OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cacao-comment message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: comments on security-playbooks-v1.0-csd01.docx


First message to the mailing list, so I donât know Âif you prefer the comments to be plain text in the email messages or if I should attach an edited version of the document with tracking changes and comments. Tell me if the text below is not enough

 

Some comments:

  • in Â2.3 , it states that the keys could be things like "work", "home", "personal", etc. Would it be worth to have a vocabulary for that?
  • at the end of 2.4 (page 12 ) it says and an underscore (_). Is there a reason why only one can be present? Or should if be and underscores(_)
  • in 2.5 hash is used for SHA256. At some point in the future, SHA256 might become obsolete, need replacement, and then confusing will arise. I suggest to have a hash_algorithm indicating the type of hash and then a hashÂ_value indicating the value (ETSI SOL001 and SOL004 do this)
  • in 2 .6, longitude says between -180.0 and 180.0 inclusive. But -180.0 and 180.0 represent the same longitude, so if the sentence means both inclusive then there may be representation ambiguity (and comparisons will need to take this into account.
  • in 5.1 on_success and on_failure use nouns, but on_complete uses a verb. Shouldnât it be on_completion for consistency?
  • 7.8 specifies the key in http_auth as authentication, token or credentials. It would need more details. E.g if it is a token, what is the header that carries this token? Or if it is username+password, how are they encoded in this single field?
  • 7.9 states that the key inside ssh_auth must be username, password, or certificate. Technically what you use for ssh is not a certificate; it is a private_key
  •  

 

HTH,

ÂÂÂÂÂÂÂÂÂÂÂÂÂÂ Juan Postlbauer

 

Attachment: smime.p7s
Description: S/MIME cryptographic signature



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]