being actuated or settled — applied to agentic AI, payments and industrial control. This member appears to address deployment aspects. Written from the series naming; specifics approximate.

By its name, an rtgwg-area individual draft on inter-domain “EBR” routing. The precise expansion of “EBR” and the mechanism could not be confirmed without the official abstract.

draft-ietf-emu-pqc-eap-tls-01 WG EMU rev -01 abstract

Proposes enhancements to EAP-TLS and EAP Tunneled TLS (EAP-TTLS) to incorporate post-quantum cryptographic mechanisms. It addresses the challenges of large certificate sizes and long certificate chains identified in RFC 9191 and gives recommendations for integrating PQC algorithms into EAP-TLS and EAP-TTLS deployments. (Abstract reflects the adopted specification, previously published as draft-reddy-emu-pqc-eap-tls.)

draft-intra-handshake-fail-38 Individual rev -38

By its name this individual submission concerns handling of handshake failures. The unusually high revision numbers announced within a single window (‑37 through ‑40) suggest rapid successive resubmissions. Content could not be confirmed without the official abstract.

draft-intra-handshake-fail-37 Individual rev -37

By its name this individual submission concerns handling of handshake failures. The unusually high revision numbers announced within a single window (‑37 through ‑40) suggest rapid successive resubmissions. Content could not be confirmed without the official abstract.

draft-liu-add-dnssd-edns-04 Individual rev -04 abstract

Defines an mDNS and DNS-Based Service Discovery (DNS-SD) mechanism for discovering encrypted DNS services on local networks. It specifies new service types (_dot, _doh, _doq) and associated TXT record parameters to enable zero-configuration discovery of DNS over TLS, DNS over HTTPS and DNS over QUIC resolvers, addressing local-network privacy gaps while staying backward compatible with RFC 6763.

draft-camarillo-rtgwg-lsn-01 Individual rev -01 abstract

Defines the Lightspeed Notification Protocol (LSN), a hardware-accelerated signalling mechanism for sub-100-microsecond network convergence in AI/ML data-center fabrics. LSN operates within the forwarding plane to signal link failures and congestion using efficient hardware encoding, complementing routing protocols such as BGP by providing immediate hardware-based path pruning while preserving control-plane stability.

draft-filsfils-srv6ops-srv6-ai-backend-05 Individual rev -05 abstract

Describes the use of SRv6 to enable deterministic path placement in AI back-end fabrics, optimizing load balancing and congestion control for predictable GPU workloads. The aim is tighter, more predictable path control in the high-bandwidth interconnects behind AI/ML training and inference clusters.

draft-he-idr-bgp-ec-sr-pm-01 Individual rev -01

By its name, an IDR-area individual draft defining a BGP Extended Community (“ec”) for Segment Routing performance measurement (“sr-pm”). Written from the name; specifics approximate.

draft-goto-otp-token-01 Individual rev -01

By its name, this individual submission defines an OTP (one-time password) token mechanism. Its exact scope could not be confirmed without the official abstract.

By its name, a reference architecture (“refarch”) for “agent accountability” — a framework for holding autonomous agents accountable for their actions. Written from the name; specifics approximate.

By its name and associated list discussion, this individual draft proposes a DKIM2 (and DMARC-related) sender-policy mechanism. Written from the name/subject; specifics approximate pending the official abstract.

draft-liu-fann-srv6-cc-01 Individual rev -01 abstract

Describes a congestion-control solution based on SRv6. It defines mechanisms for congestion notification and flow control within an SRv6-based network, optimizing congestion handling through hierarchical congestion-control messages carried along SRv6 paths.

By its title (“Source-IP-Origin-AS Filter for BGP Flow Specification”), a companion to the destination-IP variant: it adds a BGP-FS component type that matches on the origin AS number of the source IP address. Written from the title; specifics approximate.

By its name, a CATS (Computing-Aware Traffic Steering) individual draft defining a client request-packet mechanism. Written from the name; specifics approximate pending the official abstract.

A brand-new individual submission giving a problem statement for “ADKM” (by its acronym), companion to the requirements draft. The precise subject could not be confirmed without the official abstract.

By its title, this draft defines “Succession Receipts” — portable, signed evidence of authority succession between autonomous agents, i.e. verifiable records that authority was handed from one agent to another. Written from the document title; specifics are approximate pending its abstract.

draft-ietf-ccamp-flexe-yang-cm-10 WG CCAMP rev -10 abstract

Defines a service-provider-oriented YANG data model for configuring and managing a Flex Ethernet (FlexE) network, including the FlexE group and FlexE client. The YANG module conforms to the Network Management Datastore Architecture (NMDA).

The BGP Flow Specification mechanism (BGP-FS) propagates traffic flow specifications and filtering actions using BGP NLRI and Extended Community encodings. This document specifies a new BGP-FS component type for AS-level filtering: the match field is the origin AS number of the destination IP address encoded in the Flowspec NLRI. The function is applied within a single administrative domain.