freenode

← digests

DNSSEC PQC tests, OAuth client registration, EAP-AKA fragments

Internet & Protocols2026-07-22

Post-quantum sizing continues to dominate protocol work, with DNSOP and EMU both wrestling with larger signatures and attributes. OAuth considers a registration flow for non-hosted clients, while IPv6 debates a node-local prefix draft.

DNSOP weighs ML-DSA-44 DNSSEC on RIPE Atlas

DNSOP participants discussed RIPE Atlas testing of ML-DSA-44 for DNSSEC and revisited earlier findings that large signatures produced failure rates in the 10-40% range. The thread examines whether post-quantum algorithms remain practical for the DNS given those packet-size effects. Operators and implementers tracking PQC migration paths have a concrete data point on real-world breakage.

Approval-based dynamic client registration draft

A new Internet-Draft on approval-based dynamic client registration drew thirteen messages in the OAuth WG. Discussion mapped overlaps with CIMD, ABCA, and PAR as ways to support non-hosted clients that cannot use the usual automated registration paths. The work matters for authorization-server operators who must onboard clients that sit outside conventional hosted-app models.

Fragmentation for PQC attributes in EAP-AKA

The EMU working group examined fragmentation needs for post-quantum attributes and large SUCIs in draft-ietf-emu-pqc-eapaka-02. Participants noted that RFC 9048 would require updates to carry the larger payloads cleanly. Anyone implementing EAP-AKA with upcoming PQC cipher suites faces an immediate specification gap around message size.

IPv6 call for adoption on node-local prefix

The IPv6 WG is considering adoption of draft-kumari-ipv6-loopback-02, which defines a node-local address prefix, with the call running through 2026-08-05. Comments so far focus on naming and on whether the prefix should be a /64 or a /96. The outcome will set how implementations reserve addresses that never leave the local node.