freenode

← digests

Attestation flaws and IETF protocol debates

Internet & Protocols2026-10-03

Critical flaws in attested TLS implementations led the day's Internet protocol activity, alongside a heated TEAS dispute over power-aware traffic engineering. Working groups also confirmed post-quantum signature work in TLS, advanced MLS cipher suites, and examined OAuth authorization, email encryption signaling, RADIUS connection handling, and deep-space addressing.

Critical EarlyAttestationBleed Flaws in Attested TLS

Researchers reported three vulnerabilities of CVSS 9.0 or higher, named EarlyAttestationBleed, in two attested-TLS implementations. The findings are tied to the IETF draft-fossati-seat-early-attestation. Operators and implementers of confidential computing systems need to assess exposure in early attestation flows.

Challenge to Distributed Power-Aware Traffic Engineering

Aijun Wang argued that distributed power-aware traffic engineering is impossible, challenging the draft-many-teas-power-steering proposal on the TEAS list. Authors defended approaches based on metric-modified CSPF and power groups across a lengthy, heated exchange. The discussion bears on whether networks can practically optimize routing for power consumption in a distributed manner.

TLS Consensus Call on PQ+T Hybrid Signatures

The TLS working group opened a list consensus call to confirm adoption of PQ+T hybrid signature work after polls at IETF 126. Dozens of participants weighed in on the path for combining post-quantum and traditional signatures. The outcome will shape TLS readiness against quantum-capable adversaries.

OAuth Call for Fine-Grained Authorization Interest

The OAuth working group sought interest in fine-grained authorization following IETF 126, with references to existing drafts on missions and RAR remediation. Discussion highlighted use cases such as AI agents. Progress here would refine how delegated, limited-scope access is expressed and enforced.

Distinguishing Sender E2EE from Provider Encryption

Participants on the mailmaint list examined the need for a standard that lets mail user agents distinguish true sender end-to-end encryption from provider encryption-on-arrival or at-rest protection. The thread explored how MUAs should present these differing security properties to users. Clearer signaling would reduce confusion about actual message confidentiality.

MLS Last Call for Post-Quantum Cipher Suites

The MLS working group began a second WG Last Call on draft-ietf-mls-pq-ciphersuites-06, which registers ML-KEM post-quantum cipher suites, closing 2026-10-15. Consensus to advance appears clear. The draft prepares Messaging Layer Security for quantum-resistant key establishment.

RADIUS TLS-bis Debate on Rejected Connections

The radext working group debated final updates to RADIUS/(D)TLS-bis, focusing on whether rejected RadSec connections must close immediately or may apply tarpitting against misbehaving clients. The exchange was heated and extensive. The resolution will affect defensive options for RADIUS over TLS deployments.

Deep-Space IPv6 Address Space Proposal

A new draft proposing IPv6 address space for space environments was introduced on the deepspace list. The ensuing discussion included accusations that some contributions were AI-generated. The work addresses long-term addressing needs for communications beyond terrestrial networks.