IETF Internet-Drafts & RFCs — Daily Digest

Window: last 48 hours (2026-08-24 to 2026-08-26 UTC) · Generated 2026-08-26 UTC · All working groups (100% coverage)

36 drafts 0 newly published RFCs 27/36 drafts with official abstract Published at https://ietf-drafts-ok.pages.dev

Newly published RFCs

No newly published RFCs in the window.

The ietf-announce archive shows no RFC-publication announcements after 2026-08-21; there are no RFC items in the 48 hours (2026-08-24 to 2026-08-26 UTC) window. The most recent announcements in the archive were BCP 212 / RFC 10017 (OAuth 2.0 for Browser-Based Applications) and RFC 10036 (Incremental Forwarding of HTTP Messages), both dated 2026-08-21.

Drafts

draft-mcguinness-oauth-id-continuation-assertion-01 Individual rev -01 abstract 2026-08-26

Defines the Identity Continuation Assertion, a short-lived, sender-constrained JWT used as an OAuth 2.0 Token Exchange subject token. It lets an IdP Authorization Server issue an onward Identity Assertion JWT Authorization Grant (ID-JAG) when a user's request crosses service boundaries after the user is no longer present. The profile targets deployments where several Resource Authorization Servers trust a single IdP and use audience-local subject identifiers that only the IdP can resolve. It complements offline attenuation for intra-domain fan-out that does not change the subject.

draft-ietf-idr-ts-flowspec-srv6-policy-17 WG IDR rev -17 abstract 2026-08-26

BGP Flow Specification (FlowSpec) distributes traffic filtering and steering rules across BGP networks. This document specifies FlowSpec procedures to steer matching traffic flows into Segment Routing (SR) Policies. It defines normative mechanisms for combining FlowSpec NLRIs with specific BGP Extended Communities for transport policy steering in SR-MPLS and SRv6 networks (Mode 1), and optionally with the BGP Prefix-SID Attribute when egress service-action execution is required in SRv6 networks (Mode 2).

draft-ietf-spring-sr-policy-group-01 WG SPRING rev -01 2026-08-26

By its name and SPRING working-group scope, this draft probably defines a way to group Segment Routing (SR) Policies so that related policies can be referenced, provisioned, or steered together as a set within SR-MPLS/SRv6 networks. The document page could not be opened this run, so this summary is derived from the title; the official Abstract will be grounded on the next run.

draft-dogru-cedulon-01 Individual rev -01 abstract 2026-08-26

Defines the Cedulon Protocol, an audit layer for agent-to-agent commerce. Payment rails such as HTTP 402 flows (x402) and mandate protocols (AP2) already move value but do not, by themselves, produce a fail-closed policy check and a signed spend receipt reconcilable against a rail extract. Cedulon specifies a signed Trade Manifest, a default-deny Policy Decision Point, a COSE/CWT Spend Receipt after a gated payment, epoch checkpoints, and rail-extract reconciliation showing every settlement has a receipt and vice-versa. It also defines a Dispute Evidence Bundle and optional SCITT anchoring; it sits above x402/AP2 rather than competing with them.

draft-intra-handshake-fail-13 Individual rev -13 abstract 2026-08-25

Presents technical detail of CVE-2026-33697 and EUVD-2026-16488 as evidence that intra-handshake attestation fails in practice, even without physical access. It argues that, because continuous attestation is generally required, intra-handshake attestation adds unnecessary complexity. The results are backed by artifacts in the ProVerif formal-analysis tool, released under Apache-2.0 for reproducibility, and have been acknowledged by the relevant stakeholders.

draft-templin-6man-aero-omni-amen-13 Individual rev -13 abstract 2026-08-25

States that the Automatic Extended Route Optimization (AERO) and Overlay Multilink Network (OMNI) Interface functional specifications have reached a maturity level ready for advancement in the RFC publication process. Updates to the base specifications are documented in this first amendment, with any additional future amendments to follow as necessary.

draft-ietf-manet-inet-gap-analysis-09 WG MANET rev -09 abstract 2026-08-25

Recalls that RFC 2501 defines a MANET as an autonomous system of mobile nodes that may operate in isolation or interface with a fixed network such as the global Internet. Building on that, this document presents a MANET internetworking problem statement and a gap analysis of what is needed to connect mobile ad hoc networks to the wider Internet.

draft-ietf-rtgwg-atn-bgp-32 WG RTGWG rev -32 abstract 2026-08-25

ICAO is investigating mobile routing solutions for a worldwide Aeronautical Telecommunications Network with Internet Protocol Services (ATN/IPS), intended to replace existing services with an IP-based service supporting pervasive Air Traffic Management for controllers, airline operations, and all commercial aircraft worldwide. This informational document describes a simple, extensible mobile routing service based on the industry-standard Border Gateway Protocol (BGP) and the Domain Name System (DNS) to address the ATN/IPS requirements.

draft-reilly-uaemf-02 Individual rev -02 2026-08-25

By its name ("uaemf"), this individual submission probably defines a framework or format in the unmanned/uncrewed aerial or autonomous-systems space, but the abstract could not be retrieved this run (the document page returned 404). Treat this summary as approximate; it will be grounded from the official Abstract on the next run once the page is available.

draft-reilly-aimed-eval-01 Individual rev -01 2026-08-25

By its name, this appears to be the evaluation companion to the "aimed" work by the same author, probably describing how to assess or measure that scheme. The document page could not be opened this run (404), so this description is derived from the title only and is approximate; it will be grounded on the next run.

draft-reilly-aimed-01 Individual rev -01 2026-08-25

By its name, "aimed" appears to be an individual submission defining a method, framework, or metric proposed by the author, with a companion evaluation draft ("aimed-eval"). The abstract could not be retrieved this run (404), so this summary is approximate and derived from the title; it will be grounded on the next run.

draft-ietf-opsawg-veloce-yang-00 WG OPSAWG new -00 abstract 2026-08-25

Describes VELOCE (YANG deVELopment PrOCEss and maintenance), a process intended to be more suitable for developing new YANG modules or updating existing YANG modules within the IETF. As an OPSAWG work item, it aims to streamline how YANG models are authored and maintained across the operations and management area.

By its name, this individual submission probably proposes "query-scoped communication handles" as an identifier or addressing construct for 6G networks, scoping communication endpoints to specific queries or sessions. The document page returned 404 this run, so the description is derived from the title and is approximate; the official Abstract will be grounded on the next run.

draft-ietf-pim-pfm-forwarding-enhancements-08 WG PIM rev -08 abstract 2026-08-25

The PIM Flooding Mechanism (PFM) is an experimental hop-by-hop framework for distributing multicast information among PIM routers, enabling source discovery without Rendezvous Points, shared trees, or initial data registers. This document specifies further experimental enhancements to PFM forwarding to improve efficiency and scalability: mechanisms to reduce redundant transmission over multiple parallel links, and extended encoding via additional TLVs and sub-TLVs to convey richer flow data, while preserving interoperability with existing PFM procedures.

draft-hardt-email-verification-02 Individual rev -02 abstract 2026-08-25

Defines the Email Verification Protocol (EVP), the HTTP-level protocol by which a browser obtains a signed email verification token from an issuer and presents it to a relying party (RP), letting web applications verify a user's control of an email address without sending a verification email. It uses a three-party model in which the browser intermediates between RP and issuer, hiding the RP's identity from the issuer and supporting private, per-RP addresses. It covers issuer discovery, token issuance, EVT and Key Binding JWT formats, and verification; the browser API is defined in a companion W3C specification.

draft-dogru-cedulon-streaming-00 Individual new -00 abstract 2026-08-25

A streaming profile extending the Cedulon core: where core Cedulon does a batch reconciliation audit over a window of spend receipts, epoch checkpoints, and a rail extract, agent fleets that spend continuously need the same property as a live signal. This draft proposes short half-open micro-epochs, an incremental checkpoint cadence, a watermark separating provisional from final findings, and rules for late-arriving settlements, so that "the books are balanced" becomes a continuously maintained, externally checkable state. Its normative language is provisional and the companion implementation does not yet implement it.

draft-dogru-cedulon-reattestation-00 Individual new -00 abstract 2026-08-25

A re-attestation profile for Cedulon evidence, addressing the fact that COSE spend receipts and epoch checkpoints rely on signature algorithms that will eventually be deprecated or broken. It proposes a signed statement, produced while the original algorithm is still trustworthy, that binds the original evidence bytes to a successor algorithm and is registered in a SCITT transparency service. Chains of such statements let a verifier decades later trust evidence whose original cipher has been retired. This is a provisional extension to the Cedulon core; the companion implementation does not yet implement it.

draft-ietf-dkim-dkim2-spec-05 WG DKIM rev -05 abstract 2026-08-25

DKIM2 lets a person, role, or organization owning a signing domain document that it has handled an email by associating its domain with the message, providing a hash over the current message contents plus a signature covering the hashes and transmission details, verified via a DNS-published public key. As messages are transferred, systems that alter the body or headers record their changes and compute new hashes, adding further signatures to form a validatable chain. This lets validators identify intermediary changes and apply reputation, detect unexpected message "replay", and ensure Delivery Status Notifications reach only involved entities.

