**Session Date/Time:** 18 Jun 2026 20:00 # [SUIT](../wg/suit.html) ## Summary The SUIT Working Group held an interim meeting on June 18, 2026. The session focused on the status and recent updates of three core WG documents: the SUIT Manifest (`draft-ietf-suit-manifest`), the SUIT Report (`draft-ietf-suit-report`), and SUIT Update Management (`draft-ietf-suit-update-management`). Key updates focused on aligning CDDL specifications with text descriptions, addressing IANA and directorate feedback, and fixing minor inconsistencies discovered through implementation experience. --- ## Key Discussion Points ### 1. Administration and Document Status * **Meeting Chair:** Akira Tsukamoto * **Note Taker:** Michael Richardson * **Slides Referenced:** [Chair Slide SUIT Interim 2026 June 18](https://datatracker.ietf.org/meeting/interim-2026-suit-02/materials/slides-interim-2026-suit-02-sessa-chair-slide-suit-interim-2026-june-18-02) * Akira Tsukamoto reviewed the Note Well and administrative tasks. The draft statuses are: * `draft-ietf-suit-manifest` (version -37, RFC Editor Queue) * `draft-ietf-suit-report` (version -20, RFC Editor Queue, blocked on MISREF) * `draft-ietf-suit-update-management` (version -12, waiting for AD go-ahead) --- ### 2. SUIT Manifest (`draft-ietf-suit-manifest`) * **Slides Referenced:** [suit-manifest-status-update](https://datatracker.ietf.org/meeting/interim-2026-suit-02/materials/slides-interim-2026-suit-02-sessa-suit-manifest-status-update-00) * **Presenter:** Brendan Moran * **Discussion:** * Brendan Moran apologized for the recent spec churn (releasing versions -35, -36, and -37 quickly due to a merge conflict rebase). * The main updates in these versions were: 1. **IANA Tag Registrations:** Updated the tag descriptions for the SUIT envelope and SUIT manifest to specify "a map with SUIT envelope semantics" and "a map with SUIT manifest semantics" instead of the original text, as requested by IANA. 2. **CDDL Correction:** Ken Takayama and other reviewers identified an inconsistency in the CDDL. The full CDDL had used `send record success` and `send record failure`, whereas the main text had been updated to `suit send record on success` and `suit send record on failure`. The CDDL has been corrected to match the text. * Deb Cooley (AD) asked about the timeline of the IANA request and noted that the changes in version -37 were minor, primarily affecting the appendix (CDDL) and CBOR tag registrations. * Jacqueline McCall volunteered to review the changes immediately. * Deb Cooley and Michael Richardson agreed that due to the minor, non-substantive nature of these editorial and CDDL typo fixes, a new Working Group Last Call (WGLC) is not necessary. * Brendan Moran agreed to coordinate with the Designated Experts (DE) for CBOR and Ken Takayama to ensure the issue is fully resolved. --- ### 3. SUIT Report (`draft-ietf-suit-report`) * **Slides Referenced:** [suit-report-status-update](https://datatracker.ietf.org/meeting/interim-2026-suit-02/materials/slides-interim-2026-suit-02-sessa-suit-report-status-update-00) * **Presenter:** Brendan Moran * **Discussion:** * Version -20 was published to resolve several points raised during implementation and review: * Clarified that the reporting engine is a conceptual function, not a local API. * Defined `suit-record` manifest ID and component index semantics across dependency trees. * Added normative language stating that a `suit-record` must not be used for reconstruction without its matching manifest. * Expanded transport protection definitions to include `COSE_MAC0` (with caveats regarding repudiation) and `COSE_Encrypt0`. * Fixed CDDL alignment issues, including a missing repeat character in the extension group of the report structures. * Ken Takayama identified an outstanding inconsistency regarding the `reference URI`: * In `draft-ietf-suit-manifest`, the reference URI is an optional element. * In `draft-ietf-suit-report` (-20), the reference URI is mandatory in both the text and CDDL. * Ken Takayama and Brendan Moran agreed that the reference URI in `draft-ietf-suit-report` should be made optional while keeping the digest mandatory. * Deb Cooley highlighted an IANA comment in Section 9.3 where "coswid media type" was incorrectly written instead of "suit-report media type". Brendan Moran confirmed this was already corrected in version -20. --- ### 4. SUIT Update Management (`draft-ietf-suit-update-management`) * **Slides Referenced:** [suit-update-management-status-update](https://datatracker.ietf.org/meeting/interim-2026-suit-02/materials/slides-interim-2026-suit-02-sessa-suit-update-management-status-update-00) * **Presenter:** Brendan Moran * **Discussion:** * Version -12 was recently published to address outstanding Last Call reviews (including Gen-ART feedback): * **COSWID/SBOM:** Added clarification on why COSWID is recommended over other metadata formats, and detailed what a recipient should do if COSWID is unused, unsupported, severable, non-severable, malformed, policy-rejected, or resource-exhausting. * **Semantic Versioning:** Corrected "positive integer" to "non-negative or unsigned integer" to correctly allow zeroes in semver fields. * **Battery Parameters:** Clarified primary cell definitions (discharge-only) and updated timestamp handling (64-bit). * **CDDL & IANA Tables:** Formatted IANA tables and updated CDDL to align with text, including missing extension hooks and switching weight event UTC encodings to tagged integers. * Deb Cooley discussed next steps for the draft: * Deb will ping Russ Housley (Gen-ART reviewer) to confirm if the updates satisfy his review. * Deb plans to issue the ballot and schedule this draft for the **July 8, 2026** IESG telechat, rather than July 2, to allow reviewers more time and accommodate scheduling constraints. --- ### 5. Planning for the Vienna Meeting (IETF 126) * Michael Richardson asked about the agenda items for the upcoming Vienna meeting. * Jacqueline McCall confirmed that a session has been requested for Vienna. * Deb Cooley and Brendan Moran discussed potential topics: * If `draft-ietf-suit-update-management` receives comments during the July 8 telechat, resolving those comments will be the priority. * If the update management draft passes without issue, the WG will pivot to discussing the new Post-Quantum Cryptography (PQC) manifest draft. --- ## Decisions and Action Items * **Decision:** The Working Group agreed that no additional Working Group Last Call is required for the minor editorial and CDDL updates in `draft-ietf-suit-manifest` (v37). * **Action Item:** Brendan Moran to publish a new version of `draft-ietf-suit-report` (v21) to make the reference URI optional (matching the manifest specification) and resolve Ken Takayama's implementation issue. *(Note: Brendan published this during the meeting).* * **Action Item:** Jacqueline McCall to review the minor updates to `draft-ietf-suit-manifest` today and confirm correctness. * **Action Item:** Deb Cooley to coordinate with IANA regarding the registry updates and contact the CBOR Designated Experts. * **Action Item:** Deb Cooley to schedule `draft-ietf-suit-update-management` for the IESG telechat on July 8, 2026, and follow up with Russ Housley for Gen-ART review confirmation. --- ## Next Steps * Monitor the progress of `draft-ietf-suit-update-management` as it moves onto the IESG telechat. * Prepare presentation materials for the Vienna (IETF 126) session once draft statuses and the agenda are finalized.