freenode

← digests

TLS verification milestone and protocol WG debates

Internet & Protocols2026-09-08

Formal methods progress on TLS and several working group debates over security requirements, traffic engineering feasibility, and post-quantum updates shaped Internet protocol activity. Adoption calls and last calls advanced alongside disputes on design constraints.

Verifpal verifies detailed TLS 1.3 model

Nadim Kobeissi announced that Verifpal 1.4.6 completed symbolic verification of a detailed TLS 1.3 model that includes concurrent sessions and staged compromise. The work was reported to the UFRMG and TLS lists. Protocol implementers and security analysts gain a stronger formal baseline for assessing TLS session handling under concurrent and compromised conditions.

SEAT debates shared secrets for TLS binders

The SEAT working group continued a heated exchange on guidance text for draft-ietf-seat-use-cases, focusing on whether mandatory shared secrets in TLS binders are required to prevent relay attacks. Participants cited papers and formal models on both sides. The outcome will affect how relay-resistant authentication is specified for TLS extensions.

TEAS questions distributed power-aware traffic engineering

A call for adoption of draft-many-teas-power-steering (ending 2026-09-10) triggered technical debate in the TEAS working group over whether distributed power-aware traffic engineering is feasible. Several participants argued the approach is impossible under realistic constraints. Operators and routing designers concerned with energy-aware TE need to track whether the draft proceeds.

OpenPGP last call for post-quantum composite algorithms

The OpenPGP working group opened last call on draft-ietf-openpgp-nist-bp-comp-04 (ending 2026-09-09), covering composite ML-KEM/ML-DSA combined with ECDH/ECDSA. Early support appeared along with discussion of codepoint allocation. The draft moves hybrid post-quantum cryptography closer to standardization in OpenPGP.

IETF extends RFC editing SLA consultation

The IETF announced an extension of the consultation period on a Service Level Agreement for RFC Editing and Publication. The existing RFC Production Center metrics are viewed as outdated relative to current workload. Community members involved in document production retain additional time to submit feedback on replacement terms.

DKIM2 key-expiry tag under discussion

Participants on the IETF DKIM list debated a proposal to add an e= key validity (expiry) field for DKIM2, along with risks of JSON header parsing. No clear consensus emerged. Developers maintaining DKIM implementations should watch for any shift toward mandatory expiry handling.

DTN adoption call for BPv7 Echo Service

The DTN working group opened an adoption call for the BPv7 Echo Service draft, running through 21 September 2026. Minor discussion addressed choice of service number to avoid conflict with DTPC. Delay-tolerant networking implementers have a window to review and comment before the call closes.