freenode

← digests

IETF lists: PQ SSH adoption fights, attested TLS models, multi-alg DNSSEC

Internet & Protocols2026-09-01

IETF working groups spent the period on post-quantum signature adoption, attested TLS threat models, and multi-algorithm DNSSEC rules. Heated calls for adoption and formal-analysis disputes set the tone across the major protocol lists.

SSH WG call for ML-DSA signature drafts

The SSH working group ran a call for adoption of hybrid and pure ML-DSA signature drafts. The thread produced roughly seventy messages in which Daniel J. Bernstein and the chairs clashed over safety arguments and newly cited AI cryptanalysis. The result will shape which post-quantum signature algorithms SSH implementations can standardize on.

SEAT threat model dispute for attested TLS

The SEAT working group debated whether the Identity Crisis and intra-handshake.fail papers supply an adequate threat model and properties for attested TLS. Participants also contested the accompanying formal ProVerif analysis across seventy-seven messages. Clarity on the model is required before attested TLS can be specified with confidence.

DNSOP multi-algorithm DNSSEC adoption call

DNSOP opened a call for adoption of draft-huque-dnsop-multi-alg-rules-08. The exchange mixed support with strong objections centered on validator compatibility and post-quantum cryptography implications. Operators planning multi-algorithm DNSSEC deployments need the compatibility questions settled before they can proceed.

LSR power-group draft adoption call

The LSR working group is considering adoption of draft-many-lsr-power-group-03. Technical discussion focused on oscillation risks, TLV usage, and the distinction between path computation and sleep management. Routing engineers evaluating energy-aware extensions have a direct stake in how those points are resolved.

SSH ML-DSA code-point request still held

An IANA request for SSH public-key algorithm code points covering ML-DSA remains on hold pending draft merge. A Go implementer asked the designated experts to reactivate processing. Implementers waiting on registry entries cannot finish post-quantum SSH support until the hold lifts.

Handling AI-generated independent drafts

IETF participants examined the growing volume of AI-generated independent Internet-Draft submissions. Suggestions included separate announcement lists and explicit ISE labeling. The discussion bears on how the community keeps signal separable from low-quality automated input.

DKIM2 gaps with non-participating nodes

The ietf-dkim list debated whether the DKIM2 draft creates an interoperability gap when legacy nodes modify messages and break signature chains. Contributors framed the problem as a protocol gap rather than a matter of local policy. Mail operators assessing DKIM2 must account for these chain-break cases.

SCITT evidence boundaries for agent control

A new individual draft proposes four separated evidence boundaries for agent control delivery and outcome reconciliation. Working-group comments identified a multi-target reconciliation gap and open questions of composition with a related draft. Supply-chain integrity work that involves autonomous agents will need these boundaries clarified.