freenode

← digests

IETF protocols, AI prefs, and process fights

Internet & Protocols2026-08-08

CBOR EDN cleanup, OpenPGP card encoding for v6 keys, and a new OAuth workload grant led the protocol work, while AI preference categories and an LLM-in-discussions draft drew broader heat. Governance friction continued in SSH and NomCom selection debates.

CBOR EDN draft drops contested extensions

Working group participants proposed removing IANA extensibility for encoding indicators, ellipses, and CPA888 from the EDN literals draft (draft-ietf-cbor-edn-literals). The goal is to eliminate the most controversial features so the document can reach consensus. Readers tracking CBOR tooling and diagnostic notation should watch whether the trimmed scope unblocks adoption.

OpenPGP cards and modern v6 key packets

Participants examined an encoding scheme for 20-byte card fingerprint fields so existing OpenPGP card hardware can support v6 keys. The discussion centers on fitting newer key packet formats onto devices whose interfaces were designed around earlier fingerprint sizes. Hardware-backed OpenPGP users and implementers need a stable mapping before v6 deployment widens.

Workload Authorization Grant draft enters OAuth

An individual draft (draft-carleton-workload-authz-grant) proposes a JWT-based authorization grant aimed at workload and agent scenarios. Early comments focus on overlap and scope boundaries with ID-JAG and existing identity chaining work. OAuth deployers building non-human client flows will want clarity on which document owns which grant type.

NomCom composition and gender quota debate

Gendispatch continued discussion of a draft on IETF Nominating Committee composition, including extension of gender quotas into NomCom selection. Participants weighed privacy protections against the need for public verifiability of the process. The outcome will affect how future leadership slates are formed and audited.

Policy draft for LLMs in IETF discussions

A draft addressing handling of LLM-generated text in IETF discussions drew a large thread seeking concrete policy input. Contributors are trying to define acceptable use, disclosure, and moderation norms before automated text becomes pervasive on mailing lists. Process and tooling participants should track the emerging rules that will govern list traffic.

AI preference vocabulary adds inference and user-input categories

The aipref working group debated new "AI System Inference" and "AI User Input" categories for its vocabulary. Disagreement covers scope, the order of process steps, and whether the categories deliver full opt-out coverage. Sites and AI operators that rely on machine-readable preferences need stable category definitions before implementation.

Formal complaint lodged with SSH WG chairs

Daniel J. Bernstein filed a formal complaint alleging violations of consensus and participation rules by the SSH working group chairs. The thread was locked after cross-posting. SSH protocol stakeholders should note the governance dispute even though technical work is paused in that thread.

SEAT attestation binder and CVE applicability dispute

Authors and reviewers clashed over whether CVE-2026-33697 applies to the revised attestation binder in draft-fossati-seat-early-attestation-06. The argument turns on the exact security properties claimed by the updated design. Early-attestation implementers need a clear resolution before relying on the binder construction.