IETF Internet-Drafts & RFCs — Daily Digest

Report date: 2026-09-09 · Window: last 48 hours (2026-09-07 to 2026-09-09 UTC)

Coverage: all groups (WG, RG and Individual submissions). Sourced from the i-d-announce and ietf-announce mail-archive indexes; abstracts from www.ietf.org/archive/id and rfc-editor.org.

76 drafts 0 RFCs 59/76 drafts with official abstract Published at https://ietf-drafts-ok.pages.dev

Newly published RFCs

No RFC or BCP announcements were found in the window. The ietf-announce archive shows no RFC/BCP announcements after 2026-08-31; there are no RFCs in the last 48 hours (2026-09-07 to 2026-09-09 UTC).

Drafts

2026-09-09 10 documents

draft-ietf-mediaman-6838bis-10 MEDIAMAN rev -10 abstract

Defines the procedures for specifying and registering media types for use in HTTP, MIME and other Internet protocols. It obsoletes RFC 6838 and RFC 9694 and forms part of BCP 13 alongside RFC 4289, which covers registration of MIME external body access types and transfer encodings.

draft-das-ntn-rf-execution-finality-01 Individual rev -01 abstract

Specifies a radio-side execution-finality profile for non-terrestrial networks and mega-constellations. A proposed RF, inter-satellite-link, beam, gateway or payload action is treated as a Candidate Act; a Protected Enforcement Domain binds vehicle, beam, frequency class, duration, next hop, overflight/jurisdiction epoch and intended sink, then issues scoped non-bearer authority. A Finality Sink at the PA-enable, ISL switch or beam driver verifies that authority immediately before energy leaves the aperture. The guiding principle is that RF enable is not transmit authority, because radiation is irreversible.

draft-gai-intarea-ip-tunnel-node-security-01 Individual rev -01 abstract

Specifies generic security requirements for IP tunnel ingress, egress and relay nodes. Because tunnels conceal passenger-packet fields and create a new policy boundary at decapsulation, an unauthenticated source or unfiltered decapsulated packet can enable spoofing, unauthorized transit, policy bypass or resource exhaustion. Requirements cover explicit enablement, peer and passenger-packet authorization, source and forwarding-scope validation, nested tunneling, IPv6 extension headers, ICMP and PMTUD, resource controls and telemetry, applying to IP-in-IP, IPv6 tunneling, GRE and transition mechanisms. It does not define a new encapsulation.

draft-buckeyne-jsox-format-01 Individual rev -01 abstract

Defines JSOX (JavaScript Object eXchange), a lightweight, text-based, language-independent data-interchange format derived from JSON and ECMAScript object-literal syntax; every well-formed JSON text is also valid JSOX. It extends JSON with unquoted identifiers, additional string and escape forms, comments, extra number forms (including dates and arbitrary-precision integers), binary typed arrays, user-defined types carried by a type tag, field-name macros, and references for shared and cyclic structures. It registers the media type application/jsox.

draft-das-payment-execution-finality-01 Individual rev -01 abstract

Specifies a payment-side execution-finality profile. A payment instruction remains a Candidate Act; a Protected Enforcement Domain binds principal, wallet or account, amount, currency, beneficiary, rail, purpose and policy epoch, committing evidence before issuing scoped non-bearer authority. The sink that actually posts, captures or releases funds verifies that authority against the live instruction and consumes it. It is motivated by AI agents and RPA workers that treat tool selection as settlement authority. Core principle: a signed instruction is not settlement.

draft-ietf-pce-sr-p2mp-policy-21 PCE rev -21 abstract

Specifies PCEP extensions that let a stateful Path Computation Element compute and initiate point-to-multipoint (P2MP) paths for SR-MPLS from a root to a set of leaf nodes, supporting the architecture for Segment Routing P2MP service delivery.

draft-ietf-scone-protocol-08 SCONE rev -08 abstract

Describes a protocol by which on-path network elements communicate their perspective on the maximum sustainable throughput for QUIC flows to endpoints. This throughput advice suggests an upper bound on long-term average throughput, independent of and complementary to real-time congestion-control signals.

draft-kondoju-evc-02 Individual rev -02 abstract

Specifies the External Verifier Contract (EVC): a small, proof-system-agnostic boundary between a host about to take a privileged action and an external verifier subprocess that returns an allow/deny verdict on an opaque proof bundle. It governs only the transport and verdict envelope: one JSON request over stdin, exactly one JSON verdict on stdout, and fail-closed handling of exit codes, timeouts and malformed output. It is deliberately not a governance framework, delegation model or policy language, but the narrow decision boundary those larger systems require at the point of enforcement.

draft-ietf-ippm-stamp-ext-hdr-12 IPPM rev -12 abstract

Extends STAMP (Simple Two-Way Active Measurement Protocol) to reflect IP headers and IPv6 extension headers for hop-by-hop and edge-to-edge active measurements, for example carrying IOAM data fields. It also specifies requirements for IPv6 STAMP in unauthenticated mode using a UDP zero-checksum, which deviates from the integrity requirement of RFC 6936.

draft-ietf-mpls-stamp-pw-19 MPLS rev -19 abstract

Specifies encapsulations for STAMP (RFC 8762) and its optional extensions (RFC 8972) in MPLS networks, for point-to-point LSPs and single-segment pseudowires, with or without an IP/UDP header, so test packets follow the same forwarding and ECMP behavior as the measured data. It defines two new MPLS G-ACh types and updates RFC 8762 and RFC 8972 to allow STAMP to operate without an IP/UDP header over MPLS LSPs and PWs.

2026-09-08 22 documents

draft-intra-handshake-fail-26 Individual rev -26 abstract

Argues, using formal analysis in ProVerif and published CVE/GHSA evidence, that intra-handshake (early) attestation fails in practice even without physical access, and adds unnecessary complexity given that continuous attestation is generally required anyway. It catalogs numerous published CVEs and security advisories against early attestation across all layers of the ecosystem and states that remaining implementations (Edgeless Systems Contrast and Meta's AI) remain vulnerable; artifacts are shared under Apache-2.0 for reproducibility and review.

draft-hillier-scitt-arp-04 Individual rev -04 abstract

Specifies the Attestation Reconciliation Protocol (ARP), a deterministic, bilateral, minimum-disclosure mechanism for reconciling verification claims against multiple sovereign authoritative registers without raw register records leaving their data-residency jurisdiction. Extending the SCITT architecture, a reconciliation server canonicalizes a claim, binds the requester's identity (including a friend-or-foe check for autonomous agents), projects the claim through register-specific functions, and aggregates partial attestations under a Merkle-committed verdict arithmetic sealed against a policy-version hash. This revision adds a normative binding to the SCITT Reference APIs and register data-format profiles.

draft-ietf-moq-transport-21 MOQ rev -21 abstract

Defines Media over QUIC Transport (MOQT), a publish/subscribe protocol running over QUIC and WebTransport that leverages streams, datagrams, priorities and partial reliability. It operates both point-to-point and through intermediate relays for scalable low-latency delivery and, despite its name, is media-agnostic and applicable to a wide range of use cases.

draft-ietf-dtn-bp-sand-04 DTN rev -04 abstract

Defines the Secure Advertisement and Neighborhood Discovery (SAND) protocol for Bundle Protocol version 7 within a delay-tolerant network. It provides a general-purpose advertisement mechanism with an initial set of message and data types that participating nodes can advertise, focused on informing topological neighbors about local neighborhoods, with extension points for future growth.

Presents a framework for network-traffic classification and modality mapping based on large language models, addressing the inefficiencies of traditional methods in dynamic networks. It automates multi-dimensional traffic-feature extraction and decision-making in two phases: pre-training (generating multi-modal traffic representations from pcap data) and mapping (dynamically formulating resource-allocation strategies). It supports anomaly detection, QoS assurance and multi-service collaboration to improve resource utilization and network performance.

Defines an aggregate performance report format for email messaging, together with a means to discover target destinations and a specified delivery method.

draft-saha-stage-receipts-00 Individual new -00 abstract

Defines the stage receipt: a small, canonically serialized JSON record emitted by each stage of a staged pipeline (document ingestion, retrieval-augmented generation, agent workflow or benchmark) describing exactly what went in, what came out, under which pinned instrument and outcome, linked by digest to the previous receipt. A chain of receipts lets a developer reproduce a run, diff two runs to the first differing stage, and localize a fault, while letting an independent party verify the assertions later and offline. It specifies the record, its canonical form, the chain manifest, coverage/emission and anchoring declarations, conforming-verifier behavior, and golden conformance vectors.

draft-ietf-lake-edhoc-psk-09 LAKE rev -09 abstract

Specifies a Pre-Shared Key (PSK) authentication method for EDHOC (Ephemeral Diffie-Hellman Over COSE), the LAKE lightweight authenticated key exchange. The PSK method provides mutual authentication, ephemeral key exchange, identity protection and quantum resistance at lower computational cost than EDHOC's public-key methods. It suits nodes that share an external PSK out-of-band and enables efficient session resumption with a resumption PSK. It details the PSK message flow, key-derivation changes, message formatting, processing and security considerations.

Argues that Deepspace/TIPTOP interplanetary-networking protocols should use an external, standardized reference framework for celestial objects (an equivalent of ISO 3166), deferring the definitions, naming and tracking of celestial entities to the International Astronomical Union and the Minor Planet Center rather than an IANA-maintained astronomical registry. It outlines how these external identifiers guide hierarchical address allocation and aims to define what constitutes a valid celestial body for networking purposes.

draft-wei-aic-jwt-01 Individual rev -01 abstract

Defines AIC-JWT, a JWT-based application-layer representation of the AI Agent Identity Certificate (AIC) data model, which binds an AI agent's cryptographic identity to a responsible principal together with a capability container, delegation mode and authorization constraints. For HTTP, web and OAuth 2.0 deployments that cannot present X.509 certificates at the transport layer, AIC-JWT is a companion representation (not a replacement) built on JWT and JWS; the issuer-signed outer token carries the principal-signed delegation JWT in the top-level 'da' claim, preserving AIC's two-layer signature model. Authorization semantics are inherited from the AIC model.

draft-reddy-wimse-aggregate-signatures-00 Individual new -00 abstract

Profiles the WIMSE HTTP Message Signatures mechanism to protect a request passing through a chain of workloads. In the base mechanism each workload signs independently, so an intermediary can remove a signature undetected and signatures accumulate per hop. This document combines the workloads' signatures into a single aggregate signature, making removal detectable and keeping the signature material from growing with chain length, a significant saving for large post-quantum signatures. It works with any aggregate signature scheme.

draft-irtf-iccrg-pacing-03 ICCRG rev -03 abstract

Gives an overview of pacing, the technique of evenly spacing out a sender's traffic over a round-trip time to reduce the burstiness that causes unnecessary queuing and packet loss, and describes how several known pacing implementations work.

draft-corbel-updates-to-rfc2289-00 Individual new -00 abstract

Proposes several updates to RFC 2289, the One-Time Password (OTP) system: an API to the newer Secure Hash Algorithms (SHA-256, SHA-384 and SHA-512), an algorithm for folding hashes to 64 bits, the use of alternate dictionaries, and automatic renewal of authentication parameters.

draft-ietf-regext-epp-https-05 REGEXT rev -05 abstract

Describes how an Extensible Provisioning Protocol (EPP) connection is mapped onto HTTP. EPP over HTTP (EoH) requires the use of TLS to secure EPP information, i.e. HTTPS.

draft-das-precision-bounded-egress-03 Individual rev -03 abstract

Defines a precision-bounded egress profile: a data-minimization mechanism applied at the point of external disclosure, on top of an execution-finality architecture, for both conventional applications and autonomous AI agents. A proposed location release is a Candidate Act that stays non-effective while a Protected Enforcement Domain evaluates purpose, requester, component, recipient, destination, jurisdiction, required precision and cumulative disclosure, then issues scoped, cryptographically bound authority for a specific precision ceiling. An independent egress Finality Sink verifies that authority against the actual outbound payload before release, so the bound ceiling (exact, reduced or denied) governs what leaves the device. Data access is not data-export authority.

draft-das-ai-native-6g-execution-finality-03 Individual rev -03 abstract

Defines an informational execution-finality profile for AI-native 5G, 5G-Advanced, IMT-2030/6G, O-RAN and AI-RAN environments. A proposed network operation is a Network Candidate Act that stays in a Non-Effective State while a Protected Enforcement Domain validates act-specific predicates; validation evidence is committed before scoped non-bearer authority is released, and a Network Finality Sink independently re-verifies that authority immediately before live network state changes. It adds a JSON interoperability profile. The governing rule is that network authentication is not network finality, and computation is not authority.

draft-gerke-publication-process-reform-05 Individual rev -05 abstract

Proposes updating the AUTH48 (or equivalent) process by introducing deterministic state-integrity constraints within the IETF Datatracker architecture, with automated validation milestones and explicit access controls to prevent late technical modifications after Working Group Last Call and thereby safeguard rough consensus. It updates RFC 7841.

draft-zhang-dawn-agent-discovery-framework-01 Individual rev -01 abstract

Describes a two-layer federated reference architecture for the IETF DAWN (Discovery of Agents With Names) work on cross-organization agent discovery. A Local Discovery Plane performs zero-configuration agent advertisement and collection inside each site, while a Federation Plane connects site gateways to exchange lightweight Federation Metadata Records (a binding of DAWN Minimum Discoverable Information) across administrative domains, with full Capability Cards retrieved on demand. It emphasizes data sovereignty via an Export Policy Engine and is informational, composing rather than competing with existing DAWN proposals.

Describes an architecture in which first contact and future reachability are separate authorization events for map- and marketplace-based discovery. After a user's query, a platform can create a query-scoped, non-bearer communication reference and bounded preview authority; continued communication is separately authorized and bound to attributes such as the original query, business identity, purpose, channel, validity window, nonce, quota and revocation state. A Communication Authority Service creates the protected binding while an enforcement point reconstructs and verifies the actual attempted communication before releasing the communication-bearing resource. Named platforms are illustrative only, and the design aligns with GDPR data-minimization and purpose-limitation principles.

Describes an authorization-to-reach model in which a visible communication handle (a phone number, SIP URI, messaging handle, relay address or marketplace contact reference) is not by itself permission to create a communication effect. A request is held as a candidate until current, purpose-scoped, revocable and optionally consumable authority is validated. It is informational, contrasts the model with STIR/SHAKEN, masked numbers, OAuth and spam scoring, and asks whether the IETF ART area should define interoperable semantics or an encoding (for example a PASSporT claim, a SIP header or a pre-INVITE check). Named operators and platforms are illustrative only.

draft-xsaopig-nsttlp-traffic-labeling-01 Individual rev -01 abstract

Specifies a protocol mechanism for embedding service-type identifiers into network packets to enable intelligent traffic recognition, policy-based forwarding and resource optimization by network devices. Standardized service-type labels can be carried in IPv4/IPv6 headers, MPLS labels or Ethernet frame headers, and the mechanism targets a range of services including immersive VR (1080p, 4K), scientific computing, real-time communications and IoT.

draft-sato-soos-acd-03 Individual rev -03 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast www.ietf.org/archive/id source (the page returned 404), so this description is written from the name and is approximate; by its 'acd' suffix it appears to specify one component of the SOOS series. It will be grounded from the official Abstract on the next run.

2026-09-07 44 documents

draft-sato-soos-grp-02 Individual rev -02 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate; the 'grp' suffix suggests a grouping/group-related component of the SOOS series. It will be grounded on the next run.

draft-ietf-vcon-vcon-core-04 VCON rev -04 abstract

Defines vCon, a standardized JSON framework for exchanging conversational data across many modes and application platforms, encompassing metadata, conversation media, related documents and analysis. The goal is an abstracted, platform-independent format that eases integration and seamless exchange of conversational data across platforms, enterprises and trust boundaries.

draft-ietf-nfsv4-posix-acls-02 NFSV4 rev -02 abstract

Proposes four new optional file attributes for NFSv4.2 to support POSIX ACLs conforming to the withdrawn POSIX 1003.1e draft 17.

Describes an evaluation methodology for network anomaly detectors (rule-based, statistical or machine-learning) operating on network and infrastructure telemetry, complementing the NMOP working group's adopted anomaly-detection architecture, lifecycle and semantics documents. It covers the metrics to report and their failure modes, a benchmarking procedure based on controlled fault injection and replay, ground-truth labeling and scoring across multiple telemetry signals, and the properties a benchmark dataset needs for reproducible, comparable evaluation. It is informational.

draft-le-comparing-derived-identifiers-01 Individual rev -01 abstract

Presents a framework for specifying and reviewing the rules behind comparisons of independently derived identifiers, cast as a 'comparison contract' that connects source mappings to derivation-domain equivalence and to the conclusions supported by equal and unequal outputs. It distinguishes information loss before a downstream operation from that operation's own false-match properties, and guides reviewers to trace the relevant specification clauses, record evidence and identify unmet obligations. It defines no identifier format or derivation algorithm.

Introduces an ICMP extension for Node Identification, analogous to RFC 5837's interface and next-hop identification. It lets a node provide a unique IP address and/or a textual name where each node may not have a unique IP address to respond to (for example a deployment where all interfaces and next-hops are IPv6 even for IPv4 routes), which is especially useful for tools such as traceroute.

draft-ietf-bess-evpn-bfd-20 BESS rev -20 abstract

Specifies proactive, in-band network-layer OAM mechanisms (per RFC 9062) to detect loss-of-continuity faults affecting unicast and multi-destination paths (used by Broadcast, Unknown Unicast and Multicast traffic) in an EVPN network, using the widely adopted Bidirectional Forwarding Detection (BFD) protocol.

draft-ffm-rats-cca-token-04 Individual rev -04 from name/title

By its name, this individual draft relates to RATS (Remote ATtestation procedureS) and probably defines or profiles a CCA (Confidential Compute Architecture) attestation token/claims format. The official Abstract could not be retrieved from the fast source (404), so this description is approximate and will be grounded from the official Abstract on the next run.

draft-koch-librepgp-06 Individual rev -06 abstract

Specifies the message formats used in LibrePGP, an extension of the OpenPGP format that provides public-key and symmetric encryption, digital signatures, compression and key management. It documents the formats and methods needed to read, check, generate and write conforming packets and discusses implementation issues necessary to avoid security flaws. It is based on RFC 4880 (OpenPGP), RFC 5581 (Camellia) and RFC 6637 (Elliptic Curves).

Defines an ACME authority-token profile for validating the JWTClaimConstraints and EnhancedJWTClaimConstraints certificate extensions. Based on the Authority Token framework, it establishes the specific ACME identifier type, challenge mechanism and token format needed to authorize a client to request a certificate containing these constraints.

draft-ietf-opsawg-rfc5706bis-07 OPSAWG rev -07 abstract

Provides guidance to authors and reviewers on the operational and management aspects to address when specifying new protocols or protocol extensions in the IETF Stream, arguing that such considerations should be designed in rather than retrofitted. It obsoletes RFC 5706 (replacing it completely), updates RFC 2360 to remove mandatory MIB creation, and requires an 'Operational Considerations' section in relevant new RFCs, with an escape clause where no new considerations are identified.

draft-das-child-safe-rendering-finality-04 Individual rev -04 abstract

Defines a protected-rendering execution-finality architecture for adult or otherwise age-restricted content. Because upstream age checks and parental controls do not guarantee that content cannot later be decrypted, decoded, composited or rendered through another path, a proposed rendering is a Restricted Content Candidate Act kept Non-Renderable until a Protected Enforcement Domain validates recipient, content, device, policy, eligibility, freshness and revocation predicates. A Rendering Finality Sink then verifies scoped authority immediately before the content becomes perceptible, controlling key release, decryption, decoder/GPU/compositor access or an equivalent boundary. Motivated in part by a proposed Temporary Under-18 Handover Mode; the core principle is that permission to deliver content is not permission to render it.

Analyzes the network's role in distributed execution across space networks, where a node may lack sufficient compute, storage, energy or execution time, or where data is spread across nodes. Because satellite motion changes connectivity over time, reachability alone cannot determine whether an execution endpoint can support the required communication. It considers how network information affects execution decisions, how those decisions create communication requirements and relationships, when a relationship is ready for use, and how relationships change as execution and connectivity evolve.

draft-liu-sidrops-rpki-rtr-over-quic-04 Individual rev -04 abstract

Describes how to run the RPKI-to-Router (RTR) protocol over QUIC, named RTRoQUIC. RTR provides a simple, reliable mechanism to receive cryptographically validated RPKI prefix-origin data and router keys from a trusted cache; QUIC adds fast connection establishment and multi-stream carrying, reducing the time to complete RTR data synchronization.

draft-ietf-core-oscore-id-update-07 CORE rev -07 abstract

Defines an OSCORE ID update procedure so two CoAP peers using OSCORE can update the Sender and Recipient identifiers that identify their security contexts. Because these identifiers are sent in plaintext within OSCORE-protected messages, they can be used to correlate messages and track peers, with privacy implications. The procedure can run stand-alone or be integrated into an execution of the Key Update for OSCORE (KUDOS) procedure.

draft-ietf-sidrops-rtr-yang-09 SIDROPS rev -09 abstract

Defines YANG data models for managing the RPKI-to-Router protocol (RFC 6810 and RFC 8210).

Introduces a new IGP Algorithm Type in IANA's 'IGP Algorithm Type' subregistry that computes paths using the cost in the reverse direction on each link, and discusses using this new algorithm type in combination with IGP Flexible Algorithm to compute constraint-based paths.

draft-kuehlewind-audit-architecture-01 Individual rev -01 abstract

Proposes an audit architecture for autonomous and semi-autonomous software agents, including AI-based ones, that increasingly act on behalf of users, organizations and services. Existing mechanisms capture isolated system events but do not consistently represent delegation relationships, user intent or evolving authorization; auditability in agent-driven systems requires linking intent, delegation, authorization and execution. The architecture enables this through distributed audit-record generation, propagation of audit context, optional attestation and additional transparency logging.

draft-sato-soos-sov-04 Individual rev -04 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate; the 'sov' suffix suggests a sovereignty-related component of the SOOS series. It will be grounded on the next run.

draft-sato-soos-mad-05 Individual rev -05 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'mad' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-kia-07 Individual rev -07 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'kia' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-gar-08 Individual rev -08 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'gar' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-ietf-core-oscore-key-limits-08 CORE rev -08 abstract

Defines how two OSCORE peers should follow key-usage limits for the AEAD algorithms that protect their messages, since known forgery attacks make it necessary to limit how many times a key is used for encryption or decryption. It explains the steps peers should take, including updating the OSCORE keying material before the limits are reached, so communication can securely continue.

draft-sato-soos-pt-04 Individual rev -04 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'pt' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-rgp-02 Individual rev -02 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'rgp' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-peer-02 Individual rev -02 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate; the 'peer' suffix suggests a peering-related component of the SOOS series. It will be grounded on the next run.

draft-sato-soos-mjwt-06 Individual rev -06 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate; the 'mjwt' suffix suggests a component related to JSON Web Tokens within the SOOS series. It will be grounded on the next run.

draft-sato-soos-idp-06 Individual rev -06 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate; the 'idp' suffix suggests an identity-provider-related component of the SOOS series. It will be grounded on the next run.

draft-sato-soos-dam-01 Individual rev -01 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'dam' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-aop-03 Individual rev -03 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'aop' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-sato-soos-aep-04 Individual rev -04 from name/title

Part of the individual 'sato-soos' draft series. The official Abstract could not be retrieved from the fast source (404), so this is written from the name and is approximate. The 'aep' suffix names one component of the SOOS series; it will be grounded on the next run.

draft-jovancevic-saip-11 Individual rev -11 from name/title

Individual draft ('saip'). The official Abstract could not be retrieved from the fast source (404) and the acronym is not resolvable from the name alone, so no reliable summary is available. This entry is approximate and will be grounded from the official Abstract on the next run.

draft-ietf-dtn-bibe-00 DTN new -00 abstract

Describes Bundle-in-Bundle Encapsulation (BIBE), a delay-tolerant-networking Bundle Protocol tunneling mechanism in which a bundle is carried as the payload of one or more encapsulating bundles, so security measures, routing policy and protocol-version translation can be applied to the encapsulating bundle without modifying the encapsulated one. It includes an optional segmentation mechanism so a large encapsulated bundle can be carried across multiple encapsulating bundles.

draft-ietf-dtn-btpu-fec-02 DTN rev -02 abstract

Defines an optional extension to the Bundle Transfer Protocol - Unidirectional (BTP-U) to apply forward error correction (FEC) coding selectively to individual bundles on a case-by-case basis. The FEC use follows the FECFRAME framework (RFC 6363) and new message types are introduced to BTP-U to carry the FEC information.

draft-ietf-dtn-btpu-04 DTN rev -04 abstract

Defines a protocol for the unidirectional transfer of large binary objects, typically Bundle Protocol version 7 bundles, between two nodes connected by a unidirectional, unreliable, frame-based link-layer protocol, without requiring IP services. It needs no return path for acknowledgements, using data repetition to protect against loss, and supports disaggregation of flows of different priority to prevent head-of-line blocking. The wire format is designed for performant hardware or software implementation at the link's line rate.

Describes an attestation-bound execution-finality architecture for confidential-computing and large AI-accelerator fleets. Because an acceptable Attestation Result establishes that an execution environment is trustworthy but not that a specific operation may proceed, a consequential operation (an API call, storage mutation, network/config change, financial instruction and so on) first exists as a Candidate Act in a non-effective state; its parameters are then cryptographically bound to validation context such as attestation results, workload identity, execution context, policy, authorization scope and freshness. A designated Finality Sink verifies the binding at or before the boundary where the act would first acquire external effect. It complements RATS, EAT, workload identity, TEEs and existing authorization.

draft-nygate-ippm-mrl-00 Individual new -00 abstract

Defines mouth-to-ear response latency (MRL), a performance metric for conversational voice systems, and an active method to measure it at the RTP reference point of the calling endpoint. MRL is the interval between transmission of the last speech sample of a caller's utterance and arrival of the first sample of the system's response; two variants are defined, one at packet arrival and one behind a de-jitter buffer of stated depth. Both timestamps come from a single clock on one host, so no synchronization with the system under test is needed. Requirements for stimulus material, capture, quality control, calibration and reporting are given.

Addresses an SRv6 deployment problem: when a firewall exists along an SRv6 path, not only legitimate SRv6 traffic but also ICMP packets generated on an SRv6 transit node can be dropped. The draft proposes using a SID as the source address in SRv6 packets to address this issue.

Lists the security levels of certain pairing-friendly elliptic curves and motivates curve choices in light of the exTNFS attack (Kim and Barbulescu, CRYPTO 2016), which reduced curves such as 254-bit Barreto-Naehrig below their nominal 128-bit security. It surveys adoption of pairing-friendly curves in standards, libraries and applications at the 128-, 192- and 256-bit levels, selects recommended curves considering exTNFS, and specifies serialization and deserialization of the points and scalars that protocols exchange.

draft-ek-dtn-qubicle-02 Individual rev -02 abstract

Specifies a minimal convergence-layer protocol for transferring Bundle Protocol version 7 bundles over QUIC, leveraging QUIC's native reliable streaming, connection management and security. Reliable transfers carry each bundle on its own QUIC stream, either directly or wrapped in a single CBOR byte string, with no further application-layer framing; unreliable transfers use the Bundle Transfer Protocol - Unidirectional (BTP-U) over QUIC datagrams.

By its name, this PIM working-group draft likely defines YANG data-model extensions for IGMP/MLD snooping in an L2VPN context. The official Abstract could not be retrieved from the fast source (404), so this description is approximate and will be grounded from the official Abstract on the next run.

draft-llz-bier-ipfix-bier-00 Individual new -00 abstract

Introduces new IP Flow Information Export (IPFIX) Information Elements to identify a set of information related to Bit Index Explicit Replication (BIER), such as data contained in the BIER header with which traffic is being forwarded.

draft-ietf-intarea-rfc8335bis-05 INTAREA rev -05 abstract

Specifies PROBE, a network diagnostic tool similar to PING for querying the status of a probed interface, but which does not require bidirectional connectivity to that interface: instead it requires bidirectional connectivity to a proxy interface, which may reside on the same node as the probed interface or on a directly connected node. It updates RFC 4884 and obsoletes RFC 8335.

draft-ietf-pim-flex-algo-01 PIM rev -01 abstract

Defines PIM message extensions to build multicast trees over a specific topology and a constraint-based path, using Multi-Topology Routing and IGP Flexible Algorithm, instead of only the shortest path computed by routing protocols.