IETF Internet-Drafts & RFCs — Daily Digest

Window: last 48 hours (2026-09-05 → 2026-09-07). Generated 2026-09-07 05:10 UTC. All working groups, 100% coverage from the i-d-announce / ietf-announce indexes.

58Drafts
0RFCs
11/58Official abstract

Newly published RFCs

No RFCs were published in this window.

Drafts

Monday, 07 September 2026 4 documents

By its name, this PIM working group document defines a YANG module extension for IGMP and MLD snooping, applied to L2VPN service contexts. It probably augments the existing snooping YANG models so that multicast group membership state can be managed and monitored for layer-2 VPN instances. Details are approximate pending grounding in the official Abstract.

draft-llz-bier-ipfix-bier-00 Individual new -00

By its name, an individual submission defining IPFIX (IP Flow Information Export) elements or templates for Bit Index Explicit Replication (BIER) traffic, likely so that BIER-forwarded multicast flows can be measured and exported for accounting and telemetry. This is a new -00 draft; the description is approximate and will be grounded in the Abstract on the next run.

draft-ietf-intarea-rfc8335bis-05 WG INTAREA rev -05 abstract

Describes PROBE, a network diagnostic tool similar to PING that queries the status of a probed interface. Unlike PING, PROBE does not require bidirectional connectivity between the probing and probed interfaces; instead it needs bidirectional connectivity between the probing interface and a proxy interface. The proxy interface can reside on the same node as the probed interface or on a directly connected node. This revision updates RFC 4884 and obsoletes RFC 8335.

draft-ietf-pim-flex-algo-01 WG PIM rev -01 abstract

PIM normally uses the shortest path computed by routing protocols to build the multicast tree. Multi-Topology Routing enables service differentiation within an IP network, and IGP Flex-Algorithm provides a way to compute constraint-based paths. This document defines PIM message extensions that allow a multicast tree to be built through a specific topology and along a constraint-based path instead of the default shortest path.

Sunday, 06 September 2026 28 documents

draft-howard-virp-07 Individual rev -07 abstract

Defines the Verified Infrastructure Response Protocol (VIRP), a cryptographic trust framework for agentic AI systems operating on live network infrastructure. As AI agents autonomously configure, audit, and remediate production systems, the lack of a verifiable chain of custody risks fabricated telemetry and unauthorized state changes. VIRP applies seven trust primitives covering observation integrity, intent separation, action authorization, outcome verification, baseline memory, multi-vendor normalization, and process containment. Observations are signed at collection time with Ed25519, a two-channel design separates read-only observation from write-intent, and trust tiers (GREEN/YELLOW/RED/BLACK) gate actions with human-in-the-loop controls. It reports a multi-vendor implementation tested against Cisco and FortiGate gear.

draft-bubblefish-npamp-02 Individual rev -02

An individual submission whose scope is not determinable from the name alone (NPAMP). The description will be grounded once the official Abstract can be read; treat this entry as a placeholder for now.

draft-bubblefish-naalp-01 Individual rev -01

An individual submission whose scope is not determinable from the name alone (NAALP). The description will be grounded once the official Abstract can be read; treat this entry as a placeholder for now.

draft-intra-handshake-fail-23 Individual rev -23

Titled 'Intra-handshake (aka Early) Attestation Considered Harmful' and associated with CVE-2026-33697 (CVSS 7.5) and further CVEs of up to an expected CVSS 9.8. The document argues that performing remote attestation inside the TLS handshake (attested TLS) is insecure, and appears to be backed by a formal proof of insecurity for key-broker-style intra-handshake attestation. Description from the title; the full Abstract will be grounded next run.

By its name, an individual submission concerning an 'agentic market' — likely a protocol or framework for autonomous AI agents to discover, negotiate, or transact in a marketplace setting. This is a new -00 draft; the description is approximate pending the official Abstract.

By its name, a 'decision profile' companion to the Cedulon work. It probably defines how decisions or policy outcomes are represented and constrained within the Cedulon framework. Details are approximate pending grounding in the official Abstract.

draft-reilly-rlt-genesis-02 Individual rev -02

Titled 'REM License Token (RLT) - Genesis Artifact.' The document appears to define the genesis (root) artifact of a REM License Token scheme, part of a broader set of Reilly drafts on machine/web permanence and licensing. Description from the title; the full Abstract will be grounded next run.

draft-dogru-cedulon-09 Individual rev -09

The core 'Cedulon' specification (an individual submission at revision -09). Its exact subject is not determinable from the name alone; the description will be grounded once the official Abstract can be read.

Titled 'Beyond Attestation: An Execution-Finality Architecture for Controlling Release and Limiting Unauthorized Extraction and Distillation of Sensitive OpenAI and Anthropic Claude Model Information.' Part of a family of Das drafts proposing an execution-finality layer; this one targets protecting frontier model information (OpenAI/Anthropic) from extraction and distillation. Description from the title; full Abstract grounded next run.

Part of the Schrock 'EP' (Evidence Policy) family for high-risk agent actions. By its name it defines an authorization evidence chain — a linked, verifiable record binding an agent's authority to the evidence justifying an action. Approximate pending the official Abstract.

The architecture document of the Schrock 'EP' (Evidence Policy) family, which addresses evidence-bound authorization and replay for high-risk autonomous agent actions. It likely lays out the components and trust model the other EP drafts build on. Approximate pending the official Abstract.

Part of the Schrock 'EP' (Evidence Policy) family. By its name it defines 'bounded capability receipts' — signed artifacts proving that an agent exercised a capability within explicitly bounded scope. Approximate pending grounding in the official Abstract.

draft-schrock-ep-quorum-04 Individual rev -04

Part of the Schrock 'EP' (Evidence Policy) family. By its name it introduces a quorum mechanism — requiring agreement among multiple parties or authorities before a high-risk agent action is authorized. Approximate pending the official Abstract.

draft-prz-lsr-ash-packets-01 Individual rev -01

By its name, an individual link-state routing (LSR) related submission dealing with 'ASH packets.' Its precise purpose is not determinable from the name alone; the description will be grounded once the official Abstract can be read.

Titled 'Beyond Attestation: An Execution-Finality Architecture for Controlling Release and Limiting Unauthorized Extraction and Distillation of Sensitive Frontier AI Model Information.' A RATS-scoped Das draft proposing an execution-finality architecture to prevent unauthorized extraction and distillation of sensitive frontier model information. Description from the title; full Abstract grounded next run.

By its name, an individual submission on 'agentic trust' with an 'AAE' component (possibly an agent authentication/authorization or attestation element). Approximate pending grounding in the official Abstract.

Network anomaly detection is challenging and depends on deep expertise in both the network technologies and the specific service. Novel programmatic, rule-based, and AI-based techniques promise better scalability while trying to preserve accuracy, but only if the process is well designed. This document describes a lifecycle process to iteratively improve detection accuracy, proposing three key stages together with a YANG model that specifies the metadata needed to collect evidence of anomalies, validate their relevance, and refine the detection systems over time.

Titled 'A Compromised AI Server Must Not Become a Map of the Enterprise: Non-Joinable Vaults and Output-Release Finality.' The document proposes limiting the blast radius of a compromised AI server through non-joinable vaults and an output-release finality control, so that model outputs cannot be leveraged to reconstruct enterprise structure. Description from the title; full Abstract grounded next run.

Titled 'Verifiable Telemetry Ledgers for Resource-Constrained Environments.' The document appears to define a scheme for recording telemetry in a verifiable, tamper-evident ledger suitable for constrained devices. Description from the title; the full Abstract will be grounded next run.

Titled 'RDAP Extension for Structured Reliability Assessment Metadata.' A REGEXT-area document defining an RDAP (Registration Data Access Protocol) extension that conveys structured metadata for assessing the reliability of registration data. Description from the title; full Abstract grounded next run.

By its name, a new -00 individual submission proposing a 'data truck' transport — likely a store-and-forward or bulk-carry mechanism for moving large data payloads across a network. Approximate pending the official Abstract.

draft-ek-dtn-ethernet-06 Individual rev -06 abstract

Describes a mechanism for carrying Delay- and Disruption-Tolerant Networking (DTN) Bundle Protocol (BP) bundles directly over Ethernet links (BP-over-Ethernet). It covers the transmission mechanism along with its limitations and operational considerations, and requests dedicated Ethernet parameters for the purpose. Later revisions frame this around a Bundle Transfer Protocol - Unidirectional (BTP-U) over Ethernet.

draft-ietf-quic-reliable-stream-reset-11 WG QUIC rev -11 abstract

QUIC's RESET_STREAM frame aborts sending on a stream and stops retransmitting its STREAM frames on loss, so the receiver has no guarantee that any data on that stream was delivered. This document defines a new QUIC frame, RESET_STREAM_AT, that resets a stream while still guaranteeing delivery of the stream's data up to a specified byte offset, giving applications a partial-delivery reset.

draft-ietf-ccwg-ratelimited-increase-11 WG CCWG rev -11 abstract

Specifies how transport protocols should increase their congestion window when the sender is rate-limited rather than congestion-limited. Such a limitation can arise because the sending application does not supply enough data, or because of receiver flow control. The document updates RFC 5681, RFC 9002, RFC 9260, and RFC 9438 to give consistent guidance across TCP, QUIC, and SCTP.

draft-ietf-bess-evpn-bfd-17 WG BESS rev -17

Description not available; it will be grounded from the official Abstract on the next run.

draft-ietf-netconf-distributed-notif-21 WG NETCONF rev -21 abstract

Describes extensions to YANG notification subscriptions that allow metrics to be published directly from processors on line cards to target receivers, while the subscription itself is still maintained at the route processor. This supports scalable telemetry in distributed forwarding systems where the central processor would otherwise be a bottleneck for high-volume notification streams.

By its name, a SCITT (Supply Chain Integrity, Transparency, and Trust) related document defining how a payload is bound into SCITT signed statements or transparency records. Approximate pending grounding in the official Abstract.

By its name, the 'Wathiqa' work on a post-quantum (PQC) Evidence Record Syntax (ERS) — likely long-term, quantum-resistant preservation of evidence records and their timestamps. Approximate pending the official Abstract.

Saturday, 05 September 2026 26 documents

An NFSv4 working group document that, by its name and its companion 'uncacheable files' work, adds an uncacheable attribute for directories to NFSv4.2. This lets a server mark directory contents as not cacheable by clients, forcing fresh reads where directory state changes frequently. Approximate pending the official Abstract.

draft-reilly-rmrp-01 Individual rev -01

An individual submission (RMRP) whose exact expansion is not determinable from the name alone; it sits within the broader Reilly set of drafts on machine/web resilience and permanence. Description grounded next run.

Titled 'Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems.' The document proposes a standardized, structured logging format so that the actions and decisions of autonomous AI agents can be recorded and audited consistently across systems. Description from the title; full Abstract grounded next run.

draft-dua-scsp-space-uri-00 Individual new -00

By its name, an individual submission defining a URI scheme or convention for 'SCSP space.' Its precise scope is not determinable from the name alone; description grounded next run.

By its name, an individual submission defining a 'testimony record' — probably a signed, structured attestation or statement format. Approximate pending grounding in the official Abstract.

Titled 'Secure and Privacy-Preserving AI Interoperability under Article 6(7) of the European Digital Markets Act: An Execution-Finality Architecture.' The document maps the Das execution-finality architecture onto the DMA's interoperability obligations, aiming for act-bound authorization of AI agent effectuation. Description from the title; full Abstract grounded next run.

draft-jennings-moq-discovery-02 Individual rev -02

By its name, a Media over QUIC (MoQ) discovery document — likely defining how MoQ publishers, subscribers, or relays discover one another or the tracks available. Approximate pending the official Abstract.

draft-das-agentic-tool-binding-03 Individual rev -03 abstract

Argues that frontier runtimes standardized a dangerous moment: when a model emits a tool_use block, the host immediately invokes whatever the model printed, with alignment, allowlists, and OAuth sitting around that moment but not on it. The risk extends into critical infrastructure such as energy grids, SCADA, and medical devices. It proposes binding an Agent Candidate Act profile to existing tool interfaces without model changes: a local enforcer holds blocks non-effective and refuses invoke() until scoped authority is verified at the dispatch boundary, enforcing fail-closed behavior for high-consequence operations and emitting a signed, hash-chained Ledger-Anchored Validation Receipt (LAVR).

draft-reilly-webproof-01 Individual rev -01

By its name, an individual submission on a 'web proof' — probably a verifiable proof about web content or its permanence/integrity, in line with the Reilly machine-web drafts. Description grounded next run.

draft-reilly-plpes-01 Individual rev -01

An individual submission (PLPES) whose expansion is not determinable from the name alone. Description grounded next run once the official Abstract can be read.

draft-sato-soos-pt-03 Individual rev -03

Part of the Sato 'SOOS' (Sovereign Object Systems) family for agentic AI. The 'PT' component's exact scope is not clear from the name; description grounded next run.

draft-sato-soos-faip-02 Individual rev -02

Titled 'The Federated Agent Intelligence Protocol (FAIP) for Agentic AI Systems,' part of the Sato SOOS family. It appears to define a protocol for federating intelligence or coordination across agentic AI systems. Description from the title; full Abstract grounded next run.

