cti-taxii — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Re: [cti-taxii] Use of well_known
To follow up on Terry's email though... I do not believe using .well-known for the HTTP endpoint location has anything to do with if we also allow DNS discovery. I believe we should still do the DNS discovery as proposed in the spec, regardless of what the URI ends up being. The .well-known RFC is about discovering resources available at a specific web server; it does nothing to help you discover the servers themselves, as the DNS discovery does.
It is worth noting Terry proposes a TXT record, while the spec proposes a SRV record, I am not sure as to the pros/cons of each approach, not being a DNS expert. - Jason Keirstead STSM, Product Architect, Security Intelligence, IBM Security Systems www.ibm.com/security
www.securityintelligence.com Without data, all you are is just another person with an opinion - Unknown
"Back, Greg" ---10/11/2016 08:06:52 PM---I took the time to read through the RFC (only 8 pages; pretty light by RFC standards). I tend to agr
From:
"Back, Greg" <[email protected]>
To:
"Bret Jordan (CS)" <[email protected]>, Terry MacDonald <[email protected]>, Dave Cridland <[email protected]>
Cc:
Jason Keirstead/CanEast/IBM@IBMCA, "[email protected]" <[email protected]>
Date:
10/11/2016 08:06 PM
Subject:
RE: [cti-taxii] Use of well_known
Sent by:
<[email protected]>
I took the time to read through the RFC (only 8 pages; pretty light by RFC standards). I tend to agree with Dave. The intent of "/.well-known/" seems to match our use case. With the exception of registering the name, I don't see what additional complexity it adds.
I imagine the vast majority of implementers are unlikely to care and will simply accept "use this string because the TAXII spec says so." It's possible some implementers who (like me, before digging into this) were ignorant of RFC 5785, and learn something new and understand why TAXII uses it. The implementers who see it and think "why didn't the TC just use /taxii ?" (just like the people, were we not to use /.well-known/taxii, who would think "why didn't the TC use /.well-known/taxii ?") aren't the people we should be trying to please; if someone's looking for things to criticize, I'm sure they'll find something. Using /.well-known/ does show at least some level of commitment to using other standards when they make sense; I think that's worth something. Long story short: I'm about a +0 on using .well-known. I'd prefer it, in the absence of a strong reason not to, but it's not something I feel strongly about either way. I'm about a 2 out of 10 on the scale here [1] (sorry for the language in the URL). Greg [1]
http://blog.capwatkins.com/the-sliding-scale-of-giving-a-fuck
>
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]