Fwd: Novell submissions

8 Messages Forum Options Options
Permalink
Thomas R. Jones
Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
Some javascript/style in this post has been disabled (why?)
Erroneously sent to ONLY mitre. Forwarding to the community for possible discussion. 

Begin forwarded message:

From: Thomas R. Jones <thomas.jones@...>
Date: June 27, 2008 3:45:23 PM CDT
To: Jon Baker <bakerj@...>
Subject: Novell submissions

I am currently preparing the next round of submissions for Novell packages. There has been no changes to the source as of the initial phase. So this lends me to believe that QA should be smooth and without much effort.

I was going to proceed with additions of the last two distributions produced by Novell; but have elected to proceed with current development. And release new distribution inventory in conjunction with code additions within the affected_cpe_list and platform elements. Personal choice for my ease of development. ;)

Is Mitre ready to accept these for community review?

Thomas Jones

Sent from my iPhone
To unsubscribe, send an email message to LISTSERV@... with SIGNOFF OVAL-DISCUSSION-LIST in the BODY of the message. If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
bakerj
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
>-----Original Message-----
>From: Thomas R. Jones [mailto:thomas.jones@...]
>Sent: Friday, June 27, 2008 5:46 PM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>
>Erroneously sent to ONLY mitre. Forwarding to the community for
possible

>discussion.
>
>Begin forwarded message:
>
>
>
> From: Thomas R. Jones <thomas.jones@...>
> Date: June 27, 2008 3:45:23 PM CDT
> To: Jon Baker <bakerj@...>
> Subject: Novell submissions
>
>
>
> I am currently preparing the next round of submissions for
Novell
>packages. There has been no changes to the source as of the initial
>phase. So this lends me to believe that QA should be smooth and
without

>much effort.
>
> I was going to proceed with additions of the last two
>distributions produced by Novell; but have elected to proceed with
>current development. And release new distribution inventory in
>conjunction with code additions within the affected_cpe_list and
>platform elements. Personal choice for my ease of development. ;)
>
> Is Mitre ready to accept these for community review?
>
>

Yes, we are ready for another batch of definitions for Novell products.
As we previously discussed it would be ideal if submissions came in
batches that we can easily process and review. Since you know the
content you are submitting I am happy to let you decide how best to
split up content into batches.

When we last exchanged emails you were considering hosting your own
repository. Have you made any progress there? As I have said in the
past, to reduce confusion in the community we would like to avoid
having lots of duplicate content floating around. We are thrilled to
have the inventory content and can host it in the OVAL Repository. We
just would prefer not to have duplicate repositories around.

Thanks,

Jon
Thomas R. Jones
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:

> >-----Original Message-----
> >From: Thomas R. Jones [mailto:thomas.jones@...]
> >Sent: Friday, June 27, 2008 5:46 PM
> >To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
> >Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
> >
> >Erroneously sent to ONLY mitre. Forwarding to the community for
> possible
> >discussion.
> >
> >Begin forwarded message:
> >
> >
> >
> > From: Thomas R. Jones <thomas.jones@...>
> > Date: June 27, 2008 3:45:23 PM CDT
> > To: Jon Baker <bakerj@...>
> > Subject: Novell submissions
> >
> >
> >
> > I am currently preparing the next round of submissions for
> Novell
> >packages. There has been no changes to the source as of the initial
> >phase. So this lends me to believe that QA should be smooth and
> without
> >much effort.
> >
> > I was going to proceed with additions of the last two
> >distributions produced by Novell; but have elected to proceed with
> >current development. And release new distribution inventory in
> >conjunction with code additions within the affected_cpe_list and
> >platform elements. Personal choice for my ease of development. ;)
> >
> > Is Mitre ready to accept these for community review?
> >
> >
>
> Yes, we are ready for another batch of definitions for Novell products.
> As we previously discussed it would be ideal if submissions came in
> batches that we can easily process and review. Since you know the
> content you are submitting I am happy to let you decide how best to
> split up content into batches.

Great! I will do a quick QA to ensure that these definitions have not
been adversely affected somehow by further developments here at Maitreya
Security and then submit asap.

