AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
764 articles

CASE FILE
The Client Expected a Certificate. The Library Accepted a Key: TLS Raw Public Keys and the Authority of Negotiation
The key was mathematically usable. That was precisely the problem. In June 2026, wolfSSL disclosed that an RPK-enabled build could accept an unnegotiated Raw Public Key where the peer expected X.509, bypassing certificate-chain validation. The repair did more than reject a format…

CASE FILE
The Proof Arrived After the Connection Began. It Did Not Rewrite the Past: TLS Exported Authenticators and Application Authority
At 14:03, a valid certificate proof arrived on a connection that had already carried hundreds of operations. The service upgraded every stream and relabelled five earlier minutes as authenticated by the new identity. The signature was sound. The history was not. TLS Exported…

CASE FILE
The Certificate Had Not Been Verified. Its Memory Claim Already Had to Be Judged: TLS Compression and the Pre-Trust Boundary
A two-kilobyte handshake message says it will become twelve megabytes after decompression. Before the receiver can inspect a name, a signature or a chain, it must decide whether that unauthenticated claim deserves memory and CPU. RFC 8879 makes certificates smaller on the wire…

CASE FILE
The Edge Received a Key. It Did Not Receive the Certificate: TLS Delegated Credentials and the Boundary of Short-Lived Authority
A front end can finish a TLS 1.3 handshake for the certificate owner without holding the certificate’s long-term private key. What crosses that boundary is powerful but deliberately small: a signed public key, a role, an algorithm and an expiry—not the certificate, the CA…

CASE FILE
The Peer Requested New Keys. It Did Not Own the Epoch: TLS 1.3 KeyUpdate and the Authority to Rotate a Live Connection
One encrypted record leaves under the old key. Every later record from that sender must use the next one. The peer can authenticate the transition and ask for a reciprocal change, but it cannot see whether yesterday’s secret left memory, choose the other endpoint’s work queue, or…

CASE FILE
The Speaker Was in the Session, Not the Path: IXP Route Servers and the Authority to Broker Reachability
The BGP session was established to one system. The route began with another network's AS number. Its next hop named a third address on the exchange fabric, and the packets never crossed the machine that had delivered the UPDATE. Nothing was malformed. The apparent contradiction…

CASE FILE
An RFC Number Does Not Mean the IETF Approved It
A compliance register that records only “RFC 8729” looks precise. It is not. The number identifies a durable document, but it conceals that this particular RFC is an IAB-stream informational statement rather than an Internet Standard. When a single column makes every RFC look…

CASE FILE
The Request Said Urgent. The Scheduler Still Decided: HTTP Priorities and the Authority to Allocate Scarce Delivery
A browser can call a hero image urgent, an origin can prefer the font, and a CDN can see both through a different connection map. RFC 9218 lets each express useful information. It does not let any of them annex the scheduler that finally allocates the next byte.

CASE FILE
The “Obsoletes” Line Is Not a Remote Kill Switch
When RFC 9113 replaced the earlier HTTP/2 specification, the catalogue moved and selected registry references moved with it. A live connection did not. It still negotiated `h2`; no standards editor reached into a server, removed old code or accepted the outage risk on an…

CASE FILE
The Resolver Named the Failure. It Did Not Prove the Cause: Extended DNS Errors and the Authority of Diagnosis
Extended DNS Errors can turn an opaque DNS failure into a useful account of what one resolver observed. The gain is operational clarity. The danger begins when a dashboard promotes that account into proven cause, assigned blame or permission to weaken the control that produced…

CASE FILE
The Token Knew the Address, Not the Actor: DNS Cookies and the Authority of Weak Authentication
A valid DNS Server Cookie proves something useful and deliberately small: a requester using this Client Cookie at this source address previously received a value derived from a server secret. Trouble begins when an operations system promotes that narrow fact into identity, trust…

CASE FILE
An IANA Code Point Is Not a Licence to Deploy
The Internet needs common numbers, strings and names so that independently built systems can understand one another. IANA protocol-parameter registries supply that shared vocabulary. Their authority is real, but deliberately narrow: a registry entry can settle which value carries…

CASE FILE
The Public Path Looked Cleaner. Its History Had Been Rewritten: BGP Private-AS Removal and the Authority to Erase a Hop
The customer route arrived with three private autonomous systems in its path. At one public exit they vanished. At another, one survived. At a third, all three returned wearing the provider's number. Each operator had configured something called private-AS removal. The public…

CASE FILE
Trusted channels, no command: who can speak for FIRST in a cyber crisis?
A warning enters a trusted channel during a cross-border incident. Three decisions follow, and they do not belong to the same institution: who may enter the room, who may speak for the network, and who may act on an affected system. FIRST has substantial control over the first…

CASE FILE
Empowered without a vote: what the IGF Leadership Panel can actually command
The IGF Leadership Panel was designed to carry messages, recruit senior attention and find resources. Appointment by the UN Secretary-General gives that work institutional access. The operative rules still leave the annual programme with the MAG, execution with the Secretariat…

CASE FILE
A database governed by its entries: who gets a vote in PeeringDB?
A legal business entity can cross PeeringDB's membership threshold with two credentials: an active account and a representative or role subscribed to the governance list. The vote that follows is real. It is also only the first layer of authority over a database whose daily…

CASE FILE
The 30 Percent Congress Legalised After It Was Collected
For two and a half years, every covered domain registration carried a public-purpose assessment that Congress had not specifically authorised. One month after a judge exposed the defect, Congress made the past lawful “as if” it had acted first.

CASE FILE
The Tag Fit. The Authority Did Not: BGP Large Communities and the Namespace That Executes Policy
The route carried exactly the value the interconnection handbook prescribed. One provider acted on it, another erased it, and a third would have accepted the same instruction from a party that had never been authorized to give it. Twelve octets solved the numbering problem. They…

CASE FILE
The Route That Knew Nothing and Reached Everything: BGP Default Origination and the Authority of Last Resort
A customer still had an Established BGP session, a selected `0.0.0.0/0` and several successful probes. Most of the Internet had nevertheless become unreachable. The route with the widest scope had survived the loss of the service it was supposed to summarize.

CASE FILE
The Path Was Shorter Because the Evidence Was Gone: BGP ATOMIC_AGGREGATE and the Authority to Compress
The `/22` remained visible, its origin stayed valid and every external session was green. One of the four `/24`s beneath it had nevertheless disappeared. The public path looked cleaner at precisely the moment when the network knew less about the destinations it claimed to reach.
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga