technical-discuss - Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements
Subject: InCommon Technical Discussions
List archive
- From: Chris Phillips <>
- To: "Farmer, Jacob" <>, Nick Roy <>, "Cantor, Scott" <>, "" <>
- Subject: Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements
- Date: Thu, 9 Nov 2017 15:47:29 +0000
- Accept-language: en-US
- Ironport-phdr: 9a23:+k/Raxy46NLmRbrXCy+O+j09IxM/srCxBDY+r6Qd2uMVIJqq85mqBkHD//Il1AaPBtSLraocw8Pt8InYEVQa5piAtH1QOLdtbDQizfssogo7HcSeAlf6JvO5JwYzHcBFSUM3tyrjaRsdF8nxfUDdrWOv5jAOBBr/KRB1JuPoEYLOksi7ze6/9pnQbglSmDaxfa55IQmrownWqsQYm5ZpJLwryhvOrHtIeuBWyn1tKFmOgRvy5dq+8YB6/ShItP0v68BPUaPhf6QlVrNYFygpM3o05MLwqxbOSxaE62YGXWUXlhpIBBXF7A3/U5zsvCb2qvZx1S+HNsDtU7s6RSqt4LtqSB/wiScIKTg58H3MisdtiK5XuQ+tqwBjz4LRZoyeKfhwcb7Hfd4CRWRPQNtfVzBPDI2/YYsADeQOPedEoIbyvFYOogeyBQy2Ce/z0DJFhHn71rA63eQ7FgHG2RQtEswOsHTOrdX1L7oZX/q1zKnJyTXDa/JW2S/m6IPVdR0sv/GMXahxccrK00UhDQPFjlSUqYzhPjOVzv8NvnOH4OV6U+KgkXQnqwBvrTS12sgjkJDEi4QIwV7H7SV02Jg5KcG4RUJhfNKpE59duzuUOoZ4WM8uXmNltD4nxrEao5K3YSsHxZA9yxPRdfCLaYaF7g7lWe2MOzl3nmhld6i6hxuq8Uiv1On8Vs6s3VlWtCVFlNzMuWoM1xzX8MSIVuFy/kG71jaV1gDc9PtILlwumqbDKp4hxKA/loYLvEjdAiP7mF/6gLKVe0gg4OSl5erqbq/7qpKeL4N0jxvxMqUqmsyxG+Q4NQ0OUnCF9OS8zr3j/Fb5TK9QgP02k6nZtJTaJcUDpq6iGAJazpws6xClADe80dQXg2MLI05fdx6flYjmJ0nOIOzkDfe4m1mskTFryOzBPr3kB5XNKX7DnK3mfbZn5E5Q0RYzws5D6JJUDLEBIe78VVX1tNDBExA5Mhe0zPr6CNVmzYMTQmaPAq6CMKPOql+E+PgjI+iKZI8Jpjn9Mf4l6ODyjXMng1MSY7Sm3YZEIEy/S75IKl+cbGCoyvUIGmAA9EJqTvTkgUeHXCR7Zmv0Uq4hsHVzLoOtDs/5QZHl1Lqb2zaTH5tKa3pAB0zWV3rkatPAE70nYSSOJdUl2gcPUqS9Acd13hioqAjgjeBPKfHJvCAUqMSnnJJp6ubTkxA5/DgxA8WG2HyWVEl1mGgPQjox2uZ4u0M3ggOf3KN4hf1THNgW6/JSWRohLrbdyed9DtX1XETGZNjfG3i8RdDzKjErT8l5+98PZ0J8A87q2jvDxSuxRYcVlriPBYQv2qnV2XHrJss7wH+Qh/pptEUvXsYabT7uvaV47QWGQteRy0g=
Great dialogue on this.
Maybe it would be better to define what’s not acceptable regarding a grade
and what’s a reasonable duration to remediate.