We have been processing in lexicographical order. I see no reason to
change an efficient process. ;)

>
> When we last exchanged emails you were considering hosting your own
> repository. Have you made any progress there? As I have said in the
> past, to reduce confusion in the community we would like to avoid
> having lots of duplicate content floating around. We are thrilled to
> have the inventory content and can host it in the OVAL Repository. We
> just would prefer not to have duplicate repositories around.

Yes I have. As you know, the Dharma Repository contains duplicate data
definitions in their developmental state to include particular metadata
that Mitre does not accept. So I must remove and re-declare such
resources path. In our content the schema location is altered to point
to a path that is compliant with the Filesystem Hierarchy Standard(FHS)
and the Linux Standard Base(LSB).

Our repository will be utilized for community development and review.
And will be publicly available. As of this moment, it is online.
However, some services must be worked on-----mainly mailinglist
notification of SVN changes, deletions and additions. Please feel free
to discuss with me the specifics if you would like to move further to
ensure compliance.

On that note, I would like to receive the documentation needed to
proceed with certifying the Dharma Repository as OVAL compatible and/or
compliant by Mitre. I think Drew has forwarded it to me once before but
this resource was not nearly ready to proceed.

Thanks.
Thomas
>
> Thanks,
>
> Jon

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
bakerj
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
>-----Original Message-----
>From: Thomas R. Jones [mailto:thomas.jones@...]
>Sent: Wednesday, July 02, 2008 9:36 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>
>On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:
>> >-----Original Message-----
>> >From: Thomas R. Jones [mailto:thomas.jones@...]
>> >Sent: Friday, June 27, 2008 5:46 PM
>> >To: oval-discussion-list OVAL Discussion List/Closed Public
Discussi

>> >Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>> >
>> >Erroneously sent to ONLY mitre. Forwarding to the community for
>> possible
>> >discussion.
>> >
>> >Begin forwarded message:
>> >
>> >
>> >
>> > From: Thomas R. Jones <thomas.jones@...>
>> > Date: June 27, 2008 3:45:23 PM CDT
>> > To: Jon Baker <bakerj@...>
>> > Subject: Novell submissions
>> >
>> >
>> >
>> > I am currently preparing the next round of submissions for
>> Novell
>> >packages. There has been no changes to the source as of the initial
>> >phase. So this lends me to believe that QA should be smooth and
>> without
>> >much effort.
>> >
>> > I was going to proceed with additions of the last two
>> >distributions produced by Novell; but have elected to proceed with
>> >current development. And release new distribution inventory in
>> >conjunction with code additions within the affected_cpe_list and
>> >platform elements. Personal choice for my ease of development. ;)
>> >
>> > Is Mitre ready to accept these for community review?
>> >
>> >
>>
>> Yes, we are ready for another batch of definitions for Novell
>products.
>> As we previously discussed it would be ideal if submissions came in
>> batches that we can easily process and review. Since you know the
>> content you are submitting I am happy to let you decide how best to
>> split up content into batches.
>
>Great! I will do a quick QA to ensure that these definitions have not
>been adversely affected somehow by further developments here at
Maitreya
>Security and then submit asap.
>
>We have been processing in lexicographical order. I see no reason to
>change an efficient process. ;)
>

Sounds good to me.

>>
>> When we last exchanged emails you were considering hosting your own
>> repository. Have you made any progress there? As I have said in the
>> past, to reduce confusion in the community we would like to avoid
>> having lots of duplicate content floating around. We are thrilled to
>> have the inventory content and can host it in the OVAL Repository.
We
>> just would prefer not to have duplicate repositories around.
>
>Yes I have. As you know, the Dharma Repository contains duplicate data
>definitions in their developmental state to include particular
metadata
>that Mitre does not accept. So I must remove and re-declare such
>resources path. In our content the schema location is altered to point
>to a path that is compliant with the Filesystem Hierarchy
Standard(FHS)
>and the Linux Standard Base(LSB).
>
>Our repository will be utilized for community development and review.
>And will be publicly available. As of this moment, it is online.
>However, some services must be worked on-----mainly mailinglist
>notification of SVN changes, deletions and additions. Please feel free
>to discuss with me the specifics if you would like to move further to
>ensure compliance.
>

Can you send the url to your repository to this list?
As I mentioned before I still have a concern about creating duplicate
data for us all to manage. From your comments above it sounds like you
intend your repository to be the place where the definitions are
developed before they are submitted to the oval repository. Is that
correct?

Thanks,

Jon

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
Thomas R. Jones
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
Responses inline below.

Sent from my iPhone

On Jul 7, 2008, at 7:24 AM, "Baker, Jon" <bakerj@...> wrote:

>> -----Original Message-----
>> From: Thomas R. Jones [mailto:thomas.jones@...]
>> Sent: Wednesday, July 02, 2008 9:36 AM
>> To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>> Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>>
>> On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:
>>>> -----Original Message-----
>>>> From: Thomas R. Jones [mailto:thomas.jones@...]
>>>> Sent: Friday, June 27, 2008 5:46 PM
>>>> To: oval-discussion-list OVAL Discussion List/Closed Public
> Discussi
>>>> Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>>>>
>>>> Erroneously sent to ONLY mitre. Forwarding to the community for
>>> possible
>>>> discussion.
>>>>
>>>> Begin forwarded message:
>>>>
>>>>
>>>>
>>>>    From: Thomas R. Jones <thomas.jones@...>
>>>>    Date: June 27, 2008 3:45:23 PM CDT
>>>>    To: Jon Baker <bakerj@...>
>>>>    Subject: Novell submissions
>>>>
>>>>
>>>>
>>>>    I am currently preparing the next round of submissions for
>>> Novell
>>>> packages. There has been no changes to the source as of the initial
>>>> phase. So this lends me to believe that QA should be smooth and
>>> without
>>>> much effort.
>>>>
>>>>    I was going to proceed with additions of the last two
>>>> distributions produced by Novell; but have elected to proceed with
>>>> current development. And release new distribution inventory in
>>>> conjunction with code additions within the affected_cpe_list and
>>>> platform elements. Personal choice for my ease of development. ;)
>>>>
>>>>    Is Mitre ready to accept these for community review?
>>>>
>>>>
>>>
>>> Yes, we are ready for another batch of definitions for Novell
>> products.
>>> As we previously discussed it would be ideal if submissions came in
>>> batches that we can easily process and review. Since you know the
>>> content you are submitting I am happy to let you decide how best to
>>> split up content into batches.
>>
>> Great! I will do a quick QA to ensure that these definitions have not
>> been adversely affected somehow by further developments here at
> Maitreya
>> Security and then submit asap.
>>
>> We have been processing in lexicographical order. I see no reason to
>> change an efficient process. ;)
>>
>
> Sounds good to me.
>
>>>
>>> When we last exchanged emails you were considering hosting your own
>>> repository. Have you made any progress there? As I have said in the
>>> past, to reduce confusion in the community we would like to avoid
>>> having lots of duplicate content floating around. We are thrilled to
>>> have the inventory content and can host it in the OVAL Repository.
> We
>>> just would prefer not to have duplicate repositories around.
>>
>> Yes I have. As you know, the Dharma Repository contains duplicate  
>> data
>> definitions in their developmental state to include particular
> metadata
>> that Mitre does not accept. So I must remove and re-declare such
>> resources path. In our content the schema location is altered to  
>> point
>> to a path that is compliant with the Filesystem Hierarchy
> Standard(FHS)
>> and the Linux Standard Base(LSB).
>>
>> Our repository will be utilized for community development and review.
>> And will be publicly available. As of this moment, it is online.
>> However, some services must be worked on-----mainly mailinglist
>> notification of SVN changes, deletions and additions. Please feel  
>> free
>> to discuss with me the specifics if you would like to move further to
>> ensure compliance.
>>
>
> Can you send the url to your repository to this list?

http://developer.novell.com/wiki/index.php/Dharma

>
> As I mentioned before I still have a concern about creating duplicate
> data for us all to manage. From your comments above it sounds like you
> intend your repository to be the place where the definitions are
> developed before they are submitted to the oval repository. Is that
> correct?

