freenode

← digests

IETF SSH post-quantum clash and AI agent auth drafts

Internet & Protocols2026-08-22

Heated debate over post-quantum signature adoption dominated the SSH working group while several other IETF groups advanced authentication, HTTP, and attestation drafts. A new Proposed Standard, an IAB workshop call, and governance discussions on list moderation completed the day's protocol activity.

SSH WG call for ML-DSA signature drafts

The IETF SSH working group ran a call for adoption of hybrid and pure ML-DSA signature drafts that closed August 17. The thread produced 97 messages from 35 participants and turned heated as Daniel J. Bernstein and the chairs clashed over safety arguments and new AI cryptanalysis. Developers tracking post-quantum transitions for remote access need to watch whether the safety objections block or reshape adoption.

Moderators debate archiving held messages

The mod-discuss list examined procedures for handling held messages that should not be sent to the list, focusing on archiving posts from disruptive participants. Fifty messages from 19 people included off-topic escalation and renewed calls for stronger moderation. List operators and working-group chairs have a direct stake in how the IETF records or discards such traffic.

WIMSE call for AI agent authentication draft

The WIMSE working group opened a call for adoption of draft-klrc-aiagent-auth on AI agent authentication and authorization. Thirty-five messages from 29 participants centered on the distinction between agent and workload identity and on the structure of delegation chains. The outcome will influence how autonomous agents obtain and propagate credentials in networked systems.

SEAT disputes attested TLS threat model basis

The SEAT working group debated whether the Identity-crisis and Intra-handshake.fail papers can serve as the foundation for an attested TLS threat model and security properties. The fifty-message exchange among 13 participants grew heated. Designers of attested TLS extensions require settled threat assumptions before protocol work can proceed cleanly.

RFC 10036 standardizes incremental HTTP forwarding

The IETF published RFC 10036 as a seven-page Proposed Standard. It defines an Incremental HTTP header for use by intermediaries. Proxy and cache implementers gain a uniform mechanism for incremental message forwarding.

IAB workshop call on post-quantum authentication

The IAB issued a call for papers for an October 2026 workshop on accelerating deployment of post-quantum authentication. The event will examine barriers to post-quantum signature rollout. Practitioners facing migration obstacles now have a formal venue to document them.

OAuth call for RAR metadata adoption

The OAuth working group started a call for adoption of the OAuth 2.0 RAR Metadata and Error Remediation draft. Early reactions from 14 of 22 participants across 24 messages were unanimously supportive. Authorization-server and client developers may obtain clearer metadata and error handling for rich authorization requests.

SCITT coverage attestation profile under review

A new informational draft defining the Coverage Attestation Profile was posted to the SCITT list with an explicit request to break it. Twelve messages from six participants quickly exposed schema and model inconsistencies plus divergence among verifiers. Consistent coverage attestations matter for supply-chain integrity systems that rely on SCITT.