[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]
Subject: Re: [cti-taxii] Open question: Server and User-Agent headers
On 08.02.2017 02:28:45, Bret Jordan wrote: > > The MIME types say that it is STIX content or TAXII content. What > people are asking for is the ability broadcast the type and version > of the server / client. > Speaking from past experience debugging STIX/TAXII 1.x interoperability issues, the problem is immeasurably easier when you can clearly determine from your logs which implementations are correlated with the issue(s). As John Wunder pointed out during yesterday's working call, in some instances (e.g., DISA STIG requirements) you need the ability to disable this behavior. But in most cases it's helpful to have this information at hand. QED, TAXII servers and clients SHOULD support identifying their type and version via the headers but the behavior MAY be disabled when necessary. -- Cheers, Trey ++--------------------------------------------------------------------------++ Kingfisher Operations, sprl gpg fingerprint: 85F3 5F54 4A2A B4CD 33C4 5B9B B30D DD6E 62C8 6C1D ++--------------------------------------------------------------------------++ -- "There's never enough time. Thank you for yours." --Dan Geer
Attachment:
signature.asc
Description: Digital signature
[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]