To an extent yes. The content submitted to the official mitre  
repository will be developed and available for review by novell  
contributing members. It is my hope that some resources such as 0-day  
vulnerabilities will be fast-tracked through the initial phases of  
community review and quickly submitted to mitre for public  
consumption. However, less critical resources, such as inventory  
definitions or system configuration evaluations will undergo a  
timeline based review process before submission to mitre.

As we've previously discussed, there is metadata currently developed  
inline with all content published by this service. Mitre does not  
accept any such metadata in the official repository. In order to  
accomodate the use of this value-added metadata and still keep  
official content in the mitre repository there must be multiple  
branches of development. How this will be handled is still being  
reviewed.

Furthermore, this resource will provide some functionality that has  
not been implemented within the official repository. Off my head:
- digital signature implementation
- XML encryption implementation
- i18n functionality and implementation

The i18n implementation is of paramount importance in my estimation.  
As novell contributing members are diverse and hail from a great many  
countries; the native acceptance of the oval content produced by this  
repository must be easily consumed. To do so, there will be a great  
many versions of each definition developed in various languages. I  
have constructed a few po files for international translation and will  
place them in the svn repository for your review. The content itself  
will not be altered. But the language encoding will be altered  
accordingly.

I hope this quells your concerns. If not, you have my email address  
and phone number. Feel free to contact me at any time.

Thomas jones

>
>
> Thanks,
>
> Jon
>
> To unsubscribe, send an email message to LISTSERV@... with
> SIGNOFF OVAL-DISCUSSION-LIST
> in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@...
> .

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
bakerj
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
Thomas,

I have been mulling this over for a while now. I think that the work
you are doing in your repository is awesome and I would be delighted to
see your repository be granted compatibility. However, I remain
concerned about creating large amounts of duplicate content in the
community. Avoiding duplicate content will reduce content maintenance
efforts for both of us and also reduce confusion in the community about
where to look for Novell content. With this in mind I would like to
suggest that we do not include the contents of your repository in the
OVAL Repository. Having the Novell content available from a Novell url
is a huge win for everyone.

I would like to advertise the availability of your repository. We can
do this through the following web pages once your repository has been
granted compatibility:

http://oval.mitre.org/repository/index.html

and this page:

http://oval.mitre.org/repository/about/other_repositories.html

Thanks for your continued work for get OVAL definitions for Novell
products.

Regards,

Jon

============================================
Jonathan O. Baker
The MITRE Corporation
Email: bakerj@...



>-----Original Message-----
>From: Thomas R. Jones [mailto:thomas.jones@...]
>Sent: Tuesday, July 08, 2008 10:06 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>
>Responses inline below.
>
>Sent from my iPhone
>
>On Jul 7, 2008, at 7:24 AM, "Baker, Jon" <bakerj@...> wrote:
>
>>> -----Original Message-----
>>> From: Thomas R. Jones [mailto:thomas.jones@...]
>>> Sent: Wednesday, July 02, 2008 9:36 AM
>>> To: oval-discussion-list OVAL Discussion List/Closed Public
Discussi

>>> Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>>>
>>> On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:
>>>>> -----Original Message-----
>>>>> From: Thomas R. Jones [mailto:thomas.jones@...]
>>>>> Sent: Friday, June 27, 2008 5:46 PM
>>>>> To: oval-discussion-list OVAL Discussion List/Closed Public
>> Discussi
>>>>> Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>>>>>
>>>>> Erroneously sent to ONLY mitre. Forwarding to the community for
>>>> possible
>>>>> discussion.
>>>>>
>>>>> Begin forwarded message:
>>>>>
>>>>>
>>>>>
>>>>>    From: Thomas R. Jones <thomas.jones@...>
>>>>>    Date: June 27, 2008 3:45:23 PM CDT
>>>>>    To: Jon Baker <bakerj@...>
>>>>>    Subject: Novell submissions
>>>>>
>>>>>
>>>>>
>>>>>    I am currently preparing the next round of submissions for
>>>> Novell
>>>>> packages. There has been no changes to the source as of the
initial
>>>>> phase. So this lends me to believe that QA should be smooth and
>>>> without
>>>>> much effort.
>>>>>
>>>>>    I was going to proceed with additions of the last two
>>>>> distributions produced by Novell; but have elected to proceed
with

