Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

755 articles

CASE FILE

The Older Service Record Won. The Service Had Already Moved

A name collision is supposed to stop a newcomer from impersonating an established local service. Put two registration proxies between the service and that local link, however, and the same safeguard can protect yesterday’s address from today’s legitimate update. DNSSD’s proposed…

Sep 5, 2026

CASE FILE

The EAP Method Succeeded. The Protected Session Still Needed a Second Witness: RFC 9820

The access controller displayed three green facts: the EAP method had succeeded, the Master Session Key had been exported, and the constrained device had been placed in the security domain. Only the first two facts could be reconstructed. No one could produce the protected…

Sep 5, 2026

CASE FILE

The IESG Approved Three ML-KEM Groups. The Registry Recommended None

An approved IETF document can define exactly how three post-quantum groups travel through TLS while leaving the deployment verdict deliberately unresolved. That is not bureaucratic ambiguity. It is a precise boundary between an interoperable mechanism, a registry coordinate and…

Sep 5, 2026

CASE FILE

The Switch Executed the Program. It Did Not Inherit the Right to Read, Rewrite or Decide: RFC 9817

A program that runs inside a switch or network interface card is no longer merely near the traffic. It can become part of the path by which traffic is classified, transformed, delayed, replicated or converted into a control action. RFC 9817 catalogs the opportunity and, more…

Sep 5, 2026

CASE FILE

All Three Attestations Were True. They Still Did Not Belong to the CSR Key

A certification request can arrive with one valid statement about an HSM, another about corporate ownership and a third about platform health. The dangerous moment comes when a certificate authority treats three successful checks as one joined fact. Revision 29 of an IETF draft…

Sep 5, 2026

CASE FILE

One Timer Drove Three IPv6 Decisions. The Counters Could Not Explain Which One

A network team changes one millisecond value on an IPv6 interface. Address resolution, reachability probing and duplicate-address detection all inherit it. The edit receipt is precise; the operational meaning is not, until the team joins the change to an interface, an epoch and…

Sep 5, 2026

CASE FILE

The Route Reflector Distributed the Link. It Never Witnessed It: RFC 9815's Sparse-Peering Evidence Boundary

A route reflector can hold the newest authenticated account of a data-centre link and still know nothing directly about whether that link carries a packet. RFC 9815 makes this separation operationally useful: BGP can distribute a link-state graph over far fewer sessions than the…

Sep 5, 2026

CASE FILE

The Packet Had No SRH. It Could Still Target an SRv6 SID

An edge filter inspects an IPv6 packet, finds no Segment Routing Header and lets it pass. The packet still carries a locally instantiated SRv6 SID as its destination. The visible header test succeeded; the admission decision examined the wrong fact.

Sep 5, 2026

CASE FILE

The HSM Signed a Small Attribute Set. The Large CMS Content Was Bound Through One Digest: RFC 9814

An operator can truthfully say that a hardware security module produced an SLH-DSA signature while still leaving the most important question unanswered: which bytes did the module actually sign? RFC 9814 makes that question decisive for CMS. A multi-gigabyte archive may never…

Sep 5, 2026

CASE FILE

The IP Address Stopped Naming the RADIUS Client. The Cleartext PSK Identity Took Over: RFC 9813

Two network access servers can stand behind one public address, while one mobile appliance can appear from several addresses in a week. RFC 9813 lets RADIUS/TLS distinguish those relationships with a PSK Identity. The useful part is not the new name. It is the sequence of checks…

Sep 5, 2026

CASE FILE

The Indicator Was Defanged. Its Next Consumer Could Still Arm It

A security analyst pastes a bracketed address into a ticket. It looks inert, and in that surface it may be. Minutes later, a preview worker extracts the same string, restores its URI form and fetches it for inspection. The analyst never clicked. The ticketing chain still crossed…

Sep 5, 2026

CASE FILE

The HTTP Request Returned 200. The Certificate Decision Was Still Inside: RFC 9811

A green transport result is tempting because it is immediate, familiar and easy to graph. RFC 9811 makes that result useful without letting it impersonate the certificate-management decision carried inside it. The distinction is small enough to fit in one response and important…

Sep 5, 2026

CASE FILE

The Device Can Last for Years. Its Trust Anchor Cannot Be Treated as a Lifetime Constant

A field sensor can remain bolted to a bridge long after its manufacturer changes owners, its issuing CA rolls over and its original algorithm becomes uncomfortable. The device still has power. The network still reaches it. Yet whether it can trust the next service chain depends…

Sep 5, 2026

CASE FILE

The Space Was Reserved. One Executive Approval Was Still Too Weak: RFC 9812

Nearly seven-eighths of IPv6 address space was being held for a future that had not arrived. The registry called it reserved, but the rule for releasing a major piece could still be satisfied by an executive approval with no RFC. RFC 9812 repaired that mismatch without pretending…

Sep 5, 2026

CASE FILE

The IETF Approved Stateful NAT64 as an Internet Standard. The Shared IPv4 Pool Still Needs a Claim Ledger

An IPv6-only subscriber opens an ordinary connection to an IPv4 server. For a few minutes, a public IPv4 address and port become that subscriber's usable external identity. The address is shared, the claim expires, and the proof lives inside a translator. The IETF has now…

Sep 4, 2026

CASE FILE

The Server Never Saw the Password. Its OPRF Seed Still Defined the Blast Radius: RFC 9807

OPAQUE gives password authentication an unusually valuable property: the server need not learn the password, even when the account is registered. RFC 9807 also makes the harder truth visible. A secret can disappear from one side of a protocol while authority remains concentrated…

Sep 4, 2026

CASE FILE

The Registry Closed, but the Packets Still Knock: RFC 9805 and Router Alert's Residual Authority

The IETF has stopped future protocols from asking IPv6 routers for special attention through Router Alert. It has not stopped the installed protocols that already ask. That distinction turns a small registry change into a case study in how the Internet freezes a dangerous…

Sep 4, 2026

CASE FILE

The CDN Advertised a Ceiling. It Did Not Reserve the Service: RFC 9808

A new interconnection vocabulary lets one CDN publish capacity limits and aligned telemetry to another. The useful fact is narrower than the comforting one: the numbers can discipline delegation without guaranteeing that capacity has been reserved, a request will be admitted or…

Sep 4, 2026

CASE FILE

The Certificate Named Four Purposes. The Relying Party Still Had to Separate Them: RFC 9809

A new X.509 vocabulary distinguishes configuration, trust-anchor changes, update packages and safety-sensitive communication. Its value begins where its authority ends: the names travel, while combination policy, operational permission and proof of outcome remain local.

Sep 4, 2026

CASE FILE

The Standard Froze TLS 1.2. The Estate Did Not Disappear: RFC 9851

A feature freeze changes what a standards body will design next. It does not reach into a load balancer, find a dependent client or produce the receipt that says a protocol has left production.

Sep 4, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga