Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

793 articles

Protected media frames travel through one glass channel while a separate peer-verification boundary reaches an intended endpoint; an incomplete mapping between them leaves several properties unassigned.

CASE FILE

W3C WebRTC Patch Says SFrame Covers Only Part of Retired Identity Work

An open correction to W3C’s next WebRTC charter separates two decisions that its public draft had joined together. WebRTC Identity may be discontinued because implementors have shown too little interest. SFrame may cover a limited subset of its use cases. But the Working Group…

Aug 31, 2026
An ivory content sheet sends an amber signal toward a visible gap before separate teal data and evidence paths.

CASE FILE

The Preference Was Published. It Was Not an AI Control: RFC 9969

RFC 9969 records an Internet governance problem without pretending to solve it by publication. A preference attached to content can tell another actor what an owner wants considered. It does not identify that actor, bind a downstream model, prove a use was compliant, create an…

Aug 31, 2026
A circular security-review table and a separate standards workbench sit on opposite sides of a glass boundary while an unfinished folio and two role badges cross the seam.

CASE FILE

W3C’s Security IG Draft Excludes Standards Work but Retains Specification-Editor Roles

W3C opened refinement of a new Security Interest Group charter on 19 August. The draft draws a clear outer boundary: the group will advise, review and publish in-scope material, while Recommendation-track opportunities move to a competent Working Group or an incubation group. Yet…

Aug 31, 2026
A teal signal enters a small amber containment zone while a separate dark network map remains beyond a glass boundary.

CASE FILE

The Provisioning Realm Was Requested. It Was Not Network Access: RFC 9965

RFC 9965 gives an uncredentialed EAP peer a disciplined way to ask for a provisioning path. The `eap.arpa` realm and its provisioning identifier make a request legible; they do not authenticate the peer, prove a route, issue a credential or grant general network access.

Aug 31, 2026
Two cyan and violet ephemeral cryptographic materials converge in a transparent chamber, while a separate amber local verification plane remains outside the derived session-secret glow.

CASE FILE

The Hybrid Secret Was Derived. The Client Still Had to Trust the Host: RFC 10042

RFC 10042 gives SSH a precise way to combine ML-KEM and classical ECDH into a fresh session secret. It makes a key-establishment transcript stronger against a defined class of cryptographic risk; it does not make the client’s host-trust decision, authenticate a user, grant an…

Aug 31, 2026
Two cyan interest signals hover over a feature module that passes an amber at-risk frame before two distinct implementation paths converge through one open test lattice.

CASE FILE

W3C’s Web Performance Charter Separates Implementer Interest From Interoperability

W3C has approved a new charter for the Web Performance Working Group through August 2028. Its most consequential governance choice is a distinction, not a deliverable: two implementors may express interest in a feature before it enters a specification maintained as a Candidate…

Aug 31, 2026
A blue layered network configuration tree passes through an amber guarded transition toward a separate neutral decision chamber.

CASE FILE

The TACACS+ Server Was Configured. Its Authority Was Not: RFC 9950

RFC 9950 gives a device a precise YANG surface for configuring TACACS+ servers, credentials and safeguards. That configuration can change a powerful future control path; it is not an authentication event, an authorization result or a proof that a server may decide for anyone.

Aug 31, 2026
A one-way blue packet stream narrows at an amber network bottleneck while a separate blue status-feedback path returns to the sender.

CASE FILE

The Test Was Authenticated. The Capacity Claim Was Not: RFC 9946

UDPSTP can authenticate its control exchange, limit a short diagnostic test and feed status back to a sender. RFC 9946 does not convert any resulting number into a capacity entitlement, a service guarantee or an operator verdict.

Aug 31, 2026
Four CMC transport paths stop at a separate institutional decision boundary.

CASE FILE

The CMC Message Arrived. It Did Not Arrive With Certificate Authority: RFC 10003

One CMC entity can travel by file, mail, HTTP or TCP. RFC 10003 makes that portability useful without turning any carrier, delivery receipt or listener into proof that a certificate authority made a decision.

