[DNSOP] New Internet-Drafts: DNS-anchored identity discovery for autonomous agents (Groundmark)
elliot@noss.org Sat, 13 June 2026 23:26 UTC
Return-Path: <elliot@noss.org>
X-Original-To: dnsop@mail2.ietf.org
Delivered-To: dnsop@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7AE68100DC4F0 for <dnsop@mail2.ietf.org>; Sat, 13 Jun 2026 16:26:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1781393201; bh=SN9RS9+2OmNn19ofej0po17GhHVkfoq/4alv0bSo80A=; h=From:Subject:Date:To; b=fj2az2I6kUkN+VbXlMqrlnndlGZGp4XlFkWvx4gQ0zCeZomSEAwpqAOEQ/RYtol70 UI56iEsHI4u4gQpCScj9cgAyLLJqi5jkpAfjCLOE2dPJgn4yjeqbNThjL8P4XcEyJ4 yONS4zPu623Nc1cTXY9U51xGIJ0/XeTY7k1VjG8Y=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.896
X-Spam-Level:
X-Spam-Status: No, score=-1.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001, UNPARSEABLE_RELAY=0.001] autolearn=ham autolearn_force=no
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JVBw6Fp8KLWt for <dnsop@mail2.ietf.org>; Sat, 13 Jun 2026 16:26:41 -0700 (PDT)
Received: from relay.hostedemail.com (smtprelay0017.hostedemail.com [216.40.44.17]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 54C0A100DC3C2 for <dnsop@ietf.org>; Sat, 13 Jun 2026 16:25:21 -0700 (PDT)
Received: from omf02.hostedemail.com (lb01a-stub [10.200.18.249]) by unirelay01.hostedemail.com (Postfix) with ESMTP id 47BB91C276F for <dnsop@ietf.org>; Sat, 13 Jun 2026 23:25:15 +0000 (UTC)
Received: from [HIDDEN] (Authenticated sender: enoss@tucows.com) by omf02.hostedemail.com (Postfix) with ESMTPA id 360698000E for <dnsop@ietf.org>; Sat, 13 Jun 2026 23:25:14 +0000 (UTC)
From: elliot@noss.org
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3774.500.171.1.1\))
Message-Id: <1A434B6E-2831-4BB6-98E3-0277629C0DB2@noss.org>
Date: Sat, 13 Jun 2026 19:25:06 -0400
To: dnsop@ietf.org
X-Mailer: Apple Mail (2.3774.500.171.1.1)
X-Stat-Signature: bj5b96abnqqd71ebx6t645wjuom855m9
X-Rspamd-Server: rspamout08
X-Rspamd-Queue-Id: 360698000E
X-Session-Marker: 656E6F7373407475636F77732E636F6D
X-Session-ID: U2FsdGVkX1/3rkcDZ8HSb3ZzKxM92G6C+RNTlG3/xKM=
X-HE-Tag: 1781393114-213196
X-HE-Meta: U2FsdGVkX1+dcrXCK+lmMnqUld66nflvnzsrjfcW/KB2Pze2xAd2yGtbIMOx5im/OsTnwSpSzu5cOg1Kiw40hMjCNSFFf3Ls/ptKRCKKsWV6P8YrTo/Y00k+cCGuyFrSkUFPbRNLEIgj1Bdiz0I/3t9z3e3TMOly51FRtB+sscpRHdaKRRjv2o9TwZVdXCOOSQ1YKU2F3uePvMKzSdcQU9xsxAcgKaVtqdUFIMtta3h7uy5WDh7Fss3M62+aQvkO3yRLlGzf4Lf+BUujwAYOvCydWmcLPEYH2PJ5UFOT9c8Ns99+KnefQ4BaFWeay09S
Message-ID-Hash: 2HOGEZ55FBXEPKZTXSVV7YODNXI2K4SL
X-Message-ID-Hash: 2HOGEZ55FBXEPKZTXSVV7YODNXI2K4SL
X-MailFrom: elliot@noss.org
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-dnsop.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [DNSOP] New Internet-Drafts: DNS-anchored identity discovery for autonomous agents (Groundmark)
List-Id: IETF DNSOP WG mailing list <dnsop.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/dnsop/DdF-X_jwFh5ZcJGnJnNVZgjfQUs>
List-Archive: <https://mailarchive.ietf.org/arch/browse/dnsop>
List-Help: <mailto:dnsop-request@ietf.org?subject=help>
List-Owner: <mailto:dnsop-owner@ietf.org>
List-Post: <mailto:dnsop@ietf.org>
List-Subscribe: <mailto:dnsop-join@ietf.org>
List-Unsubscribe: <mailto:dnsop-leave@ietf.org>
Hello, Mark Jeftovic (easyDNS) and I filed two Internet-Drafts in May. I am writing to ask this list to look hard at the DNS-layer design before anything else. A short word on who I am, for those who do not know me: I spent many years as CEO of Tucows. Groundmark is independent of any company. The motivation is the gap left by the payment and authorization work now moving quickly around agents. Those efforts answer how an agent pays or what it is permitted to do in a session. None answers a prior question: when an agent presents itself to a counterparty, is there an accountable party behind it, established without a central registry. We think the answer is the same place DKIM put it. A key in a TXT record, anchored to a registrant a registrar has already verified. What the core draft actually adds to DNS is small and, we hope, unobjectionable: - Two TXT records under RFC 8552 reserved underscore labels: _agentid (an Ed25519 signing key) and _agentclaim (a reference to an externally hosted attestation), both tagged v=gm1. - Request authentication is a profile of HTTP Message Signatures (RFC 9421), not a new mechanism. - DNSSEC is a MUST in the verification flow, borne by participants rather than asked of the whole internet. - DNS remains discovery only. The attestation itself is fetched over HTTPS; DNS holds a reference, not the claim. The IANA ask is registration of _agentid and _agentclaim in the Underscored and Globally Scoped DNS Node Names registry (RFC 8552). That, the DNSSEC requirement, and coexistence with _dmarc, DKIM, TLSA, and the ANS and DNS-AID drafts are the places I most want your scrutiny. A companion draft carries the attestation semantics, kept separate so the DNS work stands on its own. Core: draft-noss-jeftovic-groundmark-core-00 Attestation: draft-noss-jeftovic-groundmark-attestation-00 I would value the review, sharp or otherwise. EN
- [DNSOP] New Internet-Drafts: DNS-anchored identit… elliot
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… S Moonesamy
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… Mark E. Jeftovic
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… Mark E. Jeftovic
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… S Moonesamy
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… Ben Schwartz
- [DNSOP] Re: New Internet-Drafts: DNS-anchored ide… Michael Richardson