IETF protocols: attestation flaws, SMTP debate, PQ hybrids
Security disclosures in confidential computing attestation and a lengthy last-call dispute over SMTP encryption requirements dominated IETF traffic. TLS consensus on post-quantum hybrids and several working-group adoption moves rounded out the day.
Critical flaws in attested-TLS implementations
Researchers reported three critical-severity vulnerabilities of CVSS 9.0 or higher in two attested-TLS implementations under the name EarlyAttestationBleed. The findings are tied to the IETF draft-fossati-seat-early-attestation. Confidential-computing and attested-TLS implementers have immediate reason to examine the affected paths.
Emailcore last-call dispute on unencrypted SMTP
A last-call thread of more than 130 messages debated whether the emailcore-as draft must require SMTP implementations to accept unencrypted mail. Roman's DISCUSS position drove heated exchanges among 26 participants. The resolution will set baseline expectations for email security in the core specifications.
TLS WG confirms PQ+T signatures consensus
TLS working-group chairs sought list confirmation of IETF 126 poll results favoring work on PQ+T hybrid signatures and composite-mldsa only. Twenty-seven participants contributed to the 35-message thread. The confirmation clears procedural ground for post-quantum signature work in TLS.
No-Vary-Search reaches Proposed Standard
The IETF advanced The No-Vary-Search HTTP Caching Extension to Proposed Standard. Two browser implementations already exist. Cache authors gain a standardized means to ignore nominated search parameters when deciding cache hits.
DTN adoption call for BPv7 Echo Service
The DTN working group opened an adoption call for the BPv7 Echo Service draft. Minor debate arose over service-number reuse among the twelve participants. Delay-tolerant networking developers should track whether the draft is taken on as a working-group item.
OAuth call for adoption of Delegated SD-JWT
The OAuth working group issued a call for adoption of the Delegated SD-JWT draft. Early replies from nine participants were uniformly supportive. The work extends selective-disclosure JWT patterns into delegated settings of interest to authorization-server implementers.
Draft on DPoP presentation of issuer-signed JWTs
A new individual draft proposes presenting issuer-signed JWT credentials to resource servers with DPoP, with AI agents cited as a use case. Discussion among three participants questioned novelty and fit. OAuth developers evaluating agent authentication flows may wish to follow the thread.
OAuth clarification on authorization-code exfiltration
The OAuth working group clarified poll results on whether authorization-code exfiltration is a problem the group wants to solve. Fourteen messages from three participants continued the exchange. The clarification helps set near-term priorities for the working group.