AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
755 articles
CASE FILE
The Older Service Record Won. The Service Had Already Moved
A name collision is supposed to stop a newcomer from impersonating an established local service. Put two registration proxies between the service and that local link, however, and the same safeguard can protect yesterday’s address from today’s legitimate update. DNSSD’s proposed…
CASE FILE
The EAP Method Succeeded. The Protected Session Still Needed a Second Witness: RFC 9820
The access controller displayed three green facts: the EAP method had succeeded, the Master Session Key had been exported, and the constrained device had been placed in the security domain. Only the first two facts could be reconstructed. No one could produce the protected…
CASE FILE
The IESG Approved Three ML-KEM Groups. The Registry Recommended None
An approved IETF document can define exactly how three post-quantum groups travel through TLS while leaving the deployment verdict deliberately unresolved. That is not bureaucratic ambiguity. It is a precise boundary between an interoperable mechanism, a registry coordinate and…
CASE FILE
The Switch Executed the Program. It Did Not Inherit the Right to Read, Rewrite or Decide: RFC 9817
A program that runs inside a switch or network interface card is no longer merely near the traffic. It can become part of the path by which traffic is classified, transformed, delayed, replicated or converted into a control action. RFC 9817 catalogs the opportunity and, more…
CASE FILE
All Three Attestations Were True. They Still Did Not Belong to the CSR Key
A certification request can arrive with one valid statement about an HSM, another about corporate ownership and a third about platform health. The dangerous moment comes when a certificate authority treats three successful checks as one joined fact. Revision 29 of an IETF draft…
CASE FILE
One Timer Drove Three IPv6 Decisions. The Counters Could Not Explain Which One
A network team changes one millisecond value on an IPv6 interface. Address resolution, reachability probing and duplicate-address detection all inherit it. The edit receipt is precise; the operational meaning is not, until the team joins the change to an interface, an epoch and…
CASE FILE
The Route Reflector Distributed the Link. It Never Witnessed It: RFC 9815's Sparse-Peering Evidence Boundary
A route reflector can hold the newest authenticated account of a data-centre link and still know nothing directly about whether that link carries a packet. RFC 9815 makes this separation operationally useful: BGP can distribute a link-state graph over far fewer sessions than the…
CASE FILE
The Packet Had No SRH. It Could Still Target an SRv6 SID
An edge filter inspects an IPv6 packet, finds no Segment Routing Header and lets it pass. The packet still carries a locally instantiated SRv6 SID as its destination. The visible header test succeeded; the admission decision examined the wrong fact.
CASE FILE
The HSM Signed a Small Attribute Set. The Large CMS Content Was Bound Through One Digest: RFC 9814
An operator can truthfully say that a hardware security module produced an SLH-DSA signature while still leaving the most important question unanswered: which bytes did the module actually sign? RFC 9814 makes that question decisive for CMS. A multi-gigabyte archive may never…
CASE FILE
The IP Address Stopped Naming the RADIUS Client. The Cleartext PSK Identity Took Over: RFC 9813
Two network access servers can stand behind one public address, while one mobile appliance can appear from several addresses in a week. RFC 9813 lets RADIUS/TLS distinguish those relationships with a PSK Identity. The useful part is not the new name. It is the sequence of checks…
CASE FILE
The Indicator Was Defanged. Its Next Consumer Could Still Arm It
A security analyst pastes a bracketed address into a ticket. It looks inert, and in that surface it may be. Minutes later, a preview worker extracts the same string, restores its URI form and fetches it for inspection. The analyst never clicked. The ticketing chain still crossed…
CASE FILE
The HTTP Request Returned 200. The Certificate Decision Was Still Inside: RFC 9811
A green transport result is tempting because it is immediate, familiar and easy to graph. RFC 9811 makes that result useful without letting it impersonate the certificate-management decision carried inside it. The distinction is small enough to fit in one response and important…
CASE FILE
The Device Can Last for Years. Its Trust Anchor Cannot Be Treated as a Lifetime Constant
A field sensor can remain bolted to a bridge long after its manufacturer changes owners, its issuing CA rolls over and its original algorithm becomes uncomfortable. The device still has power. The network still reaches it. Yet whether it can trust the next service chain depends…
CASE FILE
The Space Was Reserved. One Executive Approval Was Still Too Weak: RFC 9812
Nearly seven-eighths of IPv6 address space was being held for a future that had not arrived. The registry called it reserved, but the rule for releasing a major piece could still be satisfied by an executive approval with no RFC. RFC 9812 repaired that mismatch without pretending…
CASE FILE
The IETF Approved Stateful NAT64 as an Internet Standard. The Shared IPv4 Pool Still Needs a Claim Ledger
An IPv6-only subscriber opens an ordinary connection to an IPv4 server. For a few minutes, a public IPv4 address and port become that subscriber's usable external identity. The address is shared, the claim expires, and the proof lives inside a translator. The IETF has now…
CASE FILE
The Server Never Saw the Password. Its OPRF Seed Still Defined the Blast Radius: RFC 9807
OPAQUE gives password authentication an unusually valuable property: the server need not learn the password, even when the account is registered. RFC 9807 also makes the harder truth visible. A secret can disappear from one side of a protocol while authority remains concentrated…
CASE FILE
The Registry Closed, but the Packets Still Knock: RFC 9805 and Router Alert's Residual Authority
The IETF has stopped future protocols from asking IPv6 routers for special attention through Router Alert. It has not stopped the installed protocols that already ask. That distinction turns a small registry change into a case study in how the Internet freezes a dangerous…
CASE FILE
The CDN Advertised a Ceiling. It Did Not Reserve the Service: RFC 9808
A new interconnection vocabulary lets one CDN publish capacity limits and aligned telemetry to another. The useful fact is narrower than the comforting one: the numbers can discipline delegation without guaranteeing that capacity has been reserved, a request will be admitted or…
CASE FILE
The Certificate Named Four Purposes. The Relying Party Still Had to Separate Them: RFC 9809
A new X.509 vocabulary distinguishes configuration, trust-anchor changes, update packages and safety-sensitive communication. Its value begins where its authority ends: the names travel, while combination policy, operational permission and proof of outcome remain local.
CASE FILE
The Standard Froze TLS 1.2. The Estate Did Not Disappear: RFC 9851
A feature freeze changes what a standards body will design next. It does not reach into a load balancer, find a dependent client or produce the receipt that says a protocol has left production.
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga