AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
758 articles

CASE FILE
Sixty Names Were Defendants; the Statute Still Defined the Claim: Harrods v Sixty Internet Domain Names
The caption did something unusual: it named sixty domain names as defendants. That procedural choice made a dispute over the Harrods name look, for a moment, like a dispute over things rather than people. The Fourth Circuit’s answer was narrower. The names could be before the…

CASE FILE
CIRA’s 20-Endorsement Threshold Has a Separate Conflict Test
CIRA’s September endorsement window gives members a route onto the election ballot. The twenty-supporter threshold works alongside conflict-of-interest rules that treat the two nomination routes differently.

CASE FILE
At Python, an Accepted PEP Is Neither a Release Commitment Nor an Implementation Receipt
Python’s public process deliberately separates the decision on a proposal from the work of making it real. A PEP may be discussed by contributors, resolved by the Steering Council or an approved PEP-Delegate, implemented in CPython, merged to a particular branch and eventually…

CASE FILE
At Apache, a Release Vote Is Neither a Code Veto Nor a Board Technical Decision
At the Apache Software Foundation, a person can commit code, a qualified voter can stop a code change, a PMC can issue a formal release, and the Board can oversee the Foundation. Those acts sit in one institution, but they do not carry the same authority. Treating them as one…

CASE FILE
At OASIS, a Public Review Is Neither the Final Vote Nor a Suggestion
An OASIS standards document can collect comments, pass a Technical Committee ballot and still not be an OASIS Standard. Those are not redundant ceremonies. They are separate decisions with different records, constituencies and thresholds.

CASE FILE
The Name Stayed the Same. The Module Did Not: RFC 9890
RFC 9890 makes a small registry correction with a large evidentiary consequence: a YANG module keeps its name and XML namespace across revisions, so identity alone can never tell an operator which definitions a system actually uses.

CASE FILE
OpenSSF Member Seats Stop at the Project Boundary
OpenSSF publishes a membership table with real fees, real representation routes and real Foundation-level benefits. It also publishes an unusually direct limit: a membership or sponsorship level does not decide a project matter, because project maintainers define that project's…

CASE FILE
OpenJS CPC's New Community Vote Needs a Transition Receipt
This autumn, OpenJS Foundation’s Cross Project Council will replace two separate non-Impact voting paths with one Community Voting Member class. The Charter is unusually clear about the planned change: it names the effective election cycle, caps the new class at five seats and…

CASE FILE
CNCF's TAG-to-TOC Move Needs an Exit-and-Continuity Receipt
Three former Technical Advisory Group leaders entered the Cloud Native Computing Foundation's 2026 Technical Oversight Committee cohort. CNCF says they stepped down from TAG leadership because TOC members may not hold TAG lead positions at the same time. That is a useful public…

CASE FILE
The Slice Identifier Reached the Transport Edge. The Guarantee Still Had to Be Built: RFC 9889
RFC 9889 turns 5G network slicing into a chain of accountable translations: the mobile domain can name a slice, but the transport domain must still classify traffic, allocate resources, install state and prove the resulting service.

CASE FILE
The Token Arrived Before the Call. Verification Still Had to Wait: RFC 9888
The signed identity token reached the destination service first. The telephone call was still crossing a path that could not carry that token with it. RFC 9888 makes this split useful for legacy networks, but it also leaves an operational obligation: two arrivals on two channels…

CASE FILE
The Secure Channel Failed. The Client Was Not Allowed to Fall Back: RFC 9887
RFC 9887 turns a secure-transport upgrade into a rule about authority: when the protected TACACS+ path fails, reachability of the older path does not authorize the client to use it.

CASE FILE
Outsourcing Email Does Not Assign the DMARC Work
A survey of 99,300 domains puts an old procurement assumption under pressure: a hosted mailbox and a working domain-authentication programme are not the same purchase.

CASE FILE
The Tag Resolved. The Aircraft Was Not Located: RFC 9886
The reverse-DNS answer arrived in milliseconds: a public key, a registration certificate and a static Remote ID record. The airspace display was still empty. RFC 9886 explains why both screens can be correct — it makes an aircraft-related identifier resolvable without turning…

CASE FILE
The Capability Was Advertised. The Protocol Was Not Authorized: RFC 9885
A zero-length IS-IS capability can be visible on every change-board screen and still be limited public evidence to authorize one configuration command. RFC 9885 makes that limit explicit: the advertisement is management information, not a protocol trigger, while safe MP-TLV…

CASE FILE
ITU’s Agent-Security Agenda Makes Deployment Part of the Test
A draft programme for ITU’s 7 September workshop asks what evidence integrators should demand from suppliers of agents, tools and models. That puts the security claim where the system acquires its powers—and raises a question about how far a supplier’s earlier test can travel.

CASE FILE
The Path Label Reached the Egress. The Transit Route Stayed Unseen: RFC 9884
One green LSP Ping result can answer a narrow and valuable question: the egress processed a Path Segment Identifier in the control-plane context named by the probe. It cannot reveal the transit route that delivered it. RFC 9884 makes that boundary operationally useful—provided…

CASE FILE
The Request Was Signed. The Other Private Key Was Still Only Asserted: RFC 9883
A certificate request can carry a valid signature and still offer no technical proof that the requester holds the private key named by its new public key. RFC 9883 does this deliberately. It turns the gap into an explicit policy choice—and a revocation dependency that operators…

CASE FILE
RFC 9882 Put SHA-512 in the Field. It Did Not Always Use It
A CMS record can truthfully name SHA-512 while that algorithm contributes nothing to the signature being checked. RFC 9882 requires exactly that combination on one of its two ML-DSA paths. The apparent contradiction disappears only when an auditor follows the bytes rather than…

CASE FILE
WebAuthn's Report Has Four Browser Columns. Independence Needs a Key.
W3C's new WebAuthn Level 3 Recommendation links a fixed test report with four browser columns. The transition record adds that part of Chrome's implementation differs from Edge's. That caveat is important—and incomplete. Product names show where tests ran; they do not tell a…
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga