Re: [OPSAWG] I-D Action: draft-ietf-opsawg-sbom-access-18.txt

Dick Brooks <dick@reliableenergyanalytics.com> Mon, 08 May 2023 22:02 UTC

Return-Path: <dick@reliableenergyanalytics.com>
X-Original-To: opsawg@ietfa.amsl.com
Delivered-To: opsawg@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 473CFC14CF18 for <opsawg@ietfa.amsl.com>; Mon, 8 May 2023 15:02:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.094
X-Spam-Level:
X-Spam-Status: No, score=-2.094 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=reliableenergyanalytics.com header.b="W1oK4Ed4"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="NDTMaKJ7"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id P07miZy67RGi for <opsawg@ietfa.amsl.com>; Mon, 8 May 2023 15:02:29 -0700 (PDT)
Received: from out4-smtp.messagingengine.com (out4-smtp.messagingengine.com [66.111.4.28]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 12D3FC14CE30 for <opsawg@ietf.org>; Mon, 8 May 2023 15:02:27 -0700 (PDT)
Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by mailout.nyi.internal (Postfix) with ESMTP id 06E375C00F2; Mon, 8 May 2023 18:02:27 -0400 (EDT)
Received: from mailfrontend1 ([10.202.2.162]) by compute5.internal (MEProxy); Mon, 08 May 2023 18:02:27 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= reliableenergyanalytics.com; h=cc:content-transfer-encoding :content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to :reply-to:sender:subject:subject:to:to; s=fm1; t=1683583347; x= 1683669747; bh=4Zdb9KwntHYrdztJq/5gFtVkLGh/9UG3nm4jsHum+34=; b=W 1oK4Ed4sVcjvuC0nidL+3NMGAIg3B46DzWZG9jc5m7Q7LLEd6/6qeXxgTum3/noI DFyuGKSoBHBIYxzsIprlpzMLfjgbLPnlED5nRVUqMyPYNsMn5g1qHbKz2LLD/1gv V8Ns72eZUukzn8MtQjXo4GeOrYJbNegOMwuCUmnhRRXVVlQrjBOYN+AbRWugx2Jq FacpF/awClpnqyZFT4/xr3Keqlm/vi122cri+sVXGBmwqLGcUhIa4Jp+amcAh3Ar 7MooBqemiXdklZiLtvNK0micjENcK6PAADhZuEH8/2tmpsNPcTGe67CY3yTz2Y+H Xpvta/xShpRRAxoNvkgsQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :content-type:date:date:feedback-id:feedback-id:from:from :in-reply-to:in-reply-to:message-id:mime-version:references :reply-to:reply-to:sender:subject:subject:to:to:x-me-proxy :x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s=fm3; t= 1683583347; x=1683669747; bh=4Zdb9KwntHYrdztJq/5gFtVkLGh/9UG3nm4 jsHum+34=; b=NDTMaKJ7VlohOQchMFn976KyPq058NS4Wm82o3hPFb6rPzGjXLU pA7Lg3mtI885l0qFbY8cCVPb1P6qIminkh7KZ0NuCvAIT0ZL8VQYwiOnxnsjS9FH QZVUtWXwZuNteSMHk/cProUltMNezy6Yyr0Ek5OM4jtp5yFKTGqkeDuG8ltK7NhV /DS2AcK4AxnaE3NanOGNiCGIkXqhX/72gWHyhtOWllBGd75WsSyw/DEZyWTqAOVT 3F9jO7FCklT+VKObll/7rB/M6vn1zBkbX8vSA9AqcM9ytl6XqPbyfD+ZLA0L0fHX C63b7ONneIKEaN/dTy6LmjAnqsPB475J58Q==
X-ME-Sender: <xms:cnFZZIJ_qDJmpkJVP_A6Vq4CszUcGGWoZz4uEZx8l678JVC6syePyQ> <xme:cnFZZIIyG4QEUPIPfVfITOiAFNIST0njbCkVrz0H4oCwWH5H9vx34MND9rk_a3Rt7 m_hNnYnEn31lfJpAg>
X-ME-Received: <xmr:cnFZZIulLfKXXSsxNzwC9fwBgOjHrLWJsCFsFblpI8Q1UAK4eCT0Z78>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvhedrfeefledgtdegucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucesvcftvggtihhpihgvnhhtshculddquddttddmne cujfgurheprhfhvfhfjgfuffhokfggtgfgofhtsehtqhhgtddvtdejnecuhfhrohhmpedf ffhitghkuceurhhoohhkshdfuceoughitghksehrvghlihgrsghlvggvnhgvrhhghigrnh grlhihthhitghsrdgtohhmqeenucggtffrrghtthgvrhhnpefghffhkeejveelgfeihfdv geethefhffffkeehudeitefghfduiefgffefudejjeenucffohhmrghinheprhgvlhhirg gslhgvvghnvghrghihrghnrghlhihtihgtshdrtghomhdpihgvthhfrdhorhhgnecuvehl uhhsthgvrhfuihiivgeptdenucfrrghrrghmpehmrghilhhfrhhomhepughitghksehrvg hlihgrsghlvggvnhgvrhhghigrnhgrlhihthhitghsrdgtohhm
X-ME-Proxy: <xmx:cnFZZFbKMYsOYdkYM3SJBHTR_6uZH7nGR7Ka48y78xjR2qhMO7DiXA> <xmx:cnFZZPYuiFdvPjqxWPV_HU-zew3h2oeUV6TTaw0sD9bJ69j4rrxtsA> <xmx:cnFZZBCf277O32kx_TQukRAxhwaj11YpridP06ECw9XaFALajNUBWA> <xmx:c3FZZADJF_ydufCoPt0nazx1u-Y2JqX5rz7CkbAIFTeKKlmWMxYNkQ>
Feedback-ID: i57d944d0:Fastmail
Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 8 May 2023 18:02:26 -0400 (EDT)
Reply-To: dick@reliableenergyanalytics.com
From: Dick Brooks <dick@reliableenergyanalytics.com>
To: 'Eliot Lear' <lear@lear.ch>, opsawg@ietf.org
References: <168270728434.50055.14139324263270906984@ietfa.amsl.com> <93ec8c12-531a-317e-0130-61bd3dc2ce81@lear.ch>
In-Reply-To: <93ec8c12-531a-317e-0130-61bd3dc2ce81@lear.ch>
Date: Mon, 08 May 2023 18:02:23 -0400
Organization: Reliable Energy Analytics LLC
Message-ID: <da6601d981f8$c6f46c00$54dd4400$@reliableenergyanalytics.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Thread-Index: AQFp7VxlG5cdRAVgYo3kJMgR3RQB2gJkglFUsBzyj2A=
Content-Language: en-us
Archived-At: <https://mailarchive.ietf.org/arch/msg/opsawg/CFsQYpG2JVMoekF8v7vdeTJTl5I>
Subject: Re: [OPSAWG] I-D Action: draft-ietf-opsawg-sbom-access-18.txt
X-BeenThere: opsawg@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OPSA Working Group Mail List <opsawg.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/opsawg>, <mailto:opsawg-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/opsawg/>
List-Post: <mailto:opsawg@ietf.org>
List-Help: <mailto:opsawg-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/opsawg>, <mailto:opsawg-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 May 2023 22:02:33 -0000

Congratulations, Eliot. 
I just saw the IESG announcement.

Thanks,

Dick Brooks
  
Active Member of the CISA Critical Manufacturing Sector, 
Sector Coordinating Council – A Public-Private Partnership

Never trust software, always verify and report! ™
http://www.reliableenergyanalytics.com
Email: dick@reliableenergyanalytics.com
Tel: +1 978-696-1788


-----Original Message-----
From: OPSAWG <opsawg-bounces@ietf.org> On Behalf Of Eliot Lear
Sent: Friday, April 28, 2023 2:45 PM
To: opsawg@ietf.org
Subject: Re: [OPSAWG] I-D Action: draft-ietf-opsawg-sbom-access-18.txt

This version makes the change for vuln-url to be a leaf-list.  If we can let that soak for a week?

Eliot

On 28.04.23 20:41, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts 
> directories. This Internet-Draft is a work item of the Operations and 
> Management Area Working Group (OPSAWG) WG of the IETF.
>
>     Title           : Discovering and Retrieving Software Transparency and Vulnerability Information
>     Authors         : Eliot Lear
>                       Scott Rose
>     Filename        : draft-ietf-opsawg-sbom-access-18.txt
>     Pages           : 21
>     Date            : 2023-04-28
>
> Abstract:
>     To improve cybersecurity posture, automation is necessary to locate
>     the software a device is using, and whether that software has known
>     vulnerabilities, and what, if any recommendations suppliers may have.
>     This memo extends the MUD YANG schema to provide the locations of
>     software bills of materials (SBOMS) and to vulnerability information
>     by introducing a transparency schema.
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-opsawg-sbom-access/
>
> There is also an htmlized version available at:
> https://datatracker.ietf.org/doc/html/draft-ietf-opsawg-sbom-access-18
>
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-opsawg-sbom-acces
> s-18
>
> Internet-Drafts are also available by rsync at 
> rsync.ietf.org::internet-drafts
>
>
> _______________________________________________
> OPSAWG mailing list
> OPSAWG@ietf.org
> https://www.ietf.org/mailman/listinfo/opsawg
>

_______________________________________________
OPSAWG mailing list
OPSAWG@ietf.org
https://www.ietf.org/mailman/listinfo/opsawg