An ACME working group document titled 'JWTClaimConstraints profile of ACME Authority Token.' It defines a profile that applies JWTClaimConstraints to the ACME Authority Token challenge, constraining the claims a token may assert when authorizing certificate issuance. Description from the title; full Abstract grounded next run.

draft-gondwana-dkim2-authres-00 Individual new -00

By its name, part of the DKIM2 effort, defining Authentication-Results reporting for DKIM2. It likely specifies how DKIM2 verification outcomes are recorded in Authentication-Results header fields. Approximate pending the official Abstract.

draft-sato-soos-hem-07 Individual rev -07

Part of the Sato 'SOOS' (Sovereign Object Systems) family for agentic AI. The 'HEM' component's exact scope is not clear from the name; description grounded next run.

draft-sato-soos-peer-01 Individual rev -01

Part of the Sato 'SOOS' (Sovereign Object Systems) family for agentic AI, addressing peer relationships or peer-to-peer interaction among sovereign agent objects. Approximate pending the official Abstract.

draft-sato-soos-cap-rrs-03 Individual rev -03

Titled 'Constitutional AI Protocol -- Regulation Record Specification (CAP-RRS),' part of the Sato SOOS family. It specifies how regulation records are represented within the Constitutional AI Protocol. Description from the title; full Abstract grounded next run.

draft-sato-soos-cap-05 Individual rev -05

Titled 'The Constitutional AI Protocol (CAP) for Agentic AI Systems,' part of the Sato SOOS family. It appears to define a protocol for binding agentic AI systems to a declared 'constitution' of rules and constraints. Description from the title; full Abstract grounded next run.

By its name, a Das execution-finality document oriented to enforcement under the EU AI Act. It likely applies the execution-enforcement/finality approach to obligations arising from the EU AI Act. New -00 draft; approximate pending the official Abstract.

By its name, a Das execution-finality document applying execution-enforcement to global privacy requirements. It likely frames privacy obligations as act-bound, enforceable execution constraints. New -00 draft; approximate pending the official Abstract.

BGP Flow Specification (FlowSpec) distributes FlowSpec NLRI to clients to mitigate (distributed) denial-of-service attacks and to filter traffic within BGP/MPLS VPN services. With the rise of SRv6-based traffic steering, this document introduces the use of BGP FlowSpec to steer matching packets into an SRv6 Policy, extending FlowSpec beyond filtering toward SR-based forwarding.

draft-williams-intent-token-02 Individual rev -02 abstract

Specifies the Intent Token, a cryptographic authorization primitive for autonomous AI agent systems. An Intent Token binds an agent action to a cryptographically signed, human-declared authorization envelope before the action is executed. It addresses a gap in existing frameworks: OAuth 2.0, OIDC, and related standards govern identity and access at the session level, but no standardized primitive governs what an autonomous agent is authorized to DO at the moment of action. The Intent Token is model-agnostic, transport-agnostic, and composable with existing authorization infrastructure.

By its name, a SCITT (Supply Chain Integrity, Transparency, and Trust) related document about a 'framing space' — probably how statements are framed or scoped within SCITT transparency services. Approximate pending the official Abstract.

A DAWN-scoped document (Discovery of Agents, Workloads, and Named Entities) proposing an agent discovery framework. It likely defines how AI agents and workloads are discovered and resolved on the network. New -00 draft; description derived from the DAWN work and grounded next run.

By its name, an individual submission defining a VPN protocol called 'ZeroPath.' Its exact design goals are not determinable from the name alone; description grounded next run once the official Abstract can be read.

By its name, an NFSv4-related individual submission defining use of an X.509 otherName (subjectAltName) with RPC-with-TLS, likely to identify NFS peers by a dedicated name form during TLS authentication. Approximate pending the official Abstract.