AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
776 articles

CASE FILE
The files matched. The authority did not
An RPKI Signed Checklist can bind exact file bytes to a declared set of Internet Number Resources. That is a useful and unusually precise proof. It is also much narrower than the green result can appear: the entity does not identify a company, certify a document's truth, prove a…

CASE FILE
The Counter Named the Discard. It Had Not Proven the Cause.
Two interfaces report the same standardized discard class during one service degradation. At the first, a deliberate access rule is doing precisely what its owner intended. At the second, an old rule is catching valid traffic after a routing change. The labels agree; the…

CASE FILE
The Extension Was in IANA’s Registry. The Server Still Had Not Promised to Accept It.
A registrar’s integration system finds an `Active` EPP extension in IANA’s public registry and enables the command path. The next registry server’s greeting does not advertise the extension namespace. The specification is real and the catalogue is correct; the automation has…

CASE FILE
Two validators agreed on the version. They did not agree on the routes
Two RPKI validators can report the same RRDP session and newest serial while retaining different repository histories. The disagreement becomes visible only if they remember what hash an already-seen delta carried before. RFC 9697 turns that memory into an operational control…

CASE FILE
The Packet Carried the Action. One Router Could Not Read Far Enough to Perform It.
A correctly formed MPLS packet enters a path with a hop-by-hop action in a post-stack header. The first router finds and performs it. A middle router sees the in-stack indication but cannot read the entire post-stack container, so it skips that processing and forwards the packet.…

CASE FILE
The Device Said “Adult.” It Did Not Prove Who Was Holding the Family Tablet.
A child resumes a browser session left open under an adult profile on a shared tablet. The site requests an over-18 signal; the device returns a valid affirmative answer. No identity dossier crosses the network, yet the answer describes the enrolled context rather than the person…

CASE FILE
The Header Asked the Proxy to Stream. It Did Not Prove the First Event Moved.
An origin opens a Server-Sent Events response, sets `Incremental: ?1` and emits its first event. One proxy understands the field and forwards every arrival. The next proxy has never heard of the field, so it waits for the complete response. The response is designed never to…

CASE FILE
The Library Named a Direct Modifier. It Did Not Calculate the Dependency Graph.
Module B inserts a container into Module A. Module C then inserts a leaf into B’s new container. RFC 10035 lets the server report B as a direct augmenter of A and C as a direct augmenter of B. It deliberately does not place C on A’s list. The new inventory exposes immediate…

CASE FILE
The Charter Opened a Work Queue. It Did Not Migrate a Certificate.
The LAMPS charter now contemplates an unsigned X.509 certificate as a slimmer way to carry trust-anchor subject information. Removing a self-signature can save expensive bytes. It does not make the container trusted, choose a post-quantum algorithm or move one relying party.…

CASE FILE
The Policy Named a Partition. It Did Not Reserve the Resources.
Two candidate paths can point to the same endpoint while carrying different Network Resource Partition identifiers. One 32-bit value changes which underlay resources the headend is meant to invoke. The BGP field can state that association; it cannot create the resources, install…

CASE FILE
Fourteen ACKs Did Not Prove a Window of Twenty-Four
An application sends ten segments, pauses, then supplies four more. Every segment is acknowledged. A naive slow-start counter can call the resulting congestion window twenty-four, although the path has never carried more than ten in one round trip. The IESG has now approved a…

CASE FILE
The Proxy Opened a Port. It Did Not Authorize the Internet.
The IESG has approved an HTTP extension that lets one proxy-bound UDP socket serve many remote peers. Its operational lesson is sharper than the feature: advertising a reachable address allocates a path, while Context IDs, tuple policy and observed forwarding decide who may use…

CASE FILE
The Signature Was Valid. The Token Was Wrong.
The IESG has approved a replacement for the JWT security playbook. Its hardest rule is also its most practical: a receiver must prove not only that a token is authentic, but that this exact kind of token is entitled to cross this exact application boundary.

CASE FILE
The Path Kept Its ID. Its Instructions Changed.
The IESG has approved a compact identifier for segment lists carried in BGP SR Policy. The number can simplify telemetry and cross-system configuration, but it stays meaningful only inside its Candidate Path—and it can remain unchanged while the actual SID sequence changes.

CASE FILE
The Gateway Said “Post-Quantum Ready.” The Tunnel Still Used ECDSA.
The IESG approved a mechanism for post-quantum signature authentication in IKEv2 on 24 August 2026. The decision advances the standards path for ML-DSA and SLH-DSA, but a supported algorithm, an advertised method and an authenticated tunnel remain three different facts.

CASE FILE
IANA Registered a DELEG Capability Key. Deployment Still Needs Proof.
IANA added a temporary `deleg` key to the DNS Resolver Information registry on 24 August 2026. The entry gives operators a common way to declare support for the emerging DELEG protocol; it does not turn an Internet-Draft into a standard or a declaration into running behavior.

CASE FILE
The serial matched. The zone did not
The transfer finished, the file parsed and the SOA serial was exactly the number operations expected. One glue record was nevertheless missing. DNS had long possessed ways to say that a copy was newer and that a transaction came from an approved peer; ZONEMD added a different…

CASE FILE
The First Endpoint Was Preferred. It Was Never Eligible.
An HTTPS record can put one endpoint first and still require a client to ignore it. SVCB makes DNS a publisher of bounded connection plans, not a substitute for compatibility, endpoint authentication or running evidence.

CASE FILE
The Network Named a Provisioning Domain. It Did Not Choose the Path.
A Provisioning Domain can keep one network's addresses, resolvers and routes from contaminating another. It names a coherent context; it does not convert a Router Advertisement into a command that chooses a connection.

CASE FILE
The bridge was gone. The topology still crossed it
Two BGP-LS producers can each retain one stale half of a failed link. A consumer that merges their disclosures may reconstruct a plausible connection that no longer exists, and a controller may compute straight across it. The failure is not simply “bad telemetry.” It exposes who…
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga