Lead Report / Afrinic

Nine Zones, One Open Link: What AFRINIC’s DNSSEC Phase 2 Actually Changed
On 3 May 2012, AFRINIC began distributing signed versions of nine IANA-delegated reverse-DNS zones—six for IPv4 and three for IPv6—while deliberately leaving the parent DS connection and the publication of members’ DS records for a later phase. That distinction was not a footnote. It defined what operators could observe, what security claims could honestly be made, and what could still be reversed if the change behaved badly. The episode is worth revisiting because it shows, in a compact and unusually legible form, how technical coordination earns credibility: not through the ceremony of an “enabled” service, but through a precise account of running state, reproducible checks, operator reports, and an executable way back. AFRINIC’s staged release was prudent engineering, not evidence of an attempted power grab. Yet precisely because the staging was prudent, it sets a demanding governance standard. A private registry’s announcement can identify a change; it cannot substitute for evidence that each promised property held across the service.











