AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
734 articles
CASE FILE
A Celestial Name Is Not a Network Address: The Authority Split TIPTOP Has to Preserve
One entity can be discovered under a temporary tag, receive several provisional designations, gain a permanent number and acquire a name years later. A route cannot afford to mistake any one of those labels for proof of where a packet should go.
CASE FILE
A Deprecation Date Is Not a Client Migration Plan
The response is still `200 OK`, but it now carries a date after which the resource will be deprecated. That date can warn a client. It cannot identify who owns the client, whether a replacement preserves its assumptions, or what must be true before the old endpoint can be…
CASE FILE
The IAB Gave Post-Quantum Authentication Evidence Another Week. It Still Needs a Chain of Custody
The extended deadline invites one more week of operational evidence. The harder task begins after a paper arrives: keeping measurements, disclosure choices, workshop synthesis and eventual standards work from collapsing into one unsupported claim.
CASE FILE
A security.txt File Needs a Live Disclosure-Channel Receipt
The `Expires` line says the coordinates are still publishable. It cannot tell a researcher whether anybody is listening. That gap between a fresh file and a working response operation is where a small disclosure-channel receipt becomes useful.
CASE FILE
The Message Was Encrypted. Its Headers Still Needed Their Own Receipts: RFC 9788
An encrypted-mail badge compresses a complicated evidence chain into one reassuring symbol. RFC 9788 shows why the symbol cannot answer which header was hidden, which sender identity was authenticated, what an intermediary changed, or where a reply may safely go.
CASE FILE
An OSPS Baseline Claim Needs a Version, a Level and a Date
“OSPS compliant” looks tidy in a supplier register. It is also incomplete. The Baseline is versioned, divided by project maturity and explicitly assessed at a point in time; a useful claim must preserve those coordinates and the evidence behind them.
CASE FILE
The Key Was Known. It Was Not Yet Trusted
A self-signed DNS update arrives at a parent carrying a new key and an instruction to delete the old one. The signature proves that somebody holds the new private key. It does not prove that this somebody may change the child's delegation. As DNSOP's 7 September Last Call reaches…
CASE FILE
A CA Audit Is Not a Certificate-Issuance Verdict
An annual assurance report can show that a certificate authority’s controls were examined over a bounded period. It cannot, on its own, answer the smaller and more consequential question a relying party often needs to ask: why was this exact certificate for this exact name and…
CASE FILE
Four Bits Looked Like IP. They Were Not: RFC 9790 and the End of Payload Guessing
An MPLS router can see `0x4` after the label stack and reach for an IPv4 hash. RFC 9790 explains why those four bits cannot carry that conclusion on their own.
CASE FILE
A GitHub Actions workflow_run Trigger Is Not an Artifact-Trust Verdict
A GitHub Actions `workflow_run` trigger can create a useful separation between an upstream check and a downstream, more privileged workflow. It does not establish that the upstream result, the artifact consumed downstream, or a later target operation deserves trust.
CASE FILE
A GitHub Actions OIDC Token Is Not a Cloud-Authorization Verdict
A GitHub Actions OIDC token can identify a bounded workflow context to an external provider. It does not, by itself, establish that a cloud trust policy matched, that a cloud session was issued, that a resource permitted an action or that a target changed.
CASE FILE
The Final Dot Vanished. The Trust Boundary Moved with It
Two hostnames can lead DNS to the same node and still lead an application to different security decisions. As the DNSOP Working Group closes its 7 September Last Call on guidance for bringing domain names into applications, a recent curl flaw gives the abstract warning a concrete…
CASE FILE
One Circuit Failed. The Port Did Not: RFC 9784 and the Cost of the Wrong Failure Domain
A provider edge port can carry thousands of virtual services. RFC 9784 asks operators to prove which entity failed before allowing recovery to inherit the size of the container.
CASE FILE
A GitHub Actions Concurrency Group Is Not a Deployment-Serialization Verdict
A GitHub Actions concurrency group can reduce conflicts between named jobs or workflow runs. It does not, on its own, establish the order of every consequential action against a target or the effect of those actions.
CASE FILE
The Timestamp Was More Precise. The Association Still Had to Survive: RFC 9769
RFC 9769 can deliver a transmission time captured closer to the wire by placing it in a later packet. The improvement is real only while the state linking those exchanges remains intact.
CASE FILE
The Root Verified. The Proof Still Could Not Name the Leaf
A one-bit path can point to leaf 1, 2, 4 or 8, depending only on how large the tree was. The current SCITT profile can still prove that a candidate statement belongs under a signed CCF root. What it cannot always do, from the proof alone, is say where that statement sat.
CASE FILE
The Message Fit the Schema. That Still Did Not Make It True: RFC 8927
RFC 8927 builds a deliberately narrow gate for JSON messages. A message that passes has the declared shape; identity, authority, freshness and real-world effect still wait on the other side.
CASE FILE
A Dismissed Dependabot Alert Is Not a Remediation Verdict
A dismissed Dependabot alert records a triage decision about a repository-facing signal. It can be sensible and well documented. It still does not prove that vulnerable code is absent from a deployed system, that an upgrade was accepted, or that a remediation has happened.
CASE FILE
The Relay Appeared on the Local Network. Who Authorized the Advertisement?
A MOQT client can now be told how to find a nearby relay, which protocol label to offer and which name to check in its certificate. The new draft is precise when DNS moves the socket. It is not yet precise about who may put the local relay in front of the client.
CASE FILE
The Client Reported the File Attributes. The Metadata Server Could Still Verify Them: RFC 9766
RFC 9766 gives an NFS client a cheaper way to carry data-file observations back to the metadata server. The design is valuable because it refuses to make that report final: weak evidence can save work without becoming metadata sovereignty.
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga