freenode

← digests

Attested TLS models, cert constraints, SSH PQ codes

Internet & Protocols2026-08-31

IETF working groups focused on security protocol properties, certificate handling, and adoption calls across TLS attestation, PKIX, SSH, and routing. Technical disputes and redesign proposals dominated the higher-traffic threads.

SEAT threat model for attested TLS

The SEAT working group debated whether the Identity Crisis and intra-handshake.fail papers supply a suitable threat model and security properties for attested TLS. Participants disputed the formal ProVerif analysis attached to the discussion. Readers building or reviewing TLS attestation need clarity on these properties before implementations diverge.

LAMPS name constraints for DNS wildcards

LAMPS discussed fixes to RFC 5280 name constraints when DNS wildcards appear in subject alternative names, centered on the leafy-greens draft. Technical feedback examined how constraints should be applied and interpreted. Certificate path validators and CA software depend on unambiguous rules to avoid broken or overly permissive chains.

SSH ML-DSA code points pending merge

An IANA request for SSH public key algorithm name code points covering ML-DSA remains held until a related draft merge completes. A Go implementer asked the designated experts to reactivate processing. Post-quantum SSH deployments require the registrations before interoperable algorithm identifiers can ship.

LSR power-group adoption call

LSR ran a working group adoption call for draft-many-lsr-power-group-03 that closed on 2026-08-30. Reviewers raised technical questions on oscillation behavior, TLV usage, and the boundary between path computation and sleep management. Operators exploring power-aware routing will watch whether the draft advances.

ACME public-key draft redesign

ACME examined a redesign of draft-geng-acme-public-key so it fits the RFC 8555 authorization and order state machine by introducing a new proof-of-possession identifier type. Discussion centered on alignment with existing flows rather than parallel machinery. ACME client and server authors need a coherent state model before deploying public-key challenges.

DKIM2 gaps with non-participating nodes

The ietf-dkim list debated whether the DKIM2 draft creates interoperability gaps when legacy nodes modify messages and break signature chains, treating the issue as more than local policy. Participants argued over required behavior in mixed deployments. Mail operators planning DKIM2 rollouts must handle partial adoption without silent failures.

Deepspace single versus multiple RIR models

The deepspace working group compared aggregation behavior under single-RIR versus multiple-RIR IPv6 allocation models for celestial bodies. Debate focused on how prefixes would aggregate and scale in each approach. Implementers of space networking stacks face allocation choices that directly affect routing table growth.

CBOR serialization working group last call

CBOR opened and then extended working group last call on the serialization draft, drawing comments on bstr wrapping and data-model boundaries. Feedback remained routine and technical. CBOR library maintainers should track the final serialization rules as they stabilize.