IOTOPS at IETF 126 Vienna

Monday 20 July 2026
07:00 (UTC)/ 09:00 (Vienna)
2 hours

Meetecho: https://meetings.conf.meetecho.com/ietf126/?session=35509
Notes: https://notes.ietf.org/notes-ietf-126-iotops
Chairs: Alexey Melnikov and Henk Birkholz

Note taker: Christian Amsüss

09:00 Administrivia

(5 mins; chairs)

AM doing introductions

Ownership and licensing statements in YANG

draft-ietf-iotops-ol
(10 mins; Eliot Lear)
slides

EL presenting.

EL, summarizing: Document is stupid simple, should do WGLC and be done
with it.
AM: Why not; will talk. Think we can do it shortly. Will need some
reviews, even "it's fine".
Review volunteers: JM

Some MUD Extensions and Clarifications

(10 mins; Eliot Lear)
slides

EL presenting.

EL: Your opportunity for "what is good, what is bad, what needs to
change, what would improve adoption".
EL: Please read it, think about it, will suggest WGA around IETF127, no
need to rush.
EL: Prefer more authors and to be Editor.

HB (from floor): Guidance to "How to just do a simple MUD file" would be
good.
EL: Easiest is to go https://mudmaker.org/ and dump pcap files in. Will
follow up on-list.

A summary of security-enabling technologies for IoT devices

draft-ietf-iotops-security-summary-03
(5 mins; Jim Mozley)
slides

JM presenting for BM.

CB (~p4): Landscape is moving all the time. Should write in that we look
at those 3 sets of requirements (from different organizations), later
document can work on 2 more. Otherwise, never finishes.
AM: If we had "living standards" in IETF… but can snapshot, and prepare
-bis.

HT: With AI, summarizing 3 documents is easy. Is goal still the same?
There were 1000s of recommendations summarized already.
HT: Also, now there is CRA that has new requirements.
JM: Objective is not summary of requirements and intent, but give
manufacturers guidance on how to meed those requirements.
AM (hat off): It's a roadmap, "if you have these requirements and those
threat models, look at these IETF or other documents".

AM: With CB and HT feedback, probably not publish now. Alternative to
breaking it up is having authors responsible for sections (editorial
decision).

JM: People willing to contribute to move forward? Will ask on list.

IoT DNS Security and Privacy Guidelines

draft-ietf-iotops-iot-dns-guidelines-03
(20 mins; Jim Mozley)
slides

JM presenting.

CB (p5): RFC9953, written to solve many of these problems (or "not
create them in the first place"). Good idea to mention this.
MSL: Postpone to after my talk.

DNS Privacy Enhancements for the Constrained IoT: DNS over CoAP, SCHC, and Onion CoAP

(15+5 mins; Martine Sophie Lenders)
slides

MSL presenting.
(aimed at T2TRG but moved here)

CA: of those 296 options, which are realistic to recommend to
iot-dns-guidelines audiences?
ML: DoC, transaction ID randomization, last-block padding
JM: obvious step would be to put this into draft we have. Not sure which
level of detail.

HT: Student working around IPsec on IPDFS (?), trying to find what is in
IPsec tunnel. Conclusion was that padding didn't help – bummer. Machine
learning find that data anyway.
HT: My conclusion from there was: No things exist that can be done
easily, if you care. But few people care anyway.

Privacy Preference Declarations and Taxonomy for IoT

draft-dsmullen-ppd-architecture/draft-dsmullen-ppd-taxonomy
(15 mins; Daniel Smullen)
slides

DS presenting

DS: Looking for broad discussion on architectural scope, assumptions,
model, including outside household setups. Find me on the hallway.

JM: Fascinating. Interaction w/ regulatory framework?
DS: European law might be encoded for all households; different in other
regions. Might also come from vendor automatically, and resolve
conflicts. Enforcement is not baked in.
HT: As manufacturer, how would I make my product work with this?
DS: Baseline is "nothing", household could conceivably ban of
segment-off baseline devices. To be open to receive policy, reference
implementation exists and registers with endpoint on household network,
declaring compliance, receiving policy and send own policy.

Authorized update to MUD URLs

draft-ietf-iotops-mud-acceptable-urls
(5 mins; Michael)

(not presented)

AOB

DS: Demo on protocol impl, no side meeting set up.

(Session ends, but DS coming back with demo)