Meeting Recap

From
John Wunder <>
Date
2018-09-24T14:08:00+00:00
ID
Thread
Meeting Recap
This seems reasonable to me. For #3, no preference here on URL parameter vs. X-Header, either seems fine.

John
From:   <>  On Behalf Of  Bret Jordan
Sent:  Friday, September 21, 2018 5:45 PM
To:  
Subject:  [cti-taxii] Meeting Recap

All,

We had a TAXII call today to talk about media types and a TAXII wrapper.  The following were on the call:

Matt Pladna
Drew Varner
Allan Thomson
Jason Keirstead
Ron Williams
Bret Jordan
John Anderson (was on for a few minutes at the start)

We talked through the problems and by the end of the hour had rough consensus on the following:

1) All endpoints will use a TAXII media type. This will eliminate the problem of sometimes getting a STIX media type and sometimes getting a TAXII media type on the same endpoint.

2) We need to create some sort of wrapper in TAXII to hold STIX content. This may just be a copy-n-paste of the STIX Bundle. STIX still needs to define its own Bundle for times when STIX is used outside of TAXII.

3) We need a way of filtering STIX content that will be returned inside the TAXII bundle. Originally we talked about doing this via a URL parameter, but Ron suggested that this would be best done as an X-header.   Either way we would allow a comma separated list of STIX versions or the keyword "all".

What does everyone else think?


Bret