freenode

← digests

IETF moves on AI agent auth, CBOR EDN cleanup, and legacy registries

Internet & Protocols2026-08-14

Working groups across the IETF advanced adoption calls and technical debates on identity for AI agents, constrained data notation, preference vocabularies, and legacy IPv4 handling. Several threads also pressed on CDDL validation edge cases, attested TLS threat models, and BGP interworking dependencies.

WIMSE call to adopt AI agent authentication draft

The WIMSE working group opened a call for adoption of draft-klrc-aiagent-auth, which defines authentication and authorization patterns for AI agents. Discussion focused on how agent identity relates to workload identity and on the shape of delegation chains. The outcome will matter for anyone building or securing systems that treat autonomous agents as first-class principals on the network.

CBOR EDN literals draft sheds contested features

Participants on the CBOR list proposed removing the CRI application extension, the unknown-app CPA999 tag, and block comments from draft-ietf-cbor-edn-literals. The goal is to eliminate remaining blockers so the extended diagnostic notation work can reach consensus. Implementers of CBOR tooling and diagnostic formats will want to track which constructs survive.

AI preference vocabulary categories under dispute

The aipref working group debated proposed "AI System Inference" and "AI User Input" categories for its control vocabulary. Contributors disagreed on scope, process ordering, and whether the categories deliver full opt-out coverage. The choices will shape how content owners signal constraints to AI systems that crawl or consume web data.

CDDL integer matching and bignum tags

A CBOR thread examined whether CDDL type #0 must match only major-type-0 integers or must also accept bignum tags, citing RFC 8610 section 2.3.2. The dispute affects validation behavior for schemas that mix compact integers and big numbers. Spec authors and validator writers need a settled reading before implementations diverge further.

Int-area adoption call for legacy IPv4 registries draft

An adoption call is open through 2026-08-21 for draft-vyncke-intarea-legacy-registries-01, which addresses legacy IPv4 IANA registries. Objections centered on IP options handling and on whether the work signals deprecation of IPv4. Operators and registry consumers still dependent on those registries have a direct stake in the result.

SEAT consolidates attested TLS threat model

The SEAT working group worked to consolidate its threat model and security properties for attested TLS. References included formal verification approaches and hardware attestation mechanisms. Parties building confidential or hardware-rooted transport will care how the group bounds attacker capabilities and required guarantees.

VELOCE experiment moves under OPSAWG

A summary of the 8 August 2026 VELOCE meeting reported that the experiment repository has moved under OPSAWG. Follow-on discussion covered use of IANA registries and the conditions under which YANG module updates require new RFCs. Network management developers tracking experimental telemetry or configuration models should note the new home and process expectations.

IDR adoption call for SRv6-MPLS BGP interworking

IDR ran an adoption call for draft-sa-idr-bgp-srv6-mpls-transport-iw-02 covering BGP-based SRv6 and MPLS transport interworking. One participant flagged a dependency on still-unresolved changes to RFC 9252. Operators planning mixed SRv6 and MPLS fabrics need clarity on both the draft and its normative prerequisites.