<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
    <channel>
        <title>Recent RFCs</title>
        <link>https://www.rfc-editor.org</link>
        <description>Recently published RFCs</description>
        <lastBuildDate>Wed, 15 Jul 2026 22:25:21 GMT</lastBuildDate>
        <docs>https://validator.w3.org/feed/docs/rss2.html</docs>
        <generator>https://www.npmjs.com/package/feed</generator>
        <language>en-us</language>
        <item>
            <title><![CDATA[RFC 9954: Hybrid Key Exchange in TLS 1.3]]></title>
            <link>https://www.rfc-editor.org/info/rfc9954/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9954/</guid>
            <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Hybrid key exchange refers to using multiple key exchange algorithms simultaneously and combining the result with the goal of providing security even if a way is found to defeat the encryption for all but one of the component algorithms. It is motivated by the transition to post-quantum cryptography. This document provides a construction for hybrid key exchange in the Transport Layer Security (TLS) protocol version 1.3.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9933: Carrying SR-Algorithm in Path Computation Element Communication Protocol (PCEP)]]></title>
            <link>https://www.rfc-editor.org/info/rfc9933/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9933/</guid>
            <pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[This document specifies extensions to the Path Computation Element Communication Protocol (PCEP) to enhance support for Segment Routing (SR) with a focus on the use of Segment Identifiers (SIDs) and SR-Algorithms in Traffic Engineering (TE). The SR-Algorithm associated with a SID defines the path computation algorithm used by Interior Gateway Protocols (IGPs). It introduces mechanisms for PCEP peers to signal the SR-Algorithm associated with SIDs by encoding this information in Explicit Route Object (ERO) and Record Route Object (RRO) subobjects, enables SR-Algorithm constraints for path computation, and defines new metric types for the METRIC object. This document updates RFC 8664 and RFC 9603 to allow such extensions.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9999: Remote ATtestation procedureS (RATS) Conceptual Message Wrapper (CMW)]]></title>
            <link>https://www.rfc-editor.org/info/rfc9999/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9999/</guid>
            <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[<p>The conceptual messages introduced by the Remote ATtestation procedureS (RATS) architecture (RFC 9334) are protocol-agnostic data units that are conveyed between RATS roles during RATS interactions. Conceptual messages describe the meaning and function of such data units within RATS data flows without specifying a wire format, encoding, transport mechanism, or processing details. The initial set of conceptual messages is defined in Section 8 of RFC 9334 and includes Evidence, Attestation Results, Endorsements, Reference Values, and Appraisal Policies.</p><p>This document introduces the Conceptual Message Wrapper (CMW) that provides a common structure to encapsulate these messages. It defines a dedicated Concise Binary Object Representation (CBOR) tag, corresponding JSON Web Token (JWT) and CBOR Web Token (CWT) claims, and an X.509 extension.</p><p>Together, these mechanisms allow CMWs to be used in CBOR-based protocols, web APIs using JWTs and CWTs, and PKIX artifacts such as X.509 certificates. Additionally, this document defines media types and CoAP Content-Formats that may be used to identify CMWs when transported over protocols such as HTTP, MIME, and CoAP.</p><p>The goal is to improve the interoperability and flexibility of remote attestation protocols. Introducing a shared message format such as CMW enables consistent support for different attestation message types, enables the evolution of message serialization formats without breaking compatibility, and avoids the need to redefine how messages are handled within each protocol.</p>]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9919: The Lightweight Online Certificate Status Protocol (OCSP) Profile for High-Volume Environments]]></title>
            <link>https://www.rfc-editor.org/info/rfc9919/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9919/</guid>
            <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[<p>This specification defines a profile of the Online Certificate Status</p><p>Protocol (OCSP) that addresses the scalability issues inherent when</p><p>using OCSP in large scale (high volume) Public Key Infrastructure</p><p>(PKI) environments and/or in PKI environments that require a</p><p>lightweight solution to minimize communication bandwidth and client-</p><p>side processing.</p><p>This specification obsoletes RFC 5019.  The profile specified in RFC</p><p>5019 has been updated to allow and recommend the use of SHA-256 over</p><p>SHA-1.</p>]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9918: Updates to Using the NETCONF Protocol over Transport Layer Security (TLS) with Mutual X.509 Authentication]]></title>
            <link>https://www.rfc-editor.org/info/rfc9918/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9918/</guid>
            <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[RFC 7589 defines how to protect Network Configuration Protocol (NETCONF) messages with TLS 1.2. This document updates RFC 7589 to update support requirements for TLS 1.2 and add TLS 1.3 support requirements, including restrictions on the use of TLS 1.3's early data.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9916: Updates to the Usage of TLS to Provide a Secure Transport for the Path Computation Element Communication Protocol (PCEP)]]></title>
            <link>https://www.rfc-editor.org/info/rfc9916/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9916/</guid>
            <pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Section 3.4 of RFC 8253 specifies TLS connection establishment restrictions for PCEPS; PCEPS refers to usage of TLS to provide a secure transport for the Path Computation Element Communication Protocol (PCEP). This document adds restrictions to specify what PCEPS implementations do if they support more than one version of the TLS protocol and to restrict the use of TLS 1.3's early data.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9995: CBOR Object Signing and Encryption (COSE) Hash Envelope]]></title>
            <link>https://www.rfc-editor.org/info/rfc9995/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9995/</guid>
            <pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[This document defines new CBOR Object Signing and Encryption (COSE) header parameters for signaling a payload as an output of a hash function. This mechanism enables faster validation, as access to the original payload is not required for signature validation. Additionally, hints of the hashed payload's content format and availability are defined, providing references to optional discovery mechanisms that can help to find the original payload content.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9846: The Transport Layer Security (TLS) Protocol Version 1.3]]></title>
