AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
748 articles
CASE FILE
The Charter Opened a Work Queue. It Did Not Migrate a Certificate.
The LAMPS charter now contemplates an unsigned X.509 certificate as a slimmer way to carry trust-anchor subject information. Removing a self-signature can save expensive bytes. It does not make the container trusted, choose a post-quantum algorithm or move one relying party.…
CASE FILE
The Policy Named a Partition. It Did Not Reserve the Resources.
Two candidate paths can point to the same endpoint while carrying different Network Resource Partition identifiers. One 32-bit value changes which underlay resources the headend is meant to invoke. The BGP field can state that association; it cannot create the resources, install…
CASE FILE
Fourteen ACKs Did Not Prove a Window of Twenty-Four
An application sends ten segments, pauses, then supplies four more. Every segment is acknowledged. A naive slow-start counter can call the resulting congestion window twenty-four, although the path has never carried more than ten in one round trip. The IESG has now approved a…
CASE FILE
The Proxy Opened a Port. It Did Not Authorize the Internet.
The IESG has approved an HTTP extension that lets one proxy-bound UDP socket serve many remote peers. Its operational lesson is sharper than the feature: advertising a reachable address allocates a path, while Context IDs, tuple policy and observed forwarding decide who may use…
CASE FILE
The Signature Was Valid. The Token Was Wrong.
The IESG has approved a replacement for the JWT security playbook. Its hardest rule is also its most practical: a receiver must prove not only that a token is authentic, but that this exact kind of token is entitled to cross this exact application boundary.
CASE FILE
The Path Kept Its ID. Its Instructions Changed.
The IESG has approved a compact identifier for segment lists carried in BGP SR Policy. The number can simplify telemetry and cross-system configuration, but it stays meaningful only inside its Candidate Path—and it can remain unchanged while the actual SID sequence changes.
CASE FILE
The Gateway Said “Post-Quantum Ready.” The Tunnel Still Used ECDSA.
The IESG approved a mechanism for post-quantum signature authentication in IKEv2 on 24 August 2026. The decision advances the standards path for ML-DSA and SLH-DSA, but a supported algorithm, an advertised method and an authenticated tunnel remain three different facts.
CASE FILE
IANA Registered a DELEG Capability Key. Deployment Still Needs Proof.
IANA added a temporary `deleg` key to the DNS Resolver Information registry on 24 August 2026. The entry gives operators a common way to declare support for the emerging DELEG protocol; it does not turn an Internet-Draft into a standard or a declaration into running behavior.
CASE FILE
The serial matched. The zone did not
The transfer finished, the file parsed and the SOA serial was exactly the number operations expected. One glue record was nevertheless missing. DNS had long possessed ways to say that a copy was newer and that a transaction came from an approved peer; ZONEMD added a different…
CASE FILE
The First Endpoint Was Preferred. It Was Never Eligible.
An HTTPS record can put one endpoint first and still require a client to ignore it. SVCB makes DNS a publisher of bounded connection plans, not a substitute for compatibility, endpoint authentication or running evidence.
CASE FILE
The Network Named a Provisioning Domain. It Did Not Choose the Path.
A Provisioning Domain can keep one network's addresses, resolvers and routes from contaminating another. It names a coherent context; it does not convert a Router Advertisement into a command that chooses a connection.
CASE FILE
The bridge was gone. The topology still crossed it
Two BGP-LS producers can each retain one stale half of a failed link. A consumer that merges their disclosures may reconstruct a plausible connection that no longer exists, and a controller may compute straight across it. The failure is not simply “bad telemetry.” It exposes who…
CASE FILE
The route existed. The subscription did not
A VPN route can be valid, selected and available at its source while a remote PE correctly receives nothing. RFC 4684 lets Route Target interest travel toward the route and matching reachability travel back. That inverse graph saves state, but it also makes an absent or stale…
CASE FILE
The Child Has Spoken. Who Makes the DS Record Real?
A child zone can publish a perfectly signed request for its next DNSSEC trust state and still be rightfully refused. CDS/CDNSKEY automation works only when signal, acceptance, parent publication and validator observation remain separate facts.
CASE FILE
Zero is not a diagnosis
An alert that says only “BGP saw zero” has thrown away the fact that decides the response. Zero is a valid ORIGIN code, a prohibited autonomous-system identity, and an RPKI disavowal value in three different protocol entities. RFC 7607 makes the distinction operational: refuse…
CASE FILE
Who Owns the Renewal Clock? ACME ARI and the Last Mile of Certificate Replacement
A certification authority can spread renewal work across a day, yet a fleet can still compress that day into one frantic minute. ACME Renewal Information supplies a window; the client, deployment system and live service decide whether that window becomes a safe replacement.
CASE FILE
The Reply Said Success. No Client Had Changed: DHCPv6 Reconfigure and the Authority of a Trigger
A relay can report that configuration changed, a server can answer `Success`, and an authenticated packet can reach a client without any of those events proving that the client now runs different addresses, prefixes or service parameters. DHCPv6 Reconfigure is useful precisely…
CASE FILE
The route outlived the speaker
BGP Long-Lived Graceful Restart can keep a failed peer’s routes for hours or days after ordinary restart protection ends. That buys time, but it also turns stale state into a temporary operating promise whose timer, forwarding basis and exit must be proved.
CASE FILE
The User Matched Twice. The Packet Was Valid: RADIUS CoA and the Authority to Change a Live Session
A correctly protected control request reaches an access router and asks for a new traffic filter. The subscriber name matches two live sessions. Cryptography has answered who sent the packet on this hop. It has not answered which connection may be changed.
CASE FILE
The session stayed green. The routes disappeared
A malformed BGP UPDATE no longer has to take an entire peering session down. That is a major containment gain, but it changes what operators must prove: an Established session can now coexist with a precise set of destinations that the receiver has removed for safety.
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga