Attestation bugs and IETF protocol disputes
Security researchers disclosed critical flaws in attested TLS for confidential computing while IETF working groups debated power-aware traffic engineering, RADIUS defenses, and email requirements. Several drafts on DKIM, ACME, and IPv6 testing also advanced under review.
Critical Flaws in Attested TLS Implementations
Researchers reported three critical-severity vulnerabilities with CVSS scores at or above 9.0, termed EarlyAttestationBleed, in two attested-TLS implementations used for confidential computing. The findings tie directly to the IETF draft-fossati-seat-early-attestation discussed on the UFM RG list. Implementers of secure attestation and confidential computing stacks should evaluate exposure given the severity ratings.
Challenge to Distributed Power-Aware TE
Aijun Wang argued that distributed power-aware traffic engineering is impossible while commenting on the call for adoption of draft-many-teas-power-steering. Draft authors defended metric-modified CSPF and power groups across a heated 91-message thread involving 13 participants. Operators tracking TEAS energy-efficiency work need to follow whether the approach remains viable.
RADIUS TLS Rejection Handling Dispute
The radext working group debated final updates to RADIUS/(D)TLS-bis over whether rejected RadSec connections must close immediately or may allow tarpitting as defense against misbehaving clients. Ten participants produced 67 messages in the exchange. RADIUS server operators gain clarity on permitted defensive behaviors for abusive connection attempts.
Cleartext SMTP Support Debate in Emailcore
The emailcore working group disputed a paragraph in draft-ietf-emailcore-as section 6.5 that requires cleartext SMTP support alongside TLS, drawing on mail statistics during last-call discussion. Twenty-three messages from ten participants examined the requirement. Email software maintainers should watch whether dual cleartext and TLS mandates survive.
DKIM Header Size Limits BCP Proposal
Participants on the ietf-dkim list proposed BCP text for operators noting header size limits and truncation risks from growth in Message-Instance and DKIM2-Signature fields. The technical thread spanned 14 messages from eight people. Mail operators running DKIM deployments need awareness of expanding header constraints.
Widespread Mail Submission Password Guessing
John Levine reported a sudden password-guessing flood against his port-465 submission server originating from more than 1200 networks. The mailop discussion covered the scale and sudden onset of the activity. Submission server operators should strengthen authentication controls against similar distributed attacks.
ACME DNS Persist Draft Revisions
The acme working group reviewed draft-ietf-acme-dns-persist-02, which alters hashed account URIs and prior-key retention while examining threat model implications. Eight participants contributed 14 messages on the changes. ACME clients and certificate authorities using DNS persistence should assess the updated design.
IPv6 Application Testing Draft Last Call
The v6ops working group ran a last call on draft-ietf-v6ops-ipv6-app-testing-02 ending 2026-09-18, which drew limited technical comments and prompted a -03 revision. Fourteen messages from eight participants addressed the text. Developers validating IPv6 application behavior can use the advancing guidance for testing practices.