Highest grade (A+) preferred but no lower than C on ssllabs and no longer
than say X days below this band of acceptance.
This gives latitude to maneuver when the tools change underneath one’s feet
and dependencies to catch up.
Jacob’s example is great in this regard. If his group didn’t care about it
(or know to test that way) then how would he have pushed for the change to
get back into compliance and hence pressured the vendor to step up?
That said, things like Poodle SSLv3 and other future events we know will
happen will change ranking from A+ to F overnight. Using the idea of X days
to come into compliance allows us to respond commensurate with the risk. It
also allows us to simply be users of the tool which is not our core mission –
we just want the output to inform our decisions.
C
On 2017-11-09, 9:53 AM, "Farmer, Jacob"
<
on behalf of
>
wrote:
Nick,
I like the Qualys SSL scanner and we use it often. Given my history,
though, I
am reluctant to rely on it for this kind of thing. A real-world story
from the
last few years: Qualys made a change to the scanner which caused sites we
manage that were in the A range to fall into the B+ range. I don't recall
all
of the details about why; I think it had to do with cipher suites. Our
load
balancer -- a widely deployed product on its current version -- could not
be
adjusted to bring it back up to A. There was something in the
configuration
that Qualys simply didn't like and there was no way to fix it until a
vendor
patch shipped.
I'm glad that we took the time to get it figured out, but I also don't
think
that the quality of SSL was meaningfully degraded in the interim.
I support the idea of defining "good TLS" but I am reluctant to rely on
this
scanner to define it.
Jacob
-----Original Message-----
From:
[mailto:]
On Behalf Of Nick Roy
Sent: Wednesday, November 8, 2017 4:59 PM
To: Cantor, Scott
<>;
Subject: Re: [InC-Technical] InCommon Baseline Expectations Metadata
Requirements
On 11/8/17 1:58 PM, Cantor, Scott wrote:
>> RECOMMENDED:
>>
>> SSL certificates on endpoints are valid
> That seems like a slippery slope: valid re: dates? Specific CAs? Key
sizes?
> What about ciphers, or use of TLS 1.0, etc.?
>
> Requiring a logo is, I think, underspecified, we should mandate
specific
> size(s).
>
> I'd like to see errorURL be required with guidance around what should
be
> behind it.
We think errorURL should be included as well, but since it was not part
of the
'required' elements that AAC specified (AAC assumed errorURL was part of
the
mdui: information, and it is not) that means this would have to go back
to ACC
to make errorURL a separate required element.
Agree re: specific requirements for SSL and logo.
Here is my proposed requirement for SSL for endpoints (since it's
recommended
but not required):
- Achieve a grade of A on the Qualys SSL scanner [1]
And for HTTPS Logo URL:
- Must result in an HTTP 200 in response to a GET request
- Image must be either a PNG or JPG
- Image must be 80 pixels in width by 60 in height
[1] https://github.com/ssllabs/research/wiki/SSL-Server-Rating-Guide
Let me know if you think this is something that would better be discussed
in
detail by the Ops Advisory Group or in some other venue.
Thank you,
Nick
>
> -- Scott
>
>
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, (continued)
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Farmer, Jacob, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Scott Koranda, 11/09/2017
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Farmer, Jacob, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Scott Koranda, 11/09/2017
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Farmer, Jacob, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Scott Koranda, 11/09/2017
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Cantor, Scott, 11/09/2017
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Cantor, Scott, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Chris Phillips, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Mark Scheible, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Nick Roy, 11/09/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Alan Buxey, 11/10/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Nick Roy, 11/10/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, David Shafer, 11/10/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Nick Roy, 11/10/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Alan Buxey, 11/10/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Nick Roy, 11/10/2017
- RE: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, Farmer, Jacob, 11/13/2017
- Re: [InC-Technical] InCommon Baseline Expectations Metadata Requirements, David Langenberg, 11/13/2017
Archive powered by MHonArc 2.6.19.