draft-correctover-ccs-06 Individual rev -06 2026-08-25

By its name, this individual submission ("ccs") could not be retrieved this run (the document page returned 404), so its purpose cannot be confirmed from the abstract. The description is intentionally left approximate rather than guessing specifics; the official Abstract will be grounded on the next run once the page is reachable.

draft-ietf-avtcore-rtp-avatar-02 WG AVTCORE rev -02 abstract 2026-08-25

Outlines RTP payload formats for the animation stream format defined in ISO/IEC 23090-39 (the MPEG-I Avatar Representation Format, ARF). ARF is composed of Avatar Animation Units (AAU), each with an AAU header and zero or more AAU packets. The RTP payload header format allows packetization of an AAU into an RTP packet payload as well as fragmentation of an AAU across multiple RTP packets, enabling real-time transport of avatar animation data.

draft-claise-green-capability-discovery-00 Individual new -00 abstract 2026-08-25

Defines a YANG module that augments the RFC 9196 system-capabilities model so a network element can advertise, per hardware component, the set of Power States each component supports along with a static characterization of the nominal power drawn in each state. It complements the GREEN Power and Energy YANG module (which reports current state and measured power, but not which states are available) and is anchored to the RFC 8348 hardware inventory. Because it is static, it may be supplied as YANG instance data so an Energy Management System can learn a platform's power-state capabilities before deployment or power-on.

draft-ietf-netconf-over-quic-11 WG NETCONF rev -11 abstract 2026-08-25

Specifies how to use QUIC as a secure transport for exchanging NETCONF messages. NETCONF over QUIC takes advantage of QUIC streams, for example to eliminate some TCP head-of-line blocking issues, while providing security properties similar to NETCONF over TLS. The document also defines a YANG module that augments the ietf-netconf-client and ietf-netconf-server YANG modules to configure the new transport.

draft-ietf-nfsv4-rfc8881bis-09 WG NFSV4 rev -09 abstract 2026-08-25

Describes NFS version 4 minor version 1, including features retained from the base protocol (NFSv4.0, RFC 7530) and the extensions that are part of Minor Version 1, which has no dependencies on Minor Version 0. This document is part of a set that collectively obsoletes RFCs 8881 and 8434; besides many corrections and clarifications, it relies on NFSv4-wide documents to substantially revise the treatment of protocol extension, internationalization, and security, superseding those aspects as described in RFCs 5661 and 8881.

draft-anjum-nmop-anomaly-detection-evaluation-01 Individual rev -01 abstract 2026-08-25

The NMOP working group has adopted documents on an architecture, operational lifecycle, and semantics for network anomaly detection, but those do not define how the accuracy of an implementation is measured, compared, or tracked over time. This informational document describes an evaluation methodology for machine-learning-based anomaly detection on network and infrastructure telemetry: the metrics to report and their known failure modes, a benchmarking procedure based on controlled fault injection and replay, and the properties a benchmark dataset needs to support reproducible, comparable evaluation.

draft-sato-soos-gar-06 Individual rev -06 2026-08-25

By its name, this individual submission ("soos-gar") could not be opened this run (the document page returned 404), so its subject cannot be confirmed from the abstract. Rather than invent specifics, this description is left approximate; the official Abstract will be grounded on the next run once the page is reachable.

draft-ietf-v6ops-rfc6146-bis-15 WG V6OPS rev -15 abstract 2026-08-25

Specifies stateful NAT64 translation, allowing IPv6-only clients to contact IPv4 servers using unicast UDP, TCP, or ICMP. One or more public IPv4 addresses assigned to a stateful NAT64 translator are shared among several IPv6-only clients, and IPv4-initiated communications to a subset of IPv6 hosts are supported through configured bindings. Used together with DNS64, no changes are required in either the IPv6 client or the IPv4 server. This document obsoletes RFC 6146.

draft-chen-oauth-agent-authz-use-cases-03 Individual rev -03 abstract 2026-08-25

Provides a systematic analysis of emerging AI-agent-based authorization use cases. It categorizes them into distinct scenarios, details their specific authorization requirements, and performs a comprehensive gap analysis against the existing OAuth 2.0 framework and its common extensions. The analysis identifies fundamental gaps and requirements, providing a foundation for future work on new extensions within the OAuth Working Group toward a more secure and interoperable ecosystem for agent-based systems.

draft-wang-idr-path-attribute-orf-00 Individual new -00 abstract 2026-08-25

Defines a family of Outbound Route Filter (ORF) Types for controlling the propagation of BGP Path Attributes. These Path Attribute ORFs (PA-ORFs) let a BGP speaker dynamically request that a peer suppress, remove, refine, or constrain the propagation of selected Path Attributes when building outbound UPDATE messages for a given AFI/SAFI. Four ORF Types are defined (Path Attribute Type, Subtype, Unknown, and Propagation Scope), reusing existing ORF Capability and ROUTE-REFRESH procedures with no new attribute or message type, chiefly to curb unintended propagation of Optional Transitive attributes valid only within a limited domain.

draft-ietf-pim-evpn-multicast-yang-06 WG PIM rev -06 2026-08-25

By its name and PIM working-group scope, this draft probably defines a YANG data model for configuring and managing EVPN multicast, likely tying PIM/EVPN multicast behavior into a manageable model. The document page returned 404 this run, so the description is derived from the title and is approximate; the official Abstract will be grounded on the next run.

draft-ietf-uta-tls13-iot-profile-24 WG UTA rev -24 abstract 2026-08-25

RFC 7925 offers guidance on using TLS/DTLS 1.2 for resource-constrained Internet of Things (IoT) devices. This document is a companion to RFC 7925, defining TLS/DTLS 1.3 profiles for IoT devices. It additionally updates RFC 7925 with respect to the X.509 certificate profile and the ciphersuite requirements, bringing IoT TLS guidance up to date with the 1.3 versions of the protocols.

draft-kushwaha-scim-didvc-binding-01 Individual rev -01 abstract 2026-08-25

Defines a SCIM extension for binding SCIM User resources to decentralized identity artifacts, including Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs). It introduces a read-only schema extension exposing binding state for discovery, a new IdentityBinding resource type recording auditable linkage between a user and one or more DIDs/credential references, and an optional ServiceProviderConfig extension advertising server capabilities. It deliberately does not define DID resolution, credential issuance, transport, or authentication; it specifies binding lifecycle semantics such as material-change classification, partial revocation, and propagation via SCIM Events.

draft-wei-aic-jwt-00 Individual new -00 abstract 2026-08-25

Defines the JSON Web Token (JWT) profile of the AI Agent Identity Certificate (AIC), a companion to draft-wei-aic-identity-cert. The AIC binds an AI agent's cryptographic identity to a responsible principal, carrying a structured capability container, authorization-boundary constraints, delegation mode, and principal-signed delegation evidence for offline authorization at the TLS layer. AIC-JWT encodes the same data model as an application-layer JWT so the same authorization semantics apply to HTTP APIs, web apps, and OAuth 2.0 ecosystems, using a nested JWS that preserves AIC's two-layer signature model, a namespaced "aic" claim, principal binding by SPKI hash or JWK thumbprint, and issuance via PKI CAs or OAuth 2.0 servers.

draft-das-execution-finality-protocol-layer-00 Individual new -00 2026-08-25

By its name, this individual submission probably proposes a protocol-layer notion of "execution finality," likely in a distributed-systems, settlement, or transaction-ordering context. The document page returned 404 this run, so this description is derived from the title only and is approximate; the official Abstract will be grounded on the next run once the page is reachable.

draft-juwan-ars-00 Individual new -00 abstract 2026-08-25

Defines ARS-1, a deterministic, human-oriented, cryptographically derived reference protocol for assigning stable public References to durable digital entities (typical references look like NX-174932 or KX4-7B19Q2). It covers cryptographic identity, deterministic derivation, namespace management, canonical serialization, variable-length encoding, checksums, optional hardware input and signatures, cryptographic agility, versioning, portability, and resolution. A core requirement is that identical canonical inputs, profile, key material, and hardware output MUST produce exactly the same canonical Reference in every conforming implementation, with versioned Profiles enabling algorithm changes without reassigning issued References.

draft-zhangb-cats-service-metrics-op-04 Individual rev -04 abstract 2026-08-25

Computing-Aware Traffic Steering (CATS) optimizes forwarding by considering both computing and networking metrics, but existing framework/metric drafts offer theoretical models that are hard to execute operationally because normalization varies across providers and aggregated unitless scores lose operational detail. This document provides an executable approach: it defines Computing Service Metrics and their operations, has service sites report service-oriented metrics (e.g., Global Available Slots) rather than raw hardware metrics, clarifies how those derive from resource, reference, and policy information, and specifies how the CATS Path Selector combines computing and network service tables for joint steering, plus update-control mechanisms for large-scale deployments.

draft-juwan-ars-uri-01 Individual rev -01 abstract 2026-08-25

Defines the "ars" URI scheme for representing ARS-1 References in a syntactically valid URI form. ARS-1 defines a deterministic, cryptographically derived reference protocol for stable public identifiers of durable digital entities; the "ars" scheme gives those references a standard URI notation for use in hyperlinks, QR codes, metadata fields, and other URI-consuming contexts. It does not redefine the ARS-1 generation pipeline, canonicalization, or verification (those are normative in ARS-1), specifying only URI syntax, encoding, comparison, and resolution semantics.