Skip to main content

Governance / Case File

CASE FILE

Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institutional BreakdownLegal and Policy ConflictElection and Control Risk
CASE FILE signal visual
Governance / Case FileCASE FILE
Active Dossiers1 Live Case

AFRINIC saga currently tracked end-to-end.

Primary DomainGovernance

Institution legitimacy and continuity risk mapping.

MethodSignal + Timeline + Failure Paths

Primary-source based timeline and risk analysis.

Decision ValueHigh

Used for continuity and policy exposure planning.

Latest Coverage

Latest from CASE FILE

748 articles

CASE FILE

W3C’s Web Performance Charter Separates Implementer Interest From Interoperability

W3C has approved a new charter for the Web Performance Working Group through August 2028. Its most consequential governance choice is a distinction, not a deliverable: two implementors may express interest in a feature before it enters a specification maintained as a Candidate…

Aug 31, 2026

CASE FILE

The TACACS+ Server Was Configured. Its Authority Was Not: RFC 9950

RFC 9950 gives a device a precise YANG surface for configuring TACACS+ servers, credentials and safeguards. That configuration can change a powerful future control path; it is not an authentication event, an authorization result or a proof that a server may decide for anyone.

Aug 31, 2026

CASE FILE

The Test Was Authenticated. The Capacity Claim Was Not: RFC 9946

UDPSTP can authenticate its control exchange, limit a short diagnostic test and feed status back to a sender. RFC 9946 does not convert any resulting number into a capacity entitlement, a service guarantee or an operator verdict.

Aug 31, 2026

CASE FILE

The CMC Message Arrived. It Did Not Arrive With Certificate Authority: RFC 10003

One CMC entity can travel by file, mail, HTTP or TCP. RFC 10003 makes that portability useful without turning any carrier, delivery receipt or listener into proof that a certificate authority made a decision.

Aug 31, 2026

CASE FILE

The Key Became Portable. Custody Did Not: RFC 9964, ML-DSA and the AKP Boundary

Post-quantum migration often arrives in a deceptively tidy form: choose a new algorithm, register an identifier, put a key in the familiar container, and continue signing. RFC 9964 does something more useful and more limited. It defines how ML-DSA keys and signatures can travel…

Aug 31, 2026

CASE FILE

A Completed SCIM Request Is Not a Completed Cross-Domain Decision: RFC 9967

An asynchronous identity request is easy to over-read. A provider accepts a SCIM change, returns 202, and later emits a Security Event Token that carries the same transaction value. The trail is valuable: it gives two parties something specific to correlate. But it does not…

Aug 31, 2026

CASE FILE

W3C’s Human-Rights Note Proposed a Group Six Days After It Launched

On 4 August, W3C’s Advisory Board published five proposals for bringing human-rights considerations further into the consortium’s technical work. The third proposal treated a Threats and Harms Community Group as a possible next step. W3C’s own community record tells the…

Aug 31, 2026

CASE FILE

The Legacy Code Point Reached the Client. It Did Not Reauthorise the Server: RFC 9963

An IANA code point can look like a broad permission slip when it appears in a migration review. RFC 9963 is deliberately narrower. It gives TLS 1.3 three legacy RSASSA-PKCS1-v1_5 signature values, but only for a client proving possession of a client-certificate key after a server…

Aug 31, 2026

CASE FILE

The Reverse Socket Arrived. The Device Had Not Yet Identified Itself: RFC 10011 and RESTCONF Call Home

A controller can receive a connection from the direction it expected, on a listener it deliberately opened, after a device has been configured to call home. That is useful evidence. It is not yet the same thing as knowing which device has arrived, establishing a RESTCONF session…

Aug 31, 2026

CASE FILE

W3C’s WebAppSec Charter Draft Gives 16 of 17 Deliverables No Completion Date

W3C’s proposed Web Application Security charter is unusually candid about time: almost every normative deliverable says its expected completion is undetermined. That is not evidence that sixteen specifications are late. It is evidence that the charter maps authority better than…

Aug 31, 2026

CASE FILE

The Quantum-Safe Key Was Added. The Classical Recipient Still Opened the Mail: RFC 9980

RFC 9980 gives OpenPGP a post-quantum vocabulary, including composite encryption keys that combine ML-KEM with X25519 or X448. That is an important interoperability step. It is also easy to overstate. A message can carry a genuinely PQ/T-capable recipient key and still be…

Aug 31, 2026

CASE FILE

The Model Could Explain the Network. It Could Not Authorize the Change: NEMOPS and the Boundary Between Visibility and Control

The NEMOPS workshop report asks for better models, observability, tooling and verification in network management. Those are valuable improvements in what an operator can see and test. They do not decide whose service may be changed, which risk is acceptable, or who bears the cost…

Aug 31, 2026

CASE FILE

The Fast Packet Kept the Session Up. It Did Not Authorise the Change: RFC 9985

RFC 9985 offers a disciplined answer to an awkward operational fact: a protocol can need frequent authenticated liveness packets at a rate that makes identical expensive authentication hard to sustain. Its answer is a split, not a blank cheque. Stronger-in-cost authentication…

Aug 31, 2026

CASE FILE

APT’s PP-26 Common Proposals Can Advance Without Regional Unanimity

The Asia-Pacific Telecommunity has finished its last scheduled preparatory meeting before ITU’s 2026 Plenipotentiary Conference. What happens next is easy to compress into a misleading phrase: “the region’s proposals.” APT’s own rules are more precise. They create a preliminary…

Aug 31, 2026

CASE FILE

An OAM Requirement Was Written Down. It Did Not Prove a Working Diagnostic: RFC 9974 and BIER Evidence

A requirements catalogue can sharpen an engineering question. It cannot, on its own, answer whether a particular network can run the test, what the test observed, or who may act on it.

Aug 31, 2026

CASE FILE

The Signed Time Saved a Transfer. It Did Not Prove a Moment: RPKI, RFC 9589 and the Switchover Boundary

A RPKI relying party can keep validating useful repository material after its preferred delivery path fails without pretending that a signed timestamp is a trustworthy clock. RFC 9589 makes that distinction operational: one CMS attribute can align filesystem comparison across…

Aug 31, 2026

CASE FILE

Four Thousand Was a Prefix Claim, Not a Rate-Limit Mandate: RFC 9977 and the Evidence Boundary

A prefix file can make an address range easier to group. It cannot convert a count of end sites into a command to relax a local risk control.

Aug 31, 2026

CASE FILE

W3C Is Considering Web Speech for Audio. The Charter Draft Still Excludes It

W3C has publicly opened a route for Web Speech API to enter the Audio Working Group, but the document that would confer that authority has not caught up. The recharter issue calls adoption a substantive scope change; the draft charter still says speech recognition and synthesis…

Aug 31, 2026

CASE FILE

The Certificate Verified the Peer. The External PSK Still Needed a Custodian: RFC 9973 and TLS Authority

A security review can make an unusually comforting statement: the client validated the certificate, the server selected an external pre-shared key, the handshake finished, and the traffic was encrypted. Every clause may be true. None answers the question a security owner…

Aug 31, 2026

CASE FILE

The BFD Counter Rose. The Service Path Was Still Unproven: RFC 9978 and Stability Evidence

A BFD session can stay Up while control packets disappear inside its Detection Time. RFC 9978 makes that early deterioration observable. It does not turn a control-packet counter into proof of data-plane loss, a failed route, or a customer-facing outage.

Aug 31, 2026

Member Unlock

Restricted Profile Intelligence

Login is required to unlock full profile briefings and deep-dive sections.

Only for Strategic Circle

Strategic Circle Briefing

Join to unlock strategic briefings after signing in.

Join Strategic Circle
Only for Leadership Alliance

Leadership Alliance Briefing

For qualified IP-asset owners and management; sign in to unlock alliance briefings.

Join Leadership Alliance

Session Map

Active Dossiers

AFRINIC Saga

Multi-year governance and legal crisis with implications for RIR accountability worldwide.

Open AFRINIC Saga