AFRINIC saga currently tracked end-to-end.
Governance / Case File
CASE FILE
Case File governance intelligence tracks institutions, policy processes, standards activity, registry operations, accountability disputes, and implementation signals that affect internet infrastructure. BTW.

Institution legitimacy and continuity risk mapping.
Primary-source based timeline and risk analysis.
Used for continuity and policy exposure planning.
Latest Coverage
Latest from CASE FILE
748 articles
CASE FILE
The Key Was Known. It Was Not Yet Trusted
A self-signed DNS update arrives at a parent carrying a new key and an instruction to delete the old one. The signature proves that somebody holds the new private key. It does not prove that this somebody may change the child's delegation. As DNSOP's 7 September Last Call reaches…
CASE FILE
A CA Audit Is Not a Certificate-Issuance Verdict
An annual assurance report can show that a certificate authority’s controls were examined over a bounded period. It cannot, on its own, answer the smaller and more consequential question a relying party often needs to ask: why was this exact certificate for this exact name and…
CASE FILE
Four Bits Looked Like IP. They Were Not: RFC 9790 and the End of Payload Guessing
An MPLS router can see `0x4` after the label stack and reach for an IPv4 hash. RFC 9790 explains why those four bits cannot carry that conclusion on their own.
CASE FILE
A GitHub Actions workflow_run Trigger Is Not an Artifact-Trust Verdict
A GitHub Actions `workflow_run` trigger can create a useful separation between an upstream check and a downstream, more privileged workflow. It does not establish that the upstream result, the artifact consumed downstream, or a later target operation deserves trust.
CASE FILE
A GitHub Actions OIDC Token Is Not a Cloud-Authorization Verdict
A GitHub Actions OIDC token can identify a bounded workflow context to an external provider. It does not, by itself, establish that a cloud trust policy matched, that a cloud session was issued, that a resource permitted an action or that a target changed.
CASE FILE
The Final Dot Vanished. The Trust Boundary Moved with It
Two hostnames can lead DNS to the same node and still lead an application to different security decisions. As the DNSOP Working Group closes its 7 September Last Call on guidance for bringing domain names into applications, a recent curl flaw gives the abstract warning a concrete…
CASE FILE
One Circuit Failed. The Port Did Not: RFC 9784 and the Cost of the Wrong Failure Domain
A provider edge port can carry thousands of virtual services. RFC 9784 asks operators to prove which entity failed before allowing recovery to inherit the size of the container.
CASE FILE
A GitHub Actions Concurrency Group Is Not a Deployment-Serialization Verdict
A GitHub Actions concurrency group can reduce conflicts between named jobs or workflow runs. It does not, on its own, establish the order of every consequential action against a target or the effect of those actions.
CASE FILE
The Timestamp Was More Precise. The Association Still Had to Survive: RFC 9769
RFC 9769 can deliver a transmission time captured closer to the wire by placing it in a later packet. The improvement is real only while the state linking those exchanges remains intact.
CASE FILE
The Root Verified. The Proof Still Could Not Name the Leaf
A one-bit path can point to leaf 1, 2, 4 or 8, depending only on how large the tree was. The current SCITT profile can still prove that a candidate statement belongs under a signed CCF root. What it cannot always do, from the proof alone, is say where that statement sat.
CASE FILE
The Message Fit the Schema. That Still Did Not Make It True: RFC 8927
RFC 8927 builds a deliberately narrow gate for JSON messages. A message that passes has the declared shape; identity, authority, freshness and real-world effect still wait on the other side.
CASE FILE
A Dismissed Dependabot Alert Is Not a Remediation Verdict
A dismissed Dependabot alert records a triage decision about a repository-facing signal. It can be sensible and well documented. It still does not prove that vulnerable code is absent from a deployed system, that an upgrade was accepted, or that a remediation has happened.
CASE FILE
The Relay Appeared on the Local Network. Who Authorized the Advertisement?
A MOQT client can now be told how to find a nearby relay, which protocol label to offer and which name to check in its certificate. The new draft is precise when DNS moves the socket. It is not yet precise about who may put the local relay in front of the client.
CASE FILE
The Client Reported the File Attributes. The Metadata Server Could Still Verify Them: RFC 9766
RFC 9766 gives an NFS client a cheaper way to carry data-file observations back to the metadata server. The design is valuable because it refuses to make that report final: weak evidence can save work without becoming metadata sovereignty.
CASE FILE
A Yanked PyPI Release Is Not a Package Withdrawal Verdict
A PyPI yank changes how a repository presents a release to selection tools. It can be an important signal for maintainers and consumers, particularly when a release is broken or violates a compatibility promise. It is not, by itself, a record that a package has been deleted, that…
CASE FILE
A Kubernetes NetworkPolicy Is Not a Network-Flow Verdict
A Kubernetes `NetworkPolicy` can be a disciplined way to declare which layer-3/4 connections should be allowed for selected Pods. It is not a transcript of a particular connection. It cannot, by its existence, prove that a CNI implementation enforced it at a stated instant, that…
CASE FILE
The Second Approval Could Be Prepared Before the First Was Signed
Revision 04 of EP-QUORUM fixes an unusually revealing defect: its earlier “strong” approval chain linked contexts that could all exist before any human signed. The replacement makes each successor depend on the completed predecessor proof. That repairs cryptographic causality…
CASE FILE
One Durable Name, a Fresh Route at Every Hop: RFC 9758
RFC 9758 gives a resource a compact name that can survive movement. That durability comes from what the name refuses to contain: no location, no reachability promise and no route. Each relay must still decide what the identifier means here and now.
CASE FILE
A GitHub Ruleset Bypass Actor Is Not a Bypass Event
A repository can deliberately name the people, roles, teams, apps or keys that may bypass a GitHub ruleset. That is an important control decision. It is not a record that any one of them did so on a particular ref, and it is not a substitute for the separate records of review…
CASE FILE
The Hashes Matched. That Did Not Prove the Network Was Right
Revision 01 of the proposed IS-IS Aggregated SNP Hash exchange can make a million-fragment database cheaper to compare. Its restraint matters more than its speed: a matching summary ends a search for differences, but does not authenticate the state, validate the topology or prove…
Member Unlock
Restricted Profile Intelligence
Login is required to unlock full profile briefings and deep-dive sections.
Strategic Circle Briefing
Join to unlock strategic briefings after signing in.
Join Strategic CircleLeadership Alliance Briefing
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership AllianceSession Map
Active Dossiers
AFRINIC Saga
Multi-year governance and legal crisis with implications for RIR accountability worldwide.
Open AFRINIC Saga