IETF Internet-Drafts & RFCs — Daily Digest

Window: last 48 hours (2026-09-25 → 2026-09-27) · Generated 2026-09-27 05:19 UTC
64 drafts 0 RFCs 13/64 drafts with official abstract Published at ietf-drafts-ok.pages.dev

Newly published RFCs

No RFCs were announced within the 48-hour window. The ietf-announce archive shows no "RFC NNNN on ..." announcements after 2026-09-19, which is before the window; the most recent were RFC 10050, RFC 10041, and RFC 10032 (announced 2026-09-19). No items are filled in from before the window.

Drafts

2026-09-27 8 drafts

By its name, an individual submission related to SCITT (Supply Chain Integrity, Transparency, and Trust) that appears to define a "framing space" concept for SCITT statements or profiles. Full details are not available from a fast source; approximate, to be grounded from the official Abstract on the next run.

By its name, an individual SCITT-related submission defining a "measurement capsule", probably a structured container for measurement or evidence data within the SCITT transparency framework. Approximate; to be grounded from the official Abstract next run.

By its name, an individual submission defining a "disclosure envelope" for AI agents — likely a structured wrapper for disclosing agent actions or evidence. Approximate; to be grounded from the official Abstract next run.

By its name, a companion individual submission defining an agent "disclosure bundle", probably an aggregation of agent disclosure artifacts. Approximate; to be grounded from the official Abstract next run.

By its name, an individual submission defining a request format for agent evidence, likely used to solicit attestation or accountability evidence from AI agents. Approximate; to be grounded from the official Abstract next run.

Per its datatracker title, "An Agent Action Capsule Profile for SCITT" — a signed statement profile for recording and verifying what an AI agent did. Description approximate (from the title and companion materials); to be grounded from the official Abstract next run.

By its name and companion materials, defines a Checkpointed Local Log (CLL): an append-only log with hash chains, a Merkle Mountain Range (MMR), and signed COSE checkpoints, used with SCITT for agent accountability. Approximate; to be grounded from the official Abstract next run.

By its name, an individual submission in the WIMSE (Workload Identity in Multi System Environments) space addressing a "connected flight" scenario — probably workload identity for connected aircraft or in-flight systems. Approximate; to be grounded from the official Abstract next run.

2026-09-26 27 drafts

draft-intra-handshake-fail-46 Individual rev -46

Per its datatracker title, "Intra-handshake (aka Early) Attestation Considered Harmful". The document argues against performing attestation during (early in) a handshake and references associated CVEs. This is a rapidly revised individual submission; approximate, to be grounded from the official Abstract next run.

By its name, an NFSv4 working-group document adding an "uncacheable" attribute for directories in NFSv4.2 — a companion to the recently approved uncacheable file-data attribute. Approximate; to be grounded from the official Abstract next run.

By its name and companion projects, defines a ZTDS (zero-trust data sanitization) protocol, apparently aimed at in-memory sanitization for AI/agent systems. Approximate; to be grounded from the official Abstract next run.

draft-hoffman-duj-06 Individual rev -06 abstract

Describes a text format called "DNS Update with JSON" (DUJ). Service providers such as certificate authorities and social-media platforms often need users to update their DNS zones to prove control or enable features, and today they convey this in prose describing record types and values. DUJ instead provides a JSON text that a service provider gives to a user, who copies and pastes it to their DNS operator to update the zone. DNS operators that understand DUJ strings can make the update process easier and more predictable for their users.

draft-crovia-tacet-01 Individual rev -01

By its name and companion materials, TACET defines verifiable "silence proofs" and a cryptographic receipt/audit approach (the "Crovia" canon) for AI output provenance. Approximate; to be grounded from the official Abstract next run.

draft-shabazz-http-x402-tswp-00 Individual new -00

By its name, an individual submission relating HTTP 402 (Payment Required) to a "TSWP" mechanism, likely in the agentic-payments space. Details are not available from a fast source; approximate, to be grounded from the official Abstract next run.

draft-zambo-aer1-01 Individual rev -01

By its name alone ("AER1"), the subject cannot be reliably determined without the official Abstract. Approximate placeholder; to be grounded next run.

draft-schrock-canonical-action-identifier-03 Individual rev -03 abstract

Defines the Canonical Action IDentifier (CAID): a typed action object, a canonicalization and digest suite, a compact identifier string, and immutable action-type definitions with required material fields. Authorization, delegation, execution, and audit artifacts often identify an action using format-local content and digests that are not directly comparable across formats; CAID addresses this. It also defines an Action-Mapping Profile for projecting independently verified native artifacts into a common action type, with the closed results EQUIVALENT_UNDER_PROFILE, NOT_EQUIVALENT, and INDETERMINATE. CAID carries no trust semantics and does not establish identity, authority, authorization, execution, safety, or legal reliance.

By its name, an individual submission proposing a registry of celestial bodies for deep-space networking (related to the IETF's deep-space / TIPTOP work). Approximate; to be grounded from the official Abstract next run.

Per its datatracker title, the Simple Agent Management Protocol (SAMP) — an individual submission defining a lightweight protocol for managing AI agents. Description approximate (from the title); to be grounded from the official Abstract next run.

By its name, an individual submission in the TIPTOP (deep-space networking) space defining an SNMP profile for deep-space or delay-tolerant environments. Approximate; to be grounded from the official Abstract next run.

draft-wang-ctp-definition-02 Individual rev -02

By its name, an individual submission defining a "CTP" (the acronym is not disambiguated by a fast source). Subject uncertain; approximate placeholder, to be grounded from the official Abstract next run.

draft-wang-cep-02 Individual rev -02

By its name, an individual submission defining a "CEP" protocol, part of the author's suite of agent-accountability protocols. Subject approximate; to be grounded from the official Abstract next run.

draft-wang-coe-02 Individual rev -02

By its name, an individual submission defining a "COE" protocol within the same agent-accountability suite. Subject approximate; to be grounded from the official Abstract next run.

draft-wang-jac-03 Individual rev -03

Per its datatracker title, "JAC: Declared Dependency Chains for Agent Receipts" — a JEP/HJS extension profile that defines declared dependency chains for AI-agent receipts. Description approximate (from the title); to be grounded from the official Abstract next run.

By its name, a receipt profile for the Judgment Event Protocol (JEP) family of agent-accountability documents. Approximate; to be grounded from the official Abstract next run.

By its name, an "action mandate" profile within the JEP family, likely describing how agent action mandates are recorded. Approximate; to be grounded from the official Abstract next run.

By its name, a JEP-family document on semantic interoperability between agent-accountability records. Approximate; to be grounded from the official Abstract next run.

draft-wang-jep-profiles-01 Individual rev -01

By its name, a document defining profiles for the Judgment Event Protocol (JEP). Approximate; to be grounded from the official Abstract next run.

draft-wang-jep-conformance-01 Individual rev -01

By its name, a conformance specification for the Judgment Event Protocol (JEP). Approximate; to be grounded from the official Abstract next run.

Per its datatracker title, defines the Judgment Event Protocol (JEP), an event-recording/accountability layer for AI agents. Description approximate (from the title and companion materials); to be grounded from the official Abstract next run.

draft-prz-lsr-ash-packets-05 Individual rev -05

By its name, an LSR (Link State Routing) individual submission concerning "ASH packets" in link-state routing protocols. Subject approximate; to be grounded from the official Abstract next run.

By its name, a BMWG (Benchmarking Methodology WG) individual submission on benchmarking the memory-integrity of AI agents. Approximate; to be grounded from the official Abstract next run.

draft-ietf-rtgwg-qos-model-16 WG RTGWG rev -16 abstract

Describes a YANG data model for the management of Quality of Service (QoS) in IP networks. The model provides a structured way to configure and manage QoS policies across IP network devices.

draft-ietf-pim-gaap-25 WG PIM rev -25 abstract

Describes a lightweight, decentralized multicast group address allocation protocol called GAAP (Group Address Allocation Protocol, pronounced "gap"). GAAP requires no configuration setup and no centralized services. It runs among group participants that need a unique group address to send and receive multicast packets, letting them allocate addresses cooperatively.

draft-ietf-hpke-hpke-05 WG HPKE rev -05 abstract

Describes Hybrid Public Key Encryption (HPKE), a scheme for public-key encryption of arbitrary-sized plaintexts to a recipient's public key, including a variant that authenticates possession of a pre-shared key. HPKE composes any combination of an asymmetric Key Encapsulation Mechanism (KEM), a key derivation function (KDF), and an AEAD encryption function. It provides concrete instantiations built on widely used, efficient primitives such as ECDH key agreement, HKDF, and SHA-2.

By its name, an individual submission defining an "action evidence boundary" for high-risk agent actions, part of the author's evidence-policy (EP) suite. Approximate; to be grounded from the official Abstract next run.

2026-09-25 29 drafts

Defines a new BGP Metadata Path Attribute (optionally transitive) and Sub-TLVs that let egress routers advertise metadata about attached edge services. Ingress routers in a 5G Local Data Network can use this metadata to make path selections based not only on routing cost but also on the running environment of edge services, improving latency and performance. The extension lets one edge-service location be preferred over others sharing the same anycast IP address for traffic from a specific source such as a given User Equipment (UE).

Per its datatracker title, "Protocol Architects Are Not the Creators of the Internet" — an individual, likely commentary/opinion submission. Description approximate (from the title); to be grounded from the official Abstract next run.

By its name, an individual submission defining routing policy for AI agents (agent routing/authorization). Approximate; to be grounded from the official Abstract next run.

draft-sayre-tppietf-00 Individual new -00

By its name and companion repo ("The Proverbial Printer Impeding Encryption Task Forces"), an individual submission that appears to be satirical/commentary in nature. Description approximate; to be grounded from the official Abstract next run.

draft-intra-handshake-fail-45 Individual rev -45

Per its datatracker title, "Intra-handshake (aka Early) Attestation Considered Harmful". The document argues against performing attestation during (early in) a handshake and references associated CVEs. This is a rapidly revised individual submission; approximate, to be grounded from the official Abstract next run.

draft-hardt-oauth-aauth-protocol-11 Individual rev -11 abstract

Defines the AAuth authorization protocol, in which agents obtain proof-of-possession tokens from auth servers to access resources on behalf of users and organizations. It specifies three token types (agent, resource, and auth), a unified token endpoint with deferred-response support, and cross-domain federation between auth servers. It builds on the AAuth Headers specification, which defines the AAuth-Requirement response header and an HTTP Message Signatures profile.

By its name and companion repo, requests IANA registries for NFSv4 protocol element numbers. Approximate; to be grounded from the official Abstract next run.

draft-intra-handshake-fail-44 Individual rev -44

Per its datatracker title, "Intra-handshake (aka Early) Attestation Considered Harmful". The document argues against performing attestation during (early in) a handshake and references associated CVEs. This is a rapidly revised individual submission; approximate, to be grounded from the official Abstract next run.

By its name, an individual submission in the WIMSE (Workload Identity in Multi System Environments) space addressing a "connected flight" scenario — probably workload identity for connected aircraft or in-flight systems. Approximate; to be grounded from the official Abstract next run.

draft-poirier-rats-eat-da-11 Individual rev -11 abstract

Defines an attestation Evidence format for device assignment (DA) in confidential computing, expressed as an EAT (Entity Attestation Token) profile. In confidential computing, DA is how a device (e.g., a network adapter or GPU, whether on-chip or behind a PCIe Root Port) is assigned to a Trusted Virtual Machine (TVM); to trust the device, the TVM needs attestation Evidence confirming the device's identity and the state of its firmware and configuration. Because Evidence claims may be consumed by third-party attestation services external to the TVM, the document standardises the Evidence representation for interoperability.

By its name, an individual submission on EST over CoAP for retrieving CA certificates in constrained environments. Approximate; to be grounded from the official Abstract next run.

Per its datatracker title, "Hardware Attestation for Email Sender Verification" — uses hardware attestation (e.g., a TPM) to verify email senders. Description approximate (from the title); to be grounded from the official Abstract next run.

Per its datatracker title, "Agent Identity Registry System: A Federated Architecture for Hardware-Anchored Identity of Autonomous Entities". Description approximate (from the title); to be grounded from the official Abstract next run.

By its name, a companion submission defining resolution of agent identities within the author's hardware-anchored agent-identity framework. Approximate; to be grounded from the official Abstract next run.

By its name, a companion submission applying EPP (Extensible Provisioning Protocol) to agent-identity registration/management. Approximate; to be grounded from the official Abstract next run.

By its name, a companion submission on governance of the agent-identity registry framework. Approximate; to be grounded from the official Abstract next run.

By its name, the problem-statement document for the author's hardware-anchored agent-identity work. Approximate; to be grounded from the official Abstract next run.

By its name, an individual submission in the WIMSE (Workload Identity in Multi System Environments) space addressing a "connected flight" scenario — probably workload identity for connected aircraft or in-flight systems. Approximate; to be grounded from the official Abstract next run.

Per its datatracker title, defines terminology for "IPv6-Only" and "IPv6-Mostly" networks within the v6ops working group. Description approximate (from the title); to be grounded from the official Abstract next run.

draft-housley-asn1-layman-guide-03 Individual rev -03 abstract

A republication of "A Layman's Guide to a Subset of ASN.1, BER, and DER", originally authored and published by RSA Security. It gives an introductory guide to a subset of Abstract Syntax Notation One (ASN.1), the Basic Encoding Rules (BER), and the Distinguished Encoding Rules (DER), with enough background to understand and implement the RSA PKCS family of standards. Change control is transferred to the IETF and the Internet technical community under BCP 78 and BCP 79.

draft-ietf-satp-core-17 WG SATP rev -17 abstract

Describes the Secure Asset Transfer (SAT) Protocol for digital assets. SATP operates between two gateways, each representing its own digital-asset network, to transfer a digital asset from one gateway to the other. The protocol establishes a secure channel between the endpoints and uses a two-phase commit (2PC) to guarantee transfer atomicity, consistency, isolation, and durability.

Per its datatracker title, "Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems". Description approximate (from the title); to be grounded from the official Abstract next run.

Per its datatracker title, defines QUIC "Alternative Server Address" frames, letting a server advertise alternative addresses to a client. Description approximate (from the title); to be grounded from the official Abstract next run.

draft-ietf-jose-deprecate-none-rsa15-06 WG JOSE rev -06 abstract

Updates RFC 7518 to deprecate the JSON Web Signature (JWS) algorithm "none" and the JSON Web Encryption (JWE) algorithm "RSA1_5". It is a short, focused update recording the deprecated status of these long-problematic algorithms; the document was in IETF Last Call for Proposed Standard during this window.

draft-prz-lsr-ash-packets-04 Individual rev -04

By its name, an LSR (Link State Routing) individual submission concerning "ASH packets" in link-state routing protocols. Subject approximate; to be grounded from the official Abstract next run.

draft-kazuho-ccwg-cuback-00 Individual new -00

By its companion repo, "CUBAK" defines CUBIC congestion control driven by the ACK clock. Description approximate; to be grounded from the official Abstract next run.

draft-morrison-mcp-dns-discovery-06 Individual rev -06 abstract

Defines a DNS-based mechanism for discovering Model Context Protocol (MCP) servers, the identity of the organisations operating them, and a cryptographic identity envelope bound to an individual handle published in the same zone. Three TXT records are specified: "_mcp" advertises an MCP server's endpoint, agent protocol family, transport binding, cryptographic identity, and capability profile; "_org-alter" advertises the operator's canonical organisational identity; and "_alter" publishes an Ed25519-signed envelope binding a handle to a public key and a revocation commitment. DNSSEC validation is required for the envelope record, and a DANE TLSA pin is required where resolving an envelope and opening an MCP session form one transaction. Revision 06 adds a key-continuity rule for the "_mcp" record. The mechanism complements HTTPS-based discovery and follows the precedent of DKIM, SPF, DMARC, and MTA-STS.

By its name, an individual submission defining an "action evidence boundary" for high-risk agent actions, part of the author's evidence-policy (EP) suite. Approximate; to be grounded from the official Abstract next run.

draft-ietf-scone-protocol-09 WG SCONE rev -09 abstract

Defines a method for on-path network elements to signal to endpoints that rate-limiting policies are in force on a flow, and what that rate limit is. The Standard Communication with Network Elements (SCONE) protocol lets endpoints learn about applied rate limits so they can adapt their behaviour accordingly.