freenode

← digests

Internet and protocols: attestation flaws and IETF debates

Internet & Protocols2026-09-22

Critical vulnerabilities in confidential-computing attestation drew attention alongside several IETF working-group disputes over email authentication, AI-generated drafts, power-aware traffic engineering, and post-quantum TLS. Adoption calls, charter questions, and document status reviews also advanced across SCITT, v6ops, and emailcore.

Critical attestation flaws in confidential computing

Researchers reported three critical-severity vulnerabilities scoring CVSS 9.0 or higher in two attested-TLS implementations. The UFMRG discussion links the EarlyAttestationBleed findings to the IETF draft-fossati-seat-early-attestation. Implementers of confidential computing and attested handshakes need to assess exposure in early protocol stages.

DKIM2 push for authentic From headers

The DKIM2 working group is debating a mandatory relaxed domain match for the RFC5322.From field on introduction or change. Participants on the ietf-dkim list are examining how strongly the standard should insist that From is authentic. The outcome will shape email authentication requirements intended to limit spoofing.

IETF debate on AI-generated Internet-Drafts

An IETF thread examined how to handle a flood of AI-generated independent submissions after an absurd draft appeared. Contributors disagreed over whether experience with large language models is needed to comment, with the exchange also touching personal relations. The discussion underscores process strain as generative tools reach the standards pipeline.

Dispute over distributed power-aware TE

The TEAS working group debated the feasibility of distributed power-aware traffic engineering during a call for adoption of draft-many-teas-power-steering-01. A lengthy technical thread questioned whether the approach is possible at all. Operators and vendors tracking energy-aware networking have a direct stake in the result.

SCITT agenda and possible re-chartering for IETF 127

The SCITT working group is planning its IETF 127 agenda, with requests for time on interoperability results and re-chartering to add generic statement-relation semantics. Multiple participants contributed proposals for session time. The decisions will set near-term scope for supply-chain integrity transparency work.

Mandatory ULA generation in rfc7084bis CE routers

The v6ops working group is reviewing draft-ietf-v6ops-rfc7084bis status and whether unique local address generation should be mandatory for customer-edge routers. Multihoming concerns feature prominently in the discussion. The choice affects IPv6 deployment guidance for home and small-office gateways.

IESG DISCUSS on emailcore cleartext requirements

An IESG DISCUSS on draft-ietf-emailcore-as prompted debate over MUST text that would require SMTP receivers to accept cleartext mail. The last-call thread examined Roman's position and overall document status. Core email protocol work needs resolution on backward-compatibility obligations.

Charter complaint on TLS post-quantum drafts

A charter-violation complaint to the area directors concerning draft-ietf-tls-mldsa and draft-ietf-tls-mlkem triggered heated debate on the TLS list. Security-regression arguments were exchanged between Mattsson and Bernstein. The dispute may influence how post-quantum algorithms proceed in TLS standardization.