            <link>https://www.rfc-editor.org/info/rfc9846/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9846/</guid>
            <pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[<p>This document specifies version 1.3 of the Transport Layer Security (TLS) protocol. TLS allows client/server applications to communicate over the Internet in a way that is designed to prevent eavesdropping, tampering, and message forgery.</p><p>This document obsoletes RFC 8446, which specified TLS 1.3. This document obsoletes RFC 5246 (specifying TLS 1.2) and RFCs 5077, 6961, 7627, and 8422, all of which pertain to TLS 1.2 or earlier, and updates RFCs 5705 and 6066. This document also specifies new requirements for TLS 1.2 implementations.</p>]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 10014: Guidelines for Characterizing the Term "OAM"]]></title>
            <link>https://www.rfc-editor.org/info/rfc10014/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc10014/</guid>
            <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[<p>As the IETF continues to produce and standardize different Operations, Administration, and Maintenance (OAM) protocols and technologies, various qualifiers and modifiers are prepended to the OAM abbreviation. While, at first glance, the most used qualifiers appear to be well understood, the same qualifier may be interpreted differently in different contexts. A case in point is the qualifiers "in-band" and "out-of-band", which have their origins in the radio lexicon, and which have been extrapolated into other communication networks. This document recommends not to use these two terms when referring to OAM.</p><p>This document considers some common qualifiers and modifiers that are prepended, within the context of packet networks, to the OAM abbreviation and lays out guidelines for their use in IETF documents.</p><p>This document extends RFC 6291 by adding to the guidelines for the use of the term "OAM" with qualifiers. It does not modify any part of RFC 6291.</p>]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 10007: Clarification to Processing Key Usage Values During Certificate Revocation List (CRL) Validation]]></title>
            <link>https://www.rfc-editor.org/info/rfc10007/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc10007/</guid>
            <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[RFC 5280 defines the profile of X.509 certificates and Certificate Revocation Lists (CRLs) for use in the Internet. Section 4.2.1.3 of RFC 5280 requires CRL issuer certificates to contain the keyUsage extension with the cRLSign bit asserted. However, the CRL validation algorithm specified in Section 6.3 of RFC 5280 does not explicitly include a corresponding check for the presence of the keyUsage certificate extension. This document updates RFC 5280 to require that check.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9980: Post-Quantum Cryptography in OpenPGP]]></title>
            <link>https://www.rfc-editor.org/info/rfc9980/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9980/</guid>
            <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[This document defines a post-quantum public key algorithm extension for the OpenPGP protocol, extending RFC 9580. Given the generally assumed threat of a cryptographically relevant quantum computer, this extension provides a basis for long-term secure OpenPGP signatures and ciphertexts. Specifically, it defines composite public key encryption based on ML-KEM (formerly CRYSTALS-Kyber), composite public key signatures based on ML-DSA (formerly CRYSTALS-Dilithium), both in combination with Elliptic Curve Cryptography (ECC), and SLH-DSA (formerly SPHINCS+) as a standalone public key signature scheme.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9943: An Architecture for Trustworthy and Transparent Digital Supply Chains]]></title>
            <link>https://www.rfc-editor.org/info/rfc9943/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9943/</guid>
            <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[Traceability in supply chains is a growing security concern. While Verifiable Data Structures (VDSs) have addressed specific issues, such as equivocation over digital certificates, they lack a universal architecture for all supply chains. This document defines such an architecture for single-issuer signed statement transparency. It ensures extensibility and interoperability between different transparency services as well as compliance with various auditing procedures and regulatory requirements.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9942: CBOR Object Signing and Encryption (COSE) Receipts]]></title>
            <link>https://www.rfc-editor.org/info/rfc9942/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9942/</guid>
            <pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[CBOR Object Signing and Encryption (COSE) Receipts prove properties of a Verifiable Data Structure (VDS) to a verifier. VDSs and associated Proof Types enable security properties, such as minimal disclosure, transparency, and non-equivocation. Transparency helps maintain trust over time and has been applied to certificates, end-to-end encrypted messaging systems, and supply chain security. This specification enables concise transparency-oriented systems by building on Concise Binary Object Representation (CBOR) and COSE. The extensibility of the approach is demonstrated by providing CBOR encodings for Merkle inclusion and consistency proofs.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9978: Bidirectional Forwarding Detection (BFD) Stability]]></title>
            <link>https://www.rfc-editor.org/info/rfc9978/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9978/</guid>
            <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[This document describes extensions to the Bidirectional Forwarding Detection (BFD) protocol to measure BFD Stability. Specifically, it describes a mechanism for the detection of BFD packet loss.]]></description>
        </item>
        <item>
            <title><![CDATA[RFC 9974: Operations, Administration, and Maintenance (OAM) Requirements for the Bit Index Explicit Replication (BIER) Layer]]></title>
            <link>https://www.rfc-editor.org/info/rfc9974/</link>
            <guid isPermaLink="true">https://www.rfc-editor.org/info/rfc9974/</guid>
            <pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate>
            <description><![CDATA[<p>This document specifies a list of functional requirements for</p><p>Operations, Administration, and Maintenance mechanisms, protocols,</p><p>and tools that support operations in the Bit Index Explicit</p><p>Replication layer of a network.</p>]]></description>
        </item>
    </channel>
</rss>