[mile] Definition of Contact@role value

"Roman D. Danyliw" <rdd@cert.org> Mon, 29 July 2013 13:54 UTC

Return-Path: <rdd@cert.org>
X-Original-To: mile@ietfa.amsl.com
Delivered-To: mile@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C2B6921F9ECA for <mile@ietfa.amsl.com>; Mon, 29 Jul 2013 06:54:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.116
X-Spam-Level:
X-Spam-Status: No, score=-6.116 tagged_above=-999 required=5 tests=[AWL=0.483, BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sI0gUcRB5Ref for <mile@ietfa.amsl.com>; Mon, 29 Jul 2013 06:54:25 -0700 (PDT)
Received: from plainfield.sei.cmu.edu (plainfield.sei.cmu.edu [192.58.107.45]) by ietfa.amsl.com (Postfix) with ESMTP id 5060021F9ED2 for <mile@ietf.org>; Mon, 29 Jul 2013 06:52:59 -0700 (PDT)
Received: from pawpaw.sei.cmu.edu (pawpaw.sei.cmu.edu [10.64.21.22]) by plainfield.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id r6TDqpRL020153 for <mile@ietf.org>; Mon, 29 Jul 2013 09:52:52 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cert.org; s=jthatj15xw2j; t=1375105972; bh=obL7JdJu63B/7IhqI5SoA3V4ePw772fY7mupR6HNles=; h=From:To:Subject:Date:Message-ID:Content-Type: Content-Transfer-Encoding:MIME-Version:Sender:Reply-To:Cc: In-Reply-To:References; b=A0ZIp7yoCqjlacSRFqkWthmnxx2kHfyX6a3Rpt2/fPIj6zIjLkrzWeZ/ys/Mjb4v0 kBk+vjmGd0Q4/egfJ1TPDN/47apEJokqxv2I5t5FT19yzXtCle2uG47C0X6BBVgGPs 25gq6kkj+Nd/U4PuqObxncGenOPIqxhUeaR3sxsk=
Received: from CASCADE.ad.sei.cmu.edu (cascade.sei.cmu.edu [10.64.28.248]) by pawpaw.sei.cmu.edu (8.14.4/8.14.4/1408) with ESMTP id r6TDr0Oa024406 for <mile@ietf.org>; Mon, 29 Jul 2013 09:53:00 -0400
Received: from MARATHON.ad.sei.cmu.edu ([10.64.28.250]) by CASCADE.ad.sei.cmu.edu ([10.64.28.248]) with mapi id 14.02.0318.004; Mon, 29 Jul 2013 09:52:51 -0400
From: "Roman D. Danyliw" <rdd@cert.org>
To: "mile@ietf.org" <mile@ietf.org>
Thread-Topic: Definition of Contact@role value
Thread-Index: Ac6MU+caXs+MWqFrR0CoutO8XzK6Cw==
Date: Mon, 29 Jul 2013 13:52:51 +0000
Message-ID: <359EC4B99E040048A7131E0F4E113AFC13C561D2@marathon>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.64.22.6]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: [mile] Definition of Contact@role value
X-BeenThere: mile@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: "Managed Incident Lightweight Exchange, IODEF extensions and RID exchanges" <mile.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/mile>, <mailto:mile-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/mile>
List-Post: <mailto:mile@ietf.org>
List-Help: <mailto:mile-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/mile>, <mailto:mile-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 29 Jul 2013 13:54:42 -0000

Hi!

Contact@role currently has the following enumerated values:

1.  creator.  The entity that generate the document.
2.  admin.  An administrative contact for a host or network.
3.  tech.  A technical contact for a host or network.
4.  irt.  The CSIRT involved in handling the incident.
5.  cc.  An entity that is to be kept informed about the handling of the incident.
6.  ext-value.  An escape value used to extend this attribute.

This text from RFC5070 strikes me as fairly ambiguous.  Do these read more clearly?

1.  creator.  The entity that reported the event or activity.
2.  admin.  The business owner of a host or network.
3.  tech.  The entity managing the host or network.
4.  irt. The primary CSIRT responding to this event or activity.
5.  cc.  same as above
6.  ext-value.  same as above

Is there a need to define additional roles?  Perhaps, the following:

7. user.  The end-user of the host or network
8. cc-irt.  The CSIRT or ISAC coordinating response to this event or activity

Roman