Aug 31, 2026
Blue public key surfaces stop at a glass boundary before an amber ML-DSA seed capsule.

CASE FILE

The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary

Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…

Aug 31, 2026
Editorial illustration of an amber completion receipt reaching a cobalt transaction trace, separate from an unlit local decision chamber behind transparent gates.

CASE FILE

A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967

An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…

Aug 31, 2026
Five blank proposal folios sit above an already assembled five-marker roundtable, joined by a dotted path and a translucent nonverbal state ledger.

CASE FILE

W3C’s Human-Rights Note Proposed a Group Six Days After It Launched

On 4 August, W3C’s Advisory Board published five proposals for bringing human-rights considerations further into the consortium’s technical work. The third proposal treated a Threats and Harms Community Group as a possible next step. W3C’s own community record tells the…

Aug 31, 2026
Editorial illustration of one narrow amber legacy client-signature lane separated from a broader cyan TLS handshake route by a physical one-way boundary.

CASE FILE

The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963

An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…

Aug 31, 2026
A small unbranded network appliance sends one copper path to a blue listener arch, with a separate translucent verification card between them.

CASE FILE

The Reverse Socket Arrived. The Device Had Not Yet Identified Itself: RFC 10011 and RESTCONF Call Home

A controller can receive a connection from the direction it expected, on a listener it deliberately opened, after a device has been configured to call home. That is useful evidence. It is not yet the same thing as knowing which device has arrived, establishing a RESTCONF session…

Aug 31, 2026
A translucent charter sheet stands above overlapping open milestone pathways, while one cyan dependency path continues into a separate web-protocol lattice.

CASE FILE

W3C’s WebAppSec Charter Draft Gives 16 of 17 Deliverables No Completion Date

W3C’s proposed Web Application Security charter is unusually candid about time: almost every normative deliverable says its expected completion is undetermined. That is not evidence that sixteen specifications are late. It is evidence that the charter maps authority better than…

Aug 31, 2026
A sealed unmarked envelope connects to one cool-blue and one aged-amber key path, showing two separate recipient decryption routes to the same OpenPGP message.

CASE FILE

The Quantum-Safe Key Was Added. The Classical Recipient Still Opened the Mail: RFC 9980

RFC 9980 gives OpenPGP a post-quantum vocabulary, including composite encryption keys that combine ML-KEM with X25519 or X448. That is an important interoperability step. It is also easy to overstate. A message can carry a genuinely PQ/T-capable recipient key and still be…

Aug 31, 2026
Editorial network-management scene separating telemetry, a service model and a bounded change-authorization record

CASE FILE

The Model Could Explain the Network. It Could Not Authorize the Change: NEMOPS and the Boundary Between Visibility and Control

The NEMOPS workshop report asks for better models, observability, tooling and verification in network management. Those are valuable improvements in what an operator can see and test. They do not decide whose service may be changed, which risk is acceptable, or who bears the cost…

Aug 31, 2026
An amber verification aperture, a cyan loop of repeated session pulses, and a separate red decision barrier show that BFD continuity does not itself authorise an operational action.

CASE FILE

The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985

RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

Aug 31, 2026
A linked chain of proposal folios crosses a conference table, with only a subset marked as signatories while neutral and opposing positions remain visible.

CASE FILE

APT’s PP-26 Common Proposals Can Advance Without Regional Unanimity

The Asia-Pacific Telecommunity has finished its last scheduled preparatory meeting before ITU’s 2026 Plenipotentiary Conference. What happens next is easy to compress into a misleading phrase: “the region’s proposals.” APT’s own rules are more precise. They create a preliminary…

Aug 31, 2026
An abstract BIER fan-out separates a specification sheet, a single-path measurement lens and an independent authorization gate.

CASE FILE

An OAM Requirement Was Written Down. It Did Not Prove a Working Diagnostic: RFC 9974 and BIER Evidence

A requirements catalogue can sharpen an engineering question. It cannot, on its own, answer whether a particular network can run the test, what the test observed, or who may act on it.

Aug 31, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga