Skip to Content.
Sympa Menu

technical-discuss - Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements

Subject: InCommon Technical Discussions

List archive

Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements


Chronological Thread 
  • From: "Cantor, Scott" <>
  • To: "" <>
  • Subject: Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements
  • Date: Wed, 8 Nov 2017 22:05:42 +0000
  • Accept-language: en-US
  • Authentication-results: spf=pass (sender IP is 128.146.138.9) smtp.mailfrom=osu.edu; incommon.org; dkim=none (message not signed) header.d=none;incommon.org; dmarc=pass action=none header.from=osu.edu;
  • Ironport-phdr: 9a23:baUJVBFgF3iEEOSWgiJF9J1GYnF86YWxBRYc798ds5kLTJ7yosiwAkXT6L1XgUPTWs2DsrQf2rqQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbQhFgDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VDK/5KlpVRDokj8KOT4n/m/Klsx+gqFVoByjqBx+34Hab46aOeFifqzGeNMWWXZNUtpTWiFHH4iyb5EPD+0EPetAoYXwuUEBrR2iBQmrHuPj0iJDiGLq0q09z+QhDQ/K1xEnEt0SqnvUqsn1NKAIUeyv0qXF1jLDb+hL2Tvn9ofHbw0hrOiKULltcsTR0VEiGx3fgVmMtIDoOi6Z2vkQv2We4eptWv6jh3IipgF/vDeiydkgh4zMi48X1lzJ+z11zJsrKdC7UkJ3fNGpHZpKuy2HOIZ6WMwvTmNwtCY01LILuoK3cS0PxZkpwxPSauCLfo2V7R3+V+ucIDJ1i2l/d76hghu961WvxvP9W8SyzV1EtDBKksPWuXAIzxHT6taISv96/kq5wTiCywfd5v1ZLUwtiKfUKYAtzqc3lpUIr0vPBCj2mFjqjKCNcUUk5+6o5Pn9brX+vJ+cMJN0hR/iPaQym8y/BuI4PhIJX2iG5eS80Lrj/Ur6QLlQkvI2lazZvIjbJcQduKG5HxdY3pg55BqjEjur1ckUkWQaIF9AdhKKgJTlN03LLfD2E/iyjEqgnTJuyv3EIrHsDI3BLn3Zn7fgebZ95VRcyA02zd1H+51bELcBIO70Wk/rrtDUEAQ0Mwuvw+b6EtlyyJ4RWX+XDq+DLKzSqUOI5v4oI+SUZY8VviryK/8g5/7rin85n0URfa6z3ZsYcXy4AuppLFmZYXrqg9cODX0Fvg4nQOP3iV2CSiJcZ2upX6In/Tw7DIOmDZzfRoC2nrCNxia7HptKZm9YEFCMF2nnd5maV/sWdi2dP9JhwXQ4Uu3rV4Iq1Revvwb+jrZmNeHJ4TYwtJTo091w4OuVkgs9v3QgE8mW02eMRGhw228JXDQrx7tXoEp2zVKG1q4+hOZXQ499/fRMB00RPJjAyPY+Q+v5XR7dNJ/dQ1+gXtK8R2sZSckshdICfhAuSJ2Zkhnf0n/yUPcunLuRCcls/w==
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

On 11/8/17, 4:58 PM, "Nick Roy"
<>
wrote:

> We think errorURL should be included as well, but since it was not part
> of the 'required' elements that AAC specified (AAC assumed errorURL was
> part of the mdui: information, and it is not) that means this would have
> to go back to ACC to make errorURL a separate required element.

Maybe the better question is the one I've been asking a lot: when can we go
back and start working on the next set of rules?

> - Achieve a grade of A on the Qualys SSL scanner [1]

I guess in my mind it's more interesting to tag systems with the grade we
find then get into rules about what the grade should be unless they're actual
rules. If I care, I should be able to filter on those grades, but just
knowing "we'd like it to be an A but it's not a requirement" doesn't really
get me anything useful that I can think of.

I guess the point is "SHOULDs" never help much. Same as with profiles.

If we don't require something, I'd rather have a tag with the actual answer
either so I can report on it to my security people, or to limit who I allow
to use my system. Is it a huge value-add for InCommon to do SSL probes? I
dunno. I know it's something I probably wouldn't do myself.

-- Scott





Archive powered by MHonArc 2.6.19.

Top of Page