Topic
Software Lifecycle and Lock-in
Within the Topic facet, Software Lifecycle and Lock-in topic intelligence connects articles that share a specific subject, signal focus, or monitoring theme. The page gives readers a richer path through related reporting, source evidence, market actors, and infrastructure implications, with enough context to understand why the topic matters across company movements, governance decisions, regional exposure, and operational risk. Readers can compare recurring signals, affected organisations, public evidence, market context, service continuity, procurement, competition, compliance, and strategic planning questions behind the subject instead of stopping at a thin list of matching articles. It explains what the topic covers, which infrastructure actors or policies are involved, what evidence supports the coverage, and why the subject may matter for operators, customers, investors, and policy readers.
CASE FILE
The Group Key Reached the Devices. It Did Not Assign the Act: RFC 10020 and CoAP Group Authority
A protected message can leave one sender and be intelligible to a group. It cannot make five receivers one decision-maker. RFC 10020 matters because it gives constrained systems a disciplined way to speak to a group without erasing the separate evidence required for membership…
CASE FILE
The Model Named an Endpoint. It Did Not Start a Service: RFC 10009 and HTTP Configuration Authority
An HTTP endpoint can look settled long before it exists in practice. A URI is present in a management tree; permitted versions are listed; TLS parameters and a proxy are named; a server has a name and an apparent stack. Those are useful, reviewable decisions. RFC 10009 makes…

History
The Name Was Local. The Number Still Needed a Record: RFC 1101’s DNS Mapping Boundary
In 1989, DNS could already distribute host information, but it did not yet offer a standard way to ask what a network number was called. RFC 1101 proposed a small answer: use PTR records, host-zero names and masks in `IN-ADDR.ARPA`. Its lasting discipline is equally small. A…
CASE FILE
What the Aggregate Report Actually Knows: RFC 9990 and the Boundary Before Enforcement
A DMARC dashboard can make a narrow observation look like a verdict. One receiver reports a large count from a source range, records an evaluated policy and shows a disposition. That is valuable operational evidence. It is not a global traffic census, proof of a sender's intent…
CASE FILE
The Preference Was Published. It Was Not an AI Control: RFC 9969
RFC 9969 records an Internet governance problem without pretending to solve it by publication. A preference attached to content can tell another actor what an owner wants considered. It does not identify that actor, bind a downstream model, prove a use was compliant, create an…

IETF
Panos Kampanakis and the SSH Session with Three Different Security Receipts
An SSH client can negotiate a hybrid ML-KEM key exchange, verify the server through a conventional host key, and admit a user through a still separate credential. The session is one connection; the evidence is not one claim.
CASE FILE
The Provisioning Realm Was Requested. It Was Not Network Access: RFC 9965
RFC 9965 gives an uncredentialed EAP peer a disciplined way to ask for a provisioning path. The `eap.arpa` realm and its provisioning identifier make a request legible; they do not authenticate the peer, prove a route, issue a credential or grant general network access.

History
The FDDI Frame Carried IP. It Did Not Carry Identity: RFC 1188’s Encapsulation Boundary
An FDDI interface could put an IP datagram onto a fast local ring only after several small facts agreed: which link grammar carried the payload, how large a packet could be, and which local hardware address represented an IP neighbour. RFC 1188 made those facts interoperable in…
CASE FILE
The Hybrid Secret Was Derived. The Client Still Had to Trust the Host: RFC 10042
RFC 10042 gives SSH a precise way to combine ML-KEM and classical ECDH into a fresh session secret. It makes a key-establishment transcript stronger against a defined class of cryptographic risk; it does not make the client’s host-trust decision, authenticate a user, grant an…

History
The Mailbox Was a Contact. It Was Not a Control Room: RFC 1173’s “Oral Tradition”
Before the Internet had a single operational mythology, it had a more modest arrangement: if a problem crossed a boundary, someone needed to be reachable on the other side. RFC 1173, published in 1990, made that arrangement visible. Its lasting lesson is not that a role mailbox…
CASE FILE
The TACACS+ Server Was Configured. Its Authority Was Not: RFC 9950
RFC 9950 gives a device a precise YANG surface for configuring TACACS+ servers, credentials and safeguards. That configuration can change a powerful future control path; it is not an authentication event, an authorization result or a proof that a server may decide for anyone.
CASE FILE
The Test Was Authenticated. The Capacity Claim Was Not: RFC 9946
UDPSTP can authenticate its control exchange, limit a short diagnostic test and feed status back to a sender. RFC 9946 does not convert any resulting number into a capacity entitlement, a service guarantee or an operator verdict.

History
A Policy Sentence Was Not a Network Control: RFC 1087 and the Limits of “Acceptable Use”
In 1989, the Internet Activities Board could identify conduct that threatened a shared research facility. It could say that intentional intrusion, disruption, waste, destruction and privacy compromise were unacceptable. What it could not do with a sentence was observe an act…

History
The Bit Preserved a Return Path. It Did Not Authenticate the Request: RFC 1044's HYPERchannel SRC
In a physical network, an address can do something concrete without saying who is entitled to act. RFC 1044 gave HYPERchannel messages a Source Address Correct bit that could survive only while the declared return address remained usable in reverse. That was valuable path…
CASE FILE
The CMC Message Arrived. It Did Not Arrive With Certificate Authority: RFC 10003
One CMC entity can travel by file, mail, HTTP or TCP. RFC 10003 makes that portability useful without turning any carrier, delivery receipt or listener into proof that a certificate authority made a decision.

History
The Speed Was a Display Hint. It Was Not the Link: RFC 1079’s Telnet Boundary
In 1988, a remote terminal program could know something useful about the terminal at the other end without pretending to know the network between them. RFC 1079 made that distinction unusually crisp. It let one Telnet peer request a pair of terminal speeds and let the other peer…
CASE FILE
The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary
Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…
CASE FILE
A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967
An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…

History
Before DHCP, Four Bytes Chose the Grammar: RFC 1048 and BOOTP's 64-Octet Limit
Before a diskless machine could fetch its operating system, it needed enough network knowledge to ask for one. BOOTP carried that knowledge in a field only 64 octets long. RFC 1048 made the field intelligible across vendors with four opening bytes and a compact option…
CASE FILE
The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963
An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…
