freenode

← digests

IETF debates PQ signatures, DNSSEC algorithms, and NomCom rules

Internet & Protocols2026-08-19

IETF lists spent the day on post-quantum signature adoption, multi-algorithm DNSSEC rules, and Nominating Committee composition. Several calls for adoption drew heated technical and process objections.

SSH WG call for ML-DSA signature drafts

The SSHM working group ran a call for adoption of hybrid and pure ML-DSA signature drafts that closed on August 17th, generating a large thread with dozens of participants. Daniel J. Bernstein and the chairs clashed over safety arguments and claims involving new AI cryptanalysis. The choice will shape how SSH authenticates peers once quantum-resistant signatures become mandatory.

DNSOP multi-algorithm DNSSEC adoption call

DNSOP opened a call for adoption of draft-huque-dnsop-multi-alg-rules-08, which sets rules for multi-algorithm DNSSEC operation and runs through the end of August. Discussion mixed support with strong objections focused on validator compatibility and post-quantum cryptography implications. Operators need clear multi-algorithm behavior before rolling out additional DNSSEC algorithms at scale.

NomCom gender representation draft under fire

Gendispatch continued debate on draft-knodel-nomcom-gender-representation, which would add a gender opt-in pool and related skips to the IETF Nominating Committee random selection process. Participants argued over composition goals and the draft's effect on existing selection mechanics. The outcome affects who can serve on the body that fills IETF leadership roles.

NFSv4 internationalization last-call dispute

An IETF last-call thread on draft-ietf-nfsv4-internationalization-16 examined Unicode normalization against form-insensitive and form-preserving filename behavior. Contributors debated how NFSv4 should treat names that differ only by normalization form when they cross heterogeneous filesystems. Filename interoperability hinges on whether servers normalize, preserve, or compare without regard to form.

OpenPGP card support for v6 key packets

OpenPGP participants discussed an encoding scheme that would let existing OpenPGP card hardware, limited to 20-byte fingerprint fields, work with modern v6 key packets. The thread focused on practical packing choices that keep current tokens usable. Hardware token users need a migration path that does not strand deployed cards.

Separate SSH chair complaint on ML-KEM guidance

A shorter SSH thread carried a complaint to the SSHM chairs in which Daniel J. Bernstein disputed claims of NSA influence over IETF ML-KEM and ML-DSA guidance and hybrid-mode recommendations. The exchange stayed heated and process-focused. It underscores unresolved trust arguments around post-quantum algorithm selection in the same working group.

SCITT transformation evidence draft update

SCITT authors circulated draft-dogru-scitt-disclosure-evidence-02 on transformation evidence and coverage reconciliation for auditable data disclosure. Discussion centered on terminology fixes and outcome vocabulary. Clearer evidence terms matter for systems that must prove how disclosed data was transformed.

BGP SRv6-MPLS interworking adoption call

IDR ran a working-group adoption call for draft-sa-idr-bgp-srv6-mpls-transport-iw-02 covering BGP SRv6-MPLS transport interworking. One participant flagged a dependency on still-unresolved changes to RFC 9252. Operators planning mixed SRv6 and MPLS cores need the dependency sorted before the draft can advance cleanly.