freenode

← digests

IETF protocols: IPsec SA failures, OpenPGP secrets, adoption calls

Internet & Protocols2026-09-06

IETF lists saw sustained technical debate on failure signaling, key storage, and several working-group adoption calls. Activity concentrated on IPsec Child SA handling under post-quantum costs, OpenPGP external secrets, and related protocol drafts.

IPsec TEMPORARY_FAILURE for Child SA in IKE_AUTH

The ipsec list continued an ongoing discussion of failing a Child SA with a TEMPORARY_FAILURE response during IKE_AUTH. Participants examined fast-refusal notify payloads intended to avoid wasted post-quantum cryptography signatures when simultaneous SAs collide. Implementers of IKEv2 stacks have a direct stake in how concurrent establishment is refused.

OpenPGP external secrets draft call for adoption

The OpenPGP working group opened a call for adoption of draft-dkg-openpgp-external-secrets-03, closing 2026-09-18. The draft defines a format for external secret key storage, and early messages showed participant support. Maintainers of OpenPGP implementations have a window to review the storage model before the deadline.

NFSv4 uncacheable directories scoping review

A non-WGLC review of draft-ietf-nfsv4-uncacheable-directories-10.txt proceeded on the nfsv4 list. A reviewer proposed alternative scoping for the uncacheable flag while the author defended the existing framing. The exchange clarifies how directory caching behavior will be expressed in NFSv4.

DISPATCH guidance sought for SMTP SENDAUTH

An author asked the DISPATCH list for venue guidance on a SENDAUTH draft that would add per-message WebAuthn verification to SMTP submission. Twelve participants raised questions about need, deployment feasibility, and whether the work belongs in the IETF. The volume of replies signals substantial skepticism on scope and practicality.

SEAT use-cases MUST language dispute

The SEAT working group debated proposed MUST statements for evidence binding in draft-ietf-seat-use-cases. Disagreement centered on shared secrets and the inclusion of CVE references. The outcome will shape normative requirements for attestation evidence.

GROW call for BGP DOWNGRADE community

The GROW working group issued a call for adoption of draft-spaghetti-grow-downgrade-bgp-community-00, ending 2026-09-18. The draft defines a BGP DOWNGRADE community for DoS mitigation. Network operators concerned with routing-based defenses can still comment before the cutoff.

RATS geographic results adoption call

The RATS working group ran an adoption call for draft-richardson-rats-geographic-results. Multiple participants voiced support along with minor technical comments. The draft would extend remote attestation result formats with geographic information.

DKIM2 key validity field proposal

A participant proposed a separate key-expiration tag and flat encoding for DKIM2. Working-group members observed that the DKIM1 design has functioned for fifteen years and that JSON is not used in DNS. The thread revisits established key-management conventions for email authentication.