IETF protocols: OAuth adoption calls and TE disputes
The OAuth working group advanced two adoption calls while traffic engineering and RADIUS groups saw heated technical disputes. Several other drafts moved through review and last call across IETF areas.
OAuth call for adoption of PoP tokens with HTTP Message Signatures
The OAuth working group issued a call for adoption of a draft defining OAuth Proof of Possession tokens based on HTTP Message Signatures. Fifteen of the seventeen participants expressed support while raising comparison concerns with existing DPoP mechanisms. The outcome will shape sender-constrained token options for OAuth deployments.
Challenge to distributed power-aware traffic engineering
Aijun Wang argued that distributed power-aware traffic engineering is impossible during discussion of draft-many-teas-power-steering. Authors defended metric-modified CSPF and power-group approaches in a 92-message exchange involving fourteen participants. Operators exploring energy-aware path computation have a direct stake in whether the draft advances.
RADIUS over TLS debate on rejected connections
The radext working group debated whether rejected RadSec connections must close immediately or may use tarpitting against misbehaving clients as part of the final RADIUS/(D)TLS-bis update. Ten participants contributed sixty-nine messages on the operational and defensive tradeoffs. The decision affects how RADIUS servers handle TLS session teardown under attack or misconfiguration.
OAuth call for adoption of Delegated SD-JWT
The OAuth working group opened a call for adoption of the Delegated SD-JWT draft. Early replies from fourteen participants were uniformly supportive. The work extends selective-disclosure JWT capabilities into delegated authorization scenarios.
ACME DNS persistence draft revised to -02
The ACME working group reviewed draft-ietf-acme-dns-persist-02, which changes hashed account URIs and prior-key retention rules. Eight participants discussed threat-model implications of the updates. Certificate automation systems that rely on persistent DNS challenges will need to track the revised security assumptions.
IPv6 application testing draft in working-group last call
The v6ops working group ran last call on draft-ietf-v6ops-ipv6-app-testing-02. Limited technical comments prompted a -03 revision from the authors. Application developers assessing IPv6 readiness will be guided by the final document.
Out-of-band authorization codes for OAuth CLI clients
Justin Richer posted draft-richer-oauth-oob-authcode-00 covering out-of-band authorization codes for command-line clients. Five participants examined UX and security tradeoffs in a short thread. CLI tools that cannot rely on browser redirects may gain a standardized pattern from the draft.
Brief exchange on network devices that spy
A three-message IETF thread compared IoT spying risks to spam and called for verifiable authentication of network machines. The discussion underscores continuing concern over untrusted devices on the network.