OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

cti-taxii message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [cti-taxii] Open question: Server and User-Agent headers


On 08.02.2017 02:28:45, Bret Jordan wrote:
> 
> The MIME types say that it is STIX content or TAXII content. What
> people are asking for is the ability broadcast the type and version
> of the server / client.
> 

Speaking from past experience debugging STIX/TAXII 1.x
interoperability issues, the problem is immeasurably easier when you
can clearly determine from your logs which implementations are
correlated with the issue(s).

As John Wunder pointed out during yesterday's working call, in some
instances (e.g., DISA STIG requirements) you need the ability to
disable this behavior. But in most cases it's helpful to have this
information at hand. QED, TAXII servers and clients SHOULD support
identifying their type and version via the headers but the behavior
MAY be disabled when necessary.

-- 
Cheers,
Trey
++--------------------------------------------------------------------------++
Kingfisher Operations, sprl
gpg fingerprint: 85F3 5F54 4A2A B4CD 33C4  5B9B B30D DD6E 62C8 6C1D
++--------------------------------------------------------------------------++
--
"There's never enough time. Thank you for yours." --Dan Geer

Attachment: signature.asc
Description: Digital signature



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]