freenode

← digests

TLS hybrids, attestation flaws, and IETF protocol disputes

Internet & Protocols2026-09-29

IETF working groups advanced post-quantum TLS signature choices and reviewed critical attestation flaws while debating power-aware traffic engineering and email core requirements. Adoption calls and design threads also moved on OAuth proof-of-possession, deep-space addressing, mail encryption signals, and DTN echo services.

TLS consensus call on hybrid PQ signatures

The TLS working group is running a consensus call on adopting one post-quantum plus traditional hybrid signature draft. Opinions remain split between composite schemes and dual certificates. The choice will set the direction for quantum-resistant authentication in future TLS deployments.

Critical flaws in attested-TLS confidential computing

Researchers reported three critical-severity vulnerabilities scoring CVSS 9.0 or higher in confidential computing stacks. Two attested-TLS implementations are affected, and the findings are tied to the IETF draft-fossati-seat-early-attestation. Operators and implementers of early-attestation flows need to assess exposure in their environments.

Challenge to distributed power-aware traffic engineering

Aijun Wang argued that distributed power-aware traffic engineering is impossible and challenged draft-many-teas-power-steering. Authors defended metric-modified CSPF and power groups across a lengthy exchange. Network operators evaluating energy-aware routing should track whether the draft proceeds.

Last-call dispute on unencrypted SMTP acceptance

A large last-call thread debated whether the emailcore-as draft must require SMTP implementations to accept unencrypted mail, centering on a DISCUSS from Roman. The outcome will determine mandatory cleartext support for emailcore-compliant servers. Email protocol developers require a clear resolution before implementation.

OAuth adoption call for HTTP Message Signatures PoP

The OAuth working group opened a call for adoption of a draft defining proof-of-possession tokens with HTTP Message Signatures. Participants expressed support while raising comparisons to existing DPoP mechanisms. API security designers should watch the result for impacts on token binding approaches.

IPv6 address space proposal for deep-space networks

A new combined draft proposes dedicated IPv6 address space for space networking on the deepspace list. The discussion includes accusations that some contributions are AI-generated. Researchers building delay-tolerant or space-oriented stacks will want clarity on the addressing model.

Distinguishing E2EE from encryption-on-arrival in mail

The mailmaint working group examined signaling so mail user agents can tell true end-to-end encryption from server-side encryption-on-arrival. Design options for the indicator were discussed. MUA implementers need reliable cues to avoid misleading users about message protection.

DTN adoption call for BPv7 Echo Service

The DTN working group is holding an adoption call for the BPv7 Echo Service draft. Minor debate focused on service number reuse. Delay-tolerant networking developers should evaluate whether the service meets operational diagnostic needs.