freenode

← digests

Internet and Protocols: 2026-07-30

Internet & Protocols2026-07-30

IETF and IRTF lists saw technical and governance traffic on attestation security, post-quantum signatures for SSH and DNS, and email authentication status. The highest-volume threads concerned ML-DSA adoption fights and multi-algorithm DNSSEC rules.

Relay attacks in attested TLS handshake bindings

A formal ProVerif analysis finds relay attacks in all intra-handshake attestation bindings for attested TLS. CVE-2026-33697 has been assigned and the work is scheduled for ESORICS. The finding matters for confidential agentic AI systems that rely on these bindings.

SSH WG call for adoption of ML-DSA signature drafts

The IETF SSH WG opened a call for adoption of hybrid and pure ML-DSA signature drafts that ends 17 August. The thread produced 80 messages from 28 participants, with DJB and the chairs clashing over safety arguments and new AI cryptanalysis. The outcome will shape post-quantum SSH deployment paths.

Proposal to relax DELEXT restrictions

Roy Arends proposes relaxing DELEXT so future delegation types can coexist with NS records without requiring DELEG. DNSOP discussion comprised 14 messages from 6 participants. The change would simplify introduction of new DNS delegation mechanisms.

DMARC WG weighs making ARC historic

The DMARC working group is evaluating consensus on marking ARC (RFC 8617) historic and publishing an experiment report. Fifteen messages from 6 participants examined the idea. Operators still using ARC for email authentication need to follow the decision.

SMTPUTF8 syntax rule blocks common Japanese names

A mailmaint thread flags the script-mixing rule in draft-ietf-mailmaint-smtputf8-syntax-04 as blocking common Japanese names and mixed local-part/domain use. Six messages from 4 participants raised the issue. The restriction affects practical internationalized email addressing.

RIPE Atlas tests of ML-DSA-44 DNSSEC

DNSOP participants discussed RIPE Atlas testing of ML-DSA-44 DNSSEC and cited earlier 10-40 percent failure rates caused by large signatures. Fourteen messages from 10 participants examined the results. Signature size remains a concrete obstacle for post-quantum DNSSEC.

Formal complaint against SSH WG chairs

DJB filed a formal complaint alleging consensus and participation rule violations by the SSH WG chairs. The six-message thread from 6 participants was locked after a cross-post. The dispute adds process friction to the post-quantum SSH work.

Multi-algorithm DNSSEC requirements debate

DNSOP continued debate on a multi-algorithm DNSSEC draft covering PQ support and downgrade signaling rules. Twenty-six messages from 11 participants refined the text. Clear multi-algorithm rules are required for orderly DNSSEC algorithm transitions.