Re: [secdir] Secdir review of draft-ietf-mile-enum-reference-format-10

"Adam W. Montville" <> Fri, 12 December 2014 17:15 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id B22C71A1BAA; Fri, 12 Dec 2014 09:15:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id HGQhRvjJltq8; Fri, 12 Dec 2014 09:15:37 -0800 (PST)
Received: from ( [IPv6:2607:f8b0:4003:c01::236]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by (Postfix) with ESMTPS id EB1191A6FBE; Fri, 12 Dec 2014 09:15:36 -0800 (PST)
Received: by with SMTP id wo20so9122507obc.13 for <multiple recipients>; Fri, 12 Dec 2014 09:15:36 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;; s=20120113; h=content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=EEIaENm6yJIOWBbCBrv03oIzjU/IjeiHC4ZY9d1mVy0=; b=CzQJqhTZ8MGMWOQn5Ep6xVIl9rS9yoVUJBvw8Oot3uCm2gpJOsIOhTsDC9ZFczUKaL LYzioO+hrkE7MZNRwwvtI0JixhAJimImH0cEg/LNIL/6952pKNFyfauGGvdhZKx/9I+i N0GjxGMs0K5A+bAZMslK2cG05mcT7xhTKJK52ajYp5cvWXZZv5b36RxOYartcOPygn4S Ug8kzTQxpqy3H97A/GdwN1eoklbWnBId9oXeSXqZ2uUTMmbA1bZKDc6Qp0gbqFElAHkO DX+lC98lk81/EvzcspESe/DLMz10NyP7prZ7YUxRocpXskDmJuc6qvBqsvLPamRi6HrX vaog==
X-Received: by with SMTP id j7mr7417487oet.80.1418404536145; Fri, 12 Dec 2014 09:15:36 -0800 (PST)
Received: from ?IPv6:2602:306:3406:4f00:1111:5e16:86f:8e4d? ([2602:306:3406:4f00:1111:5e16:86f:8e4d]) by with ESMTPSA id rh7sm787096oeb.0.2014. for <multiple recipients> (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128); Fri, 12 Dec 2014 09:15:35 -0800 (PST)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (Mac OS X Mail 8.1 \(1993\))
From: "Adam W. Montville" <>
In-Reply-To: <>
Date: Fri, 12 Dec 2014 11:15:33 -0600
Content-Transfer-Encoding: quoted-printable
Message-Id: <>
References: <> <>
To: "Zhangdacheng (Dacheng)" <>
X-Mailer: Apple Mail (2.1993)
Cc: The IESG <>, "" <>, "" <>
Subject: Re: [secdir] Secdir review of draft-ietf-mile-enum-reference-format-10
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Fri, 12 Dec 2014 17:15:40 -0000

Hi Dacheng,

Thank you for your review…responses inline.


> On Dec 9, 2014, at 9:50 PM, Zhangdacheng (Dacheng) <> wrote:
> I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors and WG chairs should treat these comments just like any other last call comments.
> This document is establishing a container for publicly available enumeration values to be included in an IODEF [IODEF] document. Several questions about the proposed solution are listed as follows. 
> 1)	In this specification, a given enumeration is uniquely identified by the specIndex attribute. However the usage of ID is not clearly introduced. In the security consideration section, it is mentioned that the miss-match between the index and the ID may cause problem. Could you please give me some clues?

The enumeration specification is identified, so that the ID expressed in a given IODEF (note v2 not v1) is understood.  The ID is a reference to a set of further information to be acquired through other means.  As an example, discovered vulnerabilities are often given a Common Vulnerability Enumeration (CVE) identifier.  This ID would be in the <iodef:enum:ID> element, and the specification for that ID’s format is what is pointed to by the IANA registry.  

> 2)	Where is section 2.2?

Good catch, thank you.

> 3)	In the abstract, it is stated that "This memo establishes a stand-alone data format to include both the external specification and specific enumeration value,. However, I didn't find the specific enumeration value in the example provided in Section 2.1:
> "      <iodef:Reference>
>         <iodef-enum:ReferenceName specIndex="1">
>            <iodef-enum:ID>CXI-1234-XYZ</iodef-enum:ID>
>         </iodef-enum:ReferenceName>
>         <iodef:URL></iodef:URL>
>         <iodef:Description>Foo</iodef:Description>
>      </iodef:Reference>
> “

That sentence should probably read (emphasis added): This memo establishes a stand-alone data format to include both the external specification and specific enumeration *identification* value.

> Cheers
> Dacheng
> _______________________________________________
> secdir mailing list
> wiki: