IETF protocols: attested TLS, ACME keys, OpenPGP PQ
IETF lists focused on threat modeling for attested TLS, reshaping an ACME public-key draft to match the existing authorization state machine, and advancing post-quantum OpenPGP composites toward last call. A smaller SCITT thread proposed public tracking of independent Vaara conformance runs.
SEAT debates attested TLS threat model scope
The SEAT working group continued a multi-party technical dispute over the threat model and security properties expected of attested TLS, including how far TLS 1.3 assumptions should stretch. Participants argued over whether WeakDH and WeakHash concerns belong in scope and over the validity of formal models drawn from ESORICS and AsiaCCS work. The outcome matters because attested TLS aims to bind channel security to hardware or environment evidence, so an underspecified model would leave implementers without clear guarantees.
ACME public-key draft pushed toward RFC 8555 fit
On the ACME list, discussion of draft-geng-acme-public-key centered on redesigning the proposal so it fits the authorization and order state machine defined in RFC 8555. Contributors examined introducing a new proof-of-possession identifier type rather than extending the draft outside existing ACME flows. Readers tracking certificate automation care because a clean fit would let operators request certificates bound to specific public keys without breaking current ACME clients and servers.
OpenPGP opens last call on NIST PQ composite algorithms
The OpenPGP working group started WG Last Call on draft-ietf-openpgp-nist-bp-comp-04, covering composite ML-KEM and ML-DSA combined with ECDH and ECDSA, with the call scheduled to end 2026-09-09. Early messages showed support and touched on codepoint allocation for the new algorithms. The draft is material for anyone maintaining OpenPGP implementations that must add post-quantum options without abandoning classical elliptic-curve interoperability.
SCITT proposes public Vaara conformance run page
SCITT participants discussed creating a public page that records independent runs of the Vaara conformance vectors, including rows that show disagreement and fixes related to hash chains. The thread stayed small but concrete about making results comparable across implementations. Transparent vector status helps supply-chain transparency deployments verify that distinct SCITT stacks interpret the same test cases consistently.