Re: [mile] Request for draft reviews - review of FC5070-bis

"Moriarty, Kathleen" <kathleen.moriarty@emc.com> Fri, 28 June 2013 14:09 UTC

Return-Path: <kathleen.moriarty@emc.com>
X-Original-To: mile@ietfa.amsl.com
Delivered-To: mile@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6AF2521F9B7C for <mile@ietfa.amsl.com>; Fri, 28 Jun 2013 07:09:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 1.39
X-Spam-Level: *
X-Spam-Status: No, score=1.39 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FRT_STOCK2=3.988, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id YIgLpQCEunaC for <mile@ietfa.amsl.com>; Fri, 28 Jun 2013 07:09:10 -0700 (PDT)
Received: from mexforward.lss.emc.com (hop-nat-141.emc.com [168.159.213.141]) by ietfa.amsl.com (Postfix) with ESMTP id B5D8321F8436 for <mile@ietf.org>; Fri, 28 Jun 2013 07:09:02 -0700 (PDT)
Received: from hop04-l1d11-si02.isus.emc.com (HOP04-L1D11-SI02.isus.emc.com [10.254.111.55]) by mexforward.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id r5SE8o7S026787 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 28 Jun 2013 10:08:50 -0400
Received: from mailhub.lss.emc.com (mailhubhoprd04.lss.emc.com [10.254.222.226]) by hop04-l1d11-si02.isus.emc.com (RSA Interceptor); Fri, 28 Jun 2013 10:08:41 -0400
Received: from mxhub02.corp.emc.com (mxhub02.corp.emc.com [10.254.141.104]) by mailhub.lss.emc.com (Switch-3.4.3/Switch-3.4.3) with ESMTP id r5SE8e9B010538; Fri, 28 Jun 2013 10:08:40 -0400
Received: from mx15a.corp.emc.com ([169.254.1.184]) by mxhub02.corp.emc.com ([10.254.141.104]) with mapi; Fri, 28 Jun 2013 10:08:40 -0400
From: "Moriarty, Kathleen" <kathleen.moriarty@emc.com>
To: "Panos Kampanakis (pkampana)" <pkampana@cisco.com>, "mile@ietf.org" <mile@ietf.org>, "Stoecker, Paul" <Paul.Stoecker@rsa.com>, Roman Danyliw <rdd@cert.org>
Date: Fri, 28 Jun 2013 10:08:39 -0400
Thread-Topic: Request for draft reviews - review of FC5070-bis
Thread-Index: Ac5i4z6UXWFgBViZRm66bWD5p9F0RwRJaugA
Message-ID: <F5063677821E3B4F81ACFB7905573F24DF1B833D@MX15A.corp.emc.com>
References: <1C9F17D1873AFA47A969C4DD98F98A753C8AC8@xmb-rcd-x10.cisco.com>
In-Reply-To: <1C9F17D1873AFA47A969C4DD98F98A753C8AC8@xmb-rcd-x10.cisco.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: multipart/alternative; boundary="_000_F5063677821E3B4F81ACFB7905573F24DF1B833DMX15Acorpemccom_"
MIME-Version: 1.0
X-EMM-MHVC: 1
Subject: Re: [mile] Request for draft reviews - review of FC5070-bis
X-BeenThere: mile@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Managed Incident Lightweight Exchange, IODEF extensions and RID exchanges" <mile.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mile>, <mailto:mile-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mile>
List-Post: <mailto:mile@ietf.org>
List-Help: <mailto:mile-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mile>, <mailto:mile-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 28 Jun 2013 14:09:14 -0000

Roman & Paul,

Can you help with these questions/comments as well?

Thank you,
Kathleen

From: Panos Kampanakis (pkampana) [mailto:pkampana@cisco.com]
Sent: Thursday, June 06, 2013 2:26 PM
To: Moriarty, Kathleen; mile@ietf.org; Stoecker, Paul
Subject: RE: Request for draft reviews - review of FC5070-bis


Hi Paul,

Good starting point. Some comments and nits below from my first pass.
There should be more when I review again.

I remember sometime in the past there was a discussion  about what is an incidents if that should be updated in the 5070. I see that in your draft an incident is used as it was in 5070. I was just wondering if we had reached a consensus on it.


I also didn't see "uid" and "set id" definitions in the draft.


I don't see the EMailDetails class described in the document.

Nits:

- Should "This document contains changes with respect to its predecessor
      RFC5070:" be bulleted?

- The list in "This class will contain indicators from

      the list below " is not exactly below. The same for "the

      following included indicators are ones commonly used ". And the same for me occurrences of "following" in this section

- I am not sure if we want to keep the "<!-- CHANGE:" comments in the draft

- there are some XML complexType like "SoftwareType" that are described as classes in the comments IODEF schema, but these are not classes.



I aqlso see that you will have usecases-examples in this doc, so mayne I will remove mine from the guidance document.


Rgs,
Panos



From: mile-bounces@ietf.org<mailto:mile-bounces@ietf.org> [mailto:mile-bounces@ietf.org] On Behalf Of Moriarty, Kathleen
Sent: Friday, May 17, 2013 2:13 PM
To: mile@ietf.org<mailto:mile@ietf.org>
Subject: [mile] Request for draft reviews

Greetings!

We have had a number of documents updated since the last meeting.  Thank you to all of the editors for making the requested changes!  The current list of drafts up for review (including those that will be a part of the WG after the charter update) include:

RFC5070-bis (IODEF Revision):
http://datatracker.ietf.org/doc/draft-ietf-mile-rfc5070-bis/

Draft on IODEF Guidance:
(input from experience, real use cases, and draft review will be helpful)
http://datatracker.ietf.org/doc/draft-ietf-mile-iodef-guidance/

Structured Cybersecurity Information draft (close to final):
http://datatracker.ietf.org/doc/draft-ietf-mile-sci/

IODEF Enumeration Reference Format:
http://datatracker.ietf.org/doc/draft-montville-mile-enum-reference-format/

Resource-Oriented Lightweight Indicator Exchange (ROLIE):
http://datatracker.ietf.org/doc/draft-field-mile-rolie/

Please take some time to review the drafts and provide feedback to the list.  It would be helpful if we can iterate on most of them prior to the next meeting.  A couple of the drafts are very close to being done.  The list of current drafts and published RFCs can be found at the following link:
http://datatracker.ietf.org/wg/mile/

We will follow up soon on the charter update as well.

Thank you all in advance!
Kathleen