AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
752 articles
CASE FILE
The Certificate Signature Passed. The Handshake Was Not Finished: TLS 1.3 `Finished` and Transcript Authority
The dashboard declared a secure session when the server's CertificateVerify signature passed. One record later, the client rejected a corrupt `Finished` message and closed the connection. The certificate key had proved one thing accurately. Operations had promoted it into proof…
CASE FILE
The Edge Negotiated HTTP/2. The Origin Still Spoke HTTP/1.1: TLS ALPN and the Authority of One Connection
The browser offered `h2` and `http/1.1`. The edge selected `h2`, completed TLS and exchanged valid HTTP/2 frames. A fleet dashboard then labelled the origin “HTTP/2 native.” It was not. The edge terminated that connection and opened a different one upstream, where it sent…
CASE FILE
The CA Was on the List. The Identity Was Not Approved: TLS `certificate_authorities` and the Authority of a Selection Hint
The client chose a certificate whose issuer appeared in the server's CA list. The server built and validated the chain. Then the application rejected the subject because that identity had never been admitted to the tenant. Every cryptographic step could be correct while access…
CASE FILE
The Staple Was Signed. The Status Could Still Be Stale: TLS OCSP and the Authority of a Cached Answer
The certificate was revoked at 10:07. At 10:11, the server still stapled a correctly signed `good` OCSP response whose `nextUpdate` was hours away. Nothing had been forged. The answer was authentic, within its declared interval and already behind reality. The incident began when…
CASE FILE
The Socket Closed. The Transaction Did Not: TLS close_notify and the Authority of an Ending
The payment service wrote a success response, initiated an orderly TLS shutdown and recorded the request as complete. Its database commit failed milliseconds later. The client had received an authentic ending, but not the fact it needed. `close_notify` said the server would send…
CASE FILE
The Ticket Survived. The Session Did Not: TLS 1.3 Resumption and the Authority of Carried State
The failover node accepted a TLS 1.3 session ticket issued before the user’s access was revoked. Cryptographically, the shortcut worked: the client knew the resumption PSK and its binder covered the new handshake. Operationally, the old decision had crossed into a new connection…
CASE FILE
The Record Was Longer. The Message Was Not: TLS 1.3 Padding and the Authority of Observable Length
The incident report treated a larger encrypted record as a larger application message. Its arithmetic was precise and its conclusion was false. The sender had rounded TLS 1.3 records to a block boundary and sometimes emitted padding-only Application Data. The capture established…
CASE FILE
The First Hello Was Rejected. It Was Not Erased: TLS HelloRetryRequest and the Authority of the Transcript
The capture began with a second ClientHello. It offered one key share, the server accepted it, and the handshake completed. Read in isolation, the trace appeared to prove that the client had chosen that group from the start. It proved nothing of the kind. The missing first flight…
CASE FILE
The Client Expected a Certificate. The Library Accepted a Key: TLS Raw Public Keys and the Authority of Negotiation
The key was mathematically usable. That was precisely the problem. In June 2026, wolfSSL disclosed that an RPK-enabled build could accept an unnegotiated Raw Public Key where the peer expected X.509, bypassing certificate-chain validation. The repair did more than reject a format…
CASE FILE
The Proof Arrived After the Connection Began. It Did Not Rewrite the Past: TLS Exported Authenticators and Application Authority
At 14:03, a valid certificate proof arrived on a connection that had already carried hundreds of operations. The service upgraded every stream and relabelled five earlier minutes as authenticated by the new identity. The signature was sound. The history was not. TLS Exported…
CASE FILE
The Certificate Had Not Been Verified. Its Memory Claim Already Had to Be Judged: TLS Compression and the Pre-Trust Boundary
A two-kilobyte handshake message says it will become twelve megabytes after decompression. Before the receiver can inspect a name, a signature or a chain, it must decide whether that unauthenticated claim deserves memory and CPU. RFC 8879 makes certificates smaller on the wire…
CASE FILE
The Edge Received a Key. It Did Not Receive the Certificate: TLS Delegated Credentials and the Boundary of Short-Lived Authority
A front end can finish a TLS 1.3 handshake for the certificate owner without holding the certificate’s long-term private key. What crosses that boundary is powerful but deliberately small: a signed public key, a role, an algorithm and an expiry—not the certificate, the CA…
CASE FILE
The Peer Requested New Keys. It Did Not Own the Epoch: TLS 1.3 KeyUpdate and the Authority to Rotate a Live Connection
One encrypted record leaves under the old key. Every later record from that sender must use the next one. The peer can authenticate the transition and ask for a reciprocal change, but it cannot see whether yesterday’s secret left memory, choose the other endpoint’s work queue, or…
CASE FILE
The Speaker Was in the Session, Not the Path: IXP Route Servers and the Authority to Broker Reachability
The BGP session was established to one system. The route began with another network's AS number. Its next hop named a third address on the exchange fabric, and the packets never crossed the machine that had delivered the UPDATE. Nothing was malformed. The apparent contradiction…
CASE FILE
An RFC Number Does Not Mean the IETF Approved It
A compliance register that records only “RFC 8729” looks precise. It is not. The number identifies a durable document, but it conceals that this particular RFC is an IAB-stream informational statement rather than an Internet Standard. When a single column makes every RFC look…
CASE FILE
The Request Said Urgent. The Scheduler Still Decided: HTTP Priorities and the Authority to Allocate Scarce Delivery
A browser can call a hero image urgent, an origin can prefer the font, and a CDN can see both through a different connection map. RFC 9218 lets each express useful information. It does not let any of them annex the scheduler that finally allocates the next byte.
CASE FILE
The “Obsoletes” Line Is Not a Remote Kill Switch
When RFC 9113 replaced the earlier HTTP/2 specification, the catalogue moved and selected registry references moved with it. A live connection did not. It still negotiated `h2`; no standards editor reached into a server, removed old code or accepted the outage risk on an…
CASE FILE
The Resolver Named the Failure. It Did Not Prove the Cause: Extended DNS Errors and the Authority of Diagnosis
Extended DNS Errors can turn an opaque DNS failure into a useful account of what one resolver observed. The gain is operational clarity. The danger begins when a dashboard promotes that account into proven cause, assigned blame or permission to weaken the control that produced…
CASE FILE
The Token Knew the Address, Not the Actor: DNS Cookies and the Authority of Weak Authentication
A valid DNS Server Cookie proves something useful and deliberately small: a requester using this Client Cookie at this source address previously received a value derived from a server secret. Trouble begins when an operations system promotes that narrow fact into identity, trust…
CASE FILE
An IANA Code Point Is Not a Licence to Deploy
The Internet needs common numbers, strings and names so that independently built systems can understand one another. IANA protocol-parameter registries supply that shared vocabulary. Their authority is real, but deliberately narrow: a registry entry can settle which value carries…
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga