freenode

← digests

IETF security debates and working group advances

Internet & Protocols2026-10-08

IETF working groups spent the day on attestation security disputes, DNS operations restructuring, and post-quantum consensus calls. Several last calls and fine-grained authorization proposals also advanced across protocols.

SEAT debates early attestation security

The SEAT working group continued a heated dispute over early and intra-handshake attestation, citing formal models and a cluster of high-severity CVEs including several rated 9.1. Participants examined whether the approach introduces systemic risks ahead of further expected disclosures. Protocol designers following attestation standards have reason to track the outcome, given the breadth of affected surfaces.

DNSOP splits into OPS and INT groups

DNSOP announced a structural split into separate operations and interoperability working groups along with chair changes, while naming discussions remain open. The move aims to clarify scope after sustained workload growth. Operators and implementers of DNS protocols will see clearer venues for future work.

OAuth seeks interest in fine-grained authorization

The OAuth working group issued a call for interest in fine-grained authorization, framed as follow-up from IETF 126 and aimed partly at AI agent use cases. Discussion referenced existing drafts on missions and RAR remediation. Developers building constrained authorization systems should note the emerging direction.

TLS confirms PQ+T hybrid signature consensus

The TLS working group ran a list consensus call on adopting one post-quantum plus traditional hybrid signature draft, building on polls from IETF 126. Broad participation reflected sustained interest in hybrid designs. Implementers preparing for quantum-resistant TLS handshakes gain a clearer path once the call closes.

MLS last call on post-quantum ciphersuites

A second working group last call opened for the MLS post-quantum ciphersuites draft, scheduled to end 2026-10-15, and drew mostly positive responses plus one typo correction. The draft defines cipher suites suitable for messaging layer security under quantum threats. Messaging protocol maintainers have a short window to register final comments.

MoQT draft proposes URI resolution rules

A new draft on MoQT discovery was proposed to define URI resolution and TLS certificate matching behavior. Working group discussion focused on appropriate scope and normative references. Contributors to media-over-QUIC transport can shape how endpoints locate and authenticate sessions.

CBOR last call covers serialization profiles

The CBOR working group opened last call on a draft defining preferred-plus and deterministic serialization forms, closing 2026-10-19, accompanied by technical corrections and profiling debate. The text aims to reduce ambiguity for constrained and deterministic encodings. Applications relying on canonical CBOR have a chance to refine the rules before advancement.

WIMSE refines agent delegation chain draft

Authors of the WIMSE agent delegation chain draft iterated on scope grammar and verifier rules after an IANA defect report, extending support for OAuth provider literals. The exchange stayed technical and focused on vocabulary precision. Parties implementing workload identity and multi-agent delegation should watch the revised text.