Skip to main content

Primary Domain

Internet Governance and Routing

Within the Primary Domain facet, Internet Governance and Routing intelligence groups reporting by primary domain so readers can follow a focused area of internet infrastructure, governance, connectivity markets, or digital capital. The page brings together related articles, public evidence, institutions, companies, people, regional exposure, operating dependencies, and market context that may otherwise sit across separate category pages. It explains the domain, the likely actor class, the market or governance context, and the source material readers should use when comparing signals. Operators, analysts, and governance readers can see how the same domain appears across events, profiles, market shifts, public-source evidence, regional dependencies, and longer-cycle infrastructure decisions over time.

Corey Bonnell in an AI editorial portrait beside two certified-key paths, only one passing an explicit CRL-signing authorization gate.

IETF

Corey Bonnell and the CRL Signature Whose Key Was Not Authorized

A certificate revocation list can carry a flawless digital signature and still be signed by the wrong certified key. RFC 10007 closes that uncomfortable gap by requiring a version 3 CRL issuer certificate to say, explicitly, that its key may sign CRLs. The change turns a skipped…

Aug 30, 2026
Kireeti Kompella in an AI editorial portrait beside branching MPLS label paths and a distinct return path.

IETF

Kireeti Kompella and the Echo Reply That Did Not Prove the Service

An MPLS Echo Reply can show that one carefully constructed probe reached a router able to account for a particular forwarding equivalence class. That is a precise and valuable result. It does not show that every equal-cost path worked, that a dormant backup was usable, that the…

Aug 30, 2026
Eliot Lear in an AI editorial portrait beside separate device-signal, recommendation, enforcement and observed-traffic layers.

IETF

Eliot Lear and the Device Policy That Was Never an Attestation

A limited-purpose device can tell a network which communications it needs without proving what the device is, who currently controls it, or whether it will behave as described. RFC 8520 makes that narrow statement useful through Manufacturer Usage Description, then leaves the…

Aug 30, 2026
Tero Kivinen in an AI editorial portrait beside a dim outgoing control plane, a luminous successor and several uninterrupted abstract data paths.

IETF

Tero Kivinen and the New IKE SA That Inherited Live Child SAs

In IKEv2, the word “rekey” can describe two materially different successions. Replacing the protected control association creates a new IKE SA, yet the Child SAs carrying ESP or AH traffic can remain exactly the ones already in service. The distinction documented in RFC 7296…

Aug 30, 2026
Roy Fielding in an AI editorial portrait between abstract request paths and separate interface and policy planes leading toward a resource.

IETF

Roy Fielding and the Method That Named an Intention, Not a Permission

An HTTP request begins with a compact public word. That word can tell a client, cache or intermediary what kind of result is being sought. It cannot say who is entitled to obtain it, whether the target will comply, or what happened after a connection failed. The architecture…

Aug 30, 2026
Mark Nottingham in an AI editorial portrait beside a translucent boundary that keeps many user signals distinct while allowing only bounded paths toward an abstract service.

IETF

Mark Nottingham and the User Agent That Could Not Speak for Every User

The browser can deny a service direct access to a person's machine, carry a narrow preference and make another implementation possible. Those powers make the user agent a valuable intermediary. They do not turn software, its vendor or a standards entity into the authorized voice…

Aug 30, 2026