[secdir] Writing Security Considerations

Yoav Nir <ynir.ietf@gmail.com> Tue, 25 June 2019 18:57 UTC

Return-Path: <ynir.ietf@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8DA9E120BE5 for <secdir@ietfa.amsl.com>; Tue, 25 Jun 2019 11:57:45 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nzkJLgqcJKT8 for <secdir@ietfa.amsl.com>; Tue, 25 Jun 2019 11:57:42 -0700 (PDT)
Received: from mail-wm1-x329.google.com (mail-wm1-x329.google.com [IPv6:2a00:1450:4864:20::329]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9921A120BEF for <secdir@ietf.org>; Tue, 25 Jun 2019 11:57:42 -0700 (PDT)
Received: by mail-wm1-x329.google.com with SMTP id c66so3922254wmf.0 for <secdir@ietf.org>; Tue, 25 Jun 2019 11:57:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:mime-version:subject:message-id:date:cc:to; bh=5zzav9dORTs0pGeg2C18Abm8cE9o0WZXkFAFYprsZdE=; b=Gguaa77D/NauVOpRAM8bQq5s39FlbXv4oVk1snIl5VGYgr89hcfzbOQL1t83y/tfrN xAJDvdLm7sSACsp1KFZRy3PX5uH8I8vaRgXVpaRQWiyRrizZeeSTP0niuo5tgk4Jz43x 5jvvQcel9SA1m/o2nyQhr29o/w3YXLQhaJqeXgNMW34xMXbqJ21Jo8vP35K3MwWKiF9g usMhtBhSM5zDCgFlk1siOKkiOACOjYCCx42gfCdZgGQJI+tHTDlOgiQGrdqSdSFMvdEt 9AhlBPihS4LhKAt1j2uobK6MX8x2exs5SwsBsmlmTCI6OlmIb1dKacryr214AwzHWTaq O3Ig==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:cc:to; bh=5zzav9dORTs0pGeg2C18Abm8cE9o0WZXkFAFYprsZdE=; b=SUay1WPqi8b5TV0pLc8l92Diiv4If7dPVx8mOg1q5tHXhz4GcwbV+t0ZpsP5cnyDhj xeadiTRlpBokjgELDCDmDRQK6CYa6T2BCuBxg/5Mnox/gBF7ZxLFSHHEtafcfhkqMkGG vldrfq9dULA6QKPGRKiYf1C3pQTn1iCkM9J9oF7LfcJyDZF7E7brT+XitQrqp2R82TJc Ae/yKnfukoE5+WEbGf0OKkO5zJlyRLDTVAUrFJJ3Y9Hfh8BQ9bnCiW/vgCIdLctT62F0 BXQOjb1QC5uxD6WqWPQ2vAuqwAQNhQxr3YSJnjYlHUDfa2mONGSS+Lu6u31nyXNXl3rq a4Tw==
X-Gm-Message-State: APjAAAW8e+xvdzC6iSCIgrdYxpyDhJzkD4koBKwfLYkNJUpE5UHNPa3N h1XU0NHwS++70Uj1kIQutAX3RDx5
X-Google-Smtp-Source: APXvYqy+gT9dnoQxXsGB+wXl0BbB6v5QcTco2WGV3M2nAMjMA647564N9F/7tzrKOIpwW3IDzhfx7w==
X-Received: by 2002:a05:600c:206:: with SMTP id 6mr19666482wmi.73.1561489060743; Tue, 25 Jun 2019 11:57:40 -0700 (PDT)
Received: from [192.168.1.12] ([46.120.57.147]) by smtp.gmail.com with ESMTPSA id i11sm3619132wmi.33.2019.06.25.11.57.39 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 25 Jun 2019 11:57:40 -0700 (PDT)
From: Yoav Nir <ynir.ietf@gmail.com>
Content-Type: multipart/alternative; boundary="Apple-Mail=_F4EFF181-3E74-4D7F-92F0-FEB9F49E48B8"
Mime-Version: 1.0 (Mac OS X Mail 12.4 \(3445.104.11\))
Message-Id: <AB6D23B6-C4F2-466B-8DE2-75CF6FD6EF8A@gmail.com>
Date: Tue, 25 Jun 2019 21:57:38 +0300
To: secdir <secdir@ietf.org>
X-Mailer: Apple Mail (2.3445.104.11)
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/xEdRMaBFGw-nABg2IMmhFGrbVhg>
Subject: [secdir] Writing Security Considerations
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 25 Jun 2019 18:57:52 -0000

Hi, all

If you’ve had a look at the draft agenda (https://datatracker.ietf.org/meeting/105/agenda.html <https://datatracker.ietf.org/meeting/105/agenda.html>), we have a Writing Security Considerations tutorial on Sunday, which Linda Dunbar and I will be doing.

The idea is to get people writing drafts to know what they should do for a smooth interaction with us SecDir people.

The slides do not exist yet, but we have a rough outline on github: https://github.com/IETF-SAAG/SecurityConsiderationsTutorial <https://github.com/IETF-SAAG/SecurityConsiderationsTutorial>

So if there’s missing or wrong stuff, we’d like to hear about it, preferably in the form of PRs.

But most of all, we’re looking for more examples in the examples page: https://github.com/IETF-SAAG/SecurityConsiderationsTutorial/blob/master/examples.md <https://github.com/IETF-SAAG/SecurityConsiderationsTutorial/blob/master/examples.md>

So any horror story, war story, stuff that’s terribly wrong, or even something that’s surprisingly right will be welcome.

Thanks in advance

Linda & Yoav