freenode

← digests

IETF PQ advances and protocol disputes

Internet & Protocols2026-10-06

IETF groups moved post-quantum work forward in TLS and MLS while debating RADIUS connection handling and SEAT attestation timing. New drafts and a proposed benchmarking working group also drew early review.

TLS consensus call on PQ hybrid signatures

The TLS working group is running a list consensus call on adopting PQ+T hybrid signature work after polls at IETF 126. The thread drew 53 messages from 41 participants. Implementers preparing TLS for quantum threats need the outcome to guide hybrid signature support.

MLS last call for PQ cipher suites

The MLS working group opened a second WG Last Call on draft-ietf-mls-pq-ciphersuites-06, which registers post-quantum ML-KEM cipher suites and ends 2026-10-15. Clear consensus favors advancement across 13 messages from 12 participants. Messaging layer deployments seeking quantum-resistant key exchange should track the draft.

radext dispute on RadSec rejection handling

The radext working group debated a final update to RADIUS/(D)TLS-bis over whether rejected RadSec connections must close immediately or may use tarpitting against misbehaving clients. The heated exchange produced 70 messages from 10 participants. RADIUS operators relying on TLS transport must watch how defensive options are specified.

SEAT debate on early attestation value

The SEAT list debated whether intra-handshake attestation adds security properties beyond post-handshake binding, citing multiple high-CVSS CVEs and related drafts. Fourteen messages from three participants examined the claims. Designers of handshake attestation need to weigh the relay-attack arguments raised.

IESG reviews proposed BPM working group

The IESG announced community review of a proposed Benchmarking and Performance Measurements (bpm) working group charter covering network benchmarking metrics. The single announcement opens the charter for input. Parties defining performance measurement methods gain a potential dedicated standards venue.

Dispatch reviews RFC 4086 bis draft

Initial reviews of draft-rsalz-4086bis-00, an update to RFC 4086, showed disagreement on scope and approach among five participants on the dispatch list. Eight messages followed the new version notification. Guidance on randomness generation could shift if the draft advances with a settled scope.

SEAT post flags early attestation CVEs

A single SEAT post agreed with analysis that early attestation enables relay attacks and listed high-CVSS CVEs, including several rated 9.1 and others expected higher. The note aligns with the broader attestation thread. Reviewers of attestation mechanisms should examine the cited vulnerability set.

ACME reviews dns-persist draft changes

The ACME working group reviewed draft-ietf-acme-dns-persist-02, covering changes to hashed account URIs, prior-key retention, and threat model implications. Seventeen messages from nine participants addressed the updates. Certificate automation systems using DNS persistence need to follow the refined requirements.