freenode

← digests

IETF faces AI draft flood, SMTP TLS dispute, and protocol adoptions

Internet & Protocols2026-09-23

IETF lists spent the day on governance of AI-generated independent drafts, a heated Last Call fight over SMTP confidentiality, and multiple working-group adoption and charter disputes. Protocol work also covered DKIM2 key fields, OAuth proof-of-possession, power-aware traffic engineering, post-quantum TLS, OpenPGP secrets, and SSH public-key hashes.

IETF debates controls on AI-generated independent drafts

Participants on the main IETF list examined a surge of AI-generated independent Internet-Draft submissions often called AI slop. Discussion covered possible mitigations such as detectors, rate limits, and web-of-trust mechanisms. Developers who submit or review drafts have a direct stake in how the IETF filters low-quality automated input without blocking legitimate work.

Last Call dispute over SMTP receivers and TLS

The Emailcore Last Call thread centered on a DISCUSS ballot concerning draft-ietf-emailcore-as and its normative requirement that SMTP receivers must accept mail lacking TLS confidentiality. Fifteen participants produced a heated exchange over whether the requirement should remain. The outcome affects baseline email security expectations for every interoperable MTA.

DKIM2 key validity field and format debate

The DKIM working group continued a long thread on a proposal to add a key validity field for DKIM2. Contributors argued over JSON versus traditional tag=value syntax, citing parser ambiguity and the consensus rules in RFC 7282. Mail authentication implementers need clarity on the chosen format before DKIM2 can advance.

OAuth call for adoption of HTTPSig proof-of-possession tokens

The OAuth WG opened a call for adoption of a draft specifying OAuth Proof of Possession Tokens with HTTP Message Signatures. Opposition focused on overlap with existing DPoP work and resulting interop risks. Token-binding choices here will shape how relying parties prove possession in future OAuth deployments.

TEAS feasibility debate on distributed power-aware TE

The TEAS list debated whether distributed power-aware traffic engineering is feasible in the context of the call for adoption of draft-many-teas-power-steering-01. Technical arguments addressed practical limits of the approach. Network operators evaluating energy-aware path selection depend on whether the working group concludes the model can work.

Charter complaint over TLS ML-DSA and ML-KEM drafts

A charter complaint was filed with the ADs regarding draft-ietf-tls-mldsa and draft-ietf-tls-mlkem, which standardize the ML-DSA and ML-KEM post-quantum algorithms. The TLS WG thread examined whether the work fits the current charter. The resolution will determine how quickly these PQC primitives can become TLS standards.

OpenPGP adoption call for external secrets draft

The OpenPGP WG opened a call for adoption of draft-dkg-openpgp-external-secrets-03, which defines a format for external secret key storage. Early messages showed participant support. Implementers of OpenPGP key management gain a clearer path for separating secret material from primary key rings.

SSH hash stand-ins for post-quantum public keys

The SSH WG discussed using hash stand-ins in place of full public keys to handle the size of post-quantum keys. Notes addressed certificate fingerprint risks and related PQ guidance. SSH implementations facing larger PQ keys need a compact, safe reference method before deployment scales.