>>>>> current development. And release new distribution inventory in
>>>>> conjunction with code additions within the affected_cpe_list and
>>>>> platform elements. Personal choice for my ease of development. ;)
>>>>>
>>>>>    Is Mitre ready to accept these for community review?
>>>>>
>>>>>
>>>>
>>>> Yes, we are ready for another batch of definitions for Novell
>>> products.
>>>> As we previously discussed it would be ideal if submissions came
in
>>>> batches that we can easily process and review. Since you know the
>>>> content you are submitting I am happy to let you decide how best
to
>>>> split up content into batches.
>>>
>>> Great! I will do a quick QA to ensure that these definitions have
not
>>> been adversely affected somehow by further developments here at
>> Maitreya
>>> Security and then submit asap.
>>>
>>> We have been processing in lexicographical order. I see no reason
to
>>> change an efficient process. ;)
>>>
>>
>> Sounds good to me.
>>
>>>>
>>>> When we last exchanged emails you were considering hosting your
own
>>>> repository. Have you made any progress there? As I have said in
the
>>>> past, to reduce confusion in the community we would like to avoid
>>>> having lots of duplicate content floating around. We are thrilled
to

>>>> have the inventory content and can host it in the OVAL Repository.
>> We
>>>> just would prefer not to have duplicate repositories around.
>>>
>>> Yes I have. As you know, the Dharma Repository contains duplicate
>>> data
>>> definitions in their developmental state to include particular
>> metadata
>>> that Mitre does not accept. So I must remove and re-declare such
>>> resources path. In our content the schema location is altered to
>>> point
>>> to a path that is compliant with the Filesystem Hierarchy
>> Standard(FHS)
>>> and the Linux Standard Base(LSB).
>>>
>>> Our repository will be utilized for community development and
review.
>>> And will be publicly available. As of this moment, it is online.
>>> However, some services must be worked on-----mainly mailinglist
>>> notification of SVN changes, deletions and additions. Please feel
>>> free
>>> to discuss with me the specifics if you would like to move further
to
>>> ensure compliance.
>>>
>>
>> Can you send the url to your repository to this list?
>
>http://developer.novell.com/wiki/index.php/Dharma
>
>>
>> As I mentioned before I still have a concern about creating
duplicate
>> data for us all to manage. From your comments above it sounds like
you

>> intend your repository to be the place where the definitions are
>> developed before they are submitted to the oval repository. Is that
>> correct?
>
>To an extent yes. The content submitted to the official mitre
>repository will be developed and available for review by novell
>contributing members. It is my hope that some resources such as 0-day
>vulnerabilities will be fast-tracked through the initial phases of
>community review and quickly submitted to mitre for public
>consumption. However, less critical resources, such as inventory
>definitions or system configuration evaluations will undergo a
>timeline based review process before submission to mitre.
>
>As we've previously discussed, there is metadata currently developed
>inline with all content published by this service. Mitre does not
>accept any such metadata in the official repository. In order to
>accomodate the use of this value-added metadata and still keep
>official content in the mitre repository there must be multiple
>branches of development. How this will be handled is still being
>reviewed.
>
>Furthermore, this resource will provide some functionality that has
>not been implemented within the official repository. Off my head:
>- digital signature implementation
>- XML encryption implementation
>- i18n functionality and implementation
>
>The i18n implementation is of paramount importance in my estimation.
>As novell contributing members are diverse and hail from a great many
>countries; the native acceptance of the oval content produced by this
>repository must be easily consumed. To do so, there will be a great
>many versions of each definition developed in various languages. I
>have constructed a few po files for international translation and will
>place them in the svn repository for your review. The content itself
>will not be altered. But the language encoding will be altered
>accordingly.
>
>I hope this quells your concerns. If not, you have my email address
>and phone number. Feel free to contact me at any time.
>
>Thomas jones
>>
>>
>> Thanks,
>>
>> Jon
>>
>> To unsubscribe, send an email message to LISTSERV@...
with
>> SIGNOFF OVAL-DISCUSSION-LIST
>> in the BODY of the message.  If you have difficulties, write to
OVAL-
>DISCUSSION-LIST-request@...
>> .
>
>To unsubscribe, send an email message to LISTSERV@... with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>DISCUSSION-LIST-request@....

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
Thomas R. Jones
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
That was an unexpected request...but I understand your continued
concern. So are vulnerability definitions also included in your request
or are we just referring to the on-going inventory development?

On Fri, 2008-08-08 at 10:12 -0400, Baker, Jon wrote:

> Thomas,
>
> I have been mulling this over for a while now. I think that the work
> you are doing in your repository is awesome and I would be delighted to
> see your repository be granted compatibility. However, I remain
> concerned about creating large amounts of duplicate content in the
> community. Avoiding duplicate content will reduce content maintenance
> efforts for both of us and also reduce confusion in the community about
> where to look for Novell content. With this in mind I would like to
> suggest that we do not include the contents of your repository in the
> OVAL Repository. Having the Novell content available from a Novell url
> is a huge win for everyone.
>
> I would like to advertise the availability of your repository. We can
> do this through the following web pages once your repository has been
> granted compatibility:
>
> http://oval.mitre.org/repository/index.html
>
> and this page:
>
> http://oval.mitre.org/repository/about/other_repositories.html
>
> Thanks for your continued work for get OVAL definitions for Novell
> products.
>
> Regards,
>
> Jon
>
> ============================================
> Jonathan O. Baker
> The MITRE Corporation
> Email: bakerj@...
>
>
>
> >-----Original Message-----
> >From: Thomas R. Jones [mailto:thomas.jones@...]
> >Sent: Tuesday, July 08, 2008 10:06 AM
> >To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
> >Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
> >
> >Responses inline below.
> >
> >Sent from my iPhone
> >
> >On Jul 7, 2008, at 7:24 AM, "Baker, Jon" <bakerj@...> wrote:
> >
> >>> -----Original Message-----
> >>> From: Thomas R. Jones [mailto:thomas.jones@...]
> >>> Sent: Wednesday, July 02, 2008 9:36 AM
> >>> To: oval-discussion-list OVAL Discussion List/Closed Public
> Discussi
> >>> Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
> >>>
> >>> On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:
> >>>>> -----Original Message-----
> >>>>> From: Thomas R. Jones [mailto:thomas.jones@...]
> >>>>> Sent: Friday, June 27, 2008 5:46 PM
> >>>>> To: oval-discussion-list OVAL Discussion List/Closed Public
> >> Discussi
> >>>>> Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
> >>>>>
> >>>>> Erroneously sent to ONLY mitre. Forwarding to the community for
> >>>> possible
> >>>>> discussion.
> >>>>>
> >>>>> Begin forwarded message:
> >>>>>
> >>>>>
> >>>>>
> >>>>>    From: Thomas R. Jones <thomas.jones@...>
> >>>>>    Date: June 27, 2008 3:45:23 PM CDT
> >>>>>    To: Jon Baker <bakerj@...>
> >>>>>    Subject: Novell submissions
> >>>>>
> >>>>>
> >>>>>
> >>>>>    I am currently preparing the next round of submissions for
> >>>> Novell
> >>>>> packages. There has been no changes to the source as of the
> initial
> >>>>> phase. So this lends me to believe that QA should be smooth and
> >>>> without
> >>>>> much effort.
> >>>>>
> >>>>>    I was going to proceed with additions of the last two
> >>>>> distributions produced by Novell; but have elected to proceed
> with
> >>>>> current development. And release new distribution inventory in
> >>>>> conjunction with code additions within the affected_cpe_list and
> >>>>> platform elements. Personal choice for my ease of development. ;)
> >>>>>
> >>>>>    Is Mitre ready to accept these for community review?
> >>>>>
> >>>>>
> >>>>
> >>>> Yes, we are ready for another batch of definitions for Novell
> >>> products.
> >>>> As we previously discussed it would be ideal if submissions came
> in
> >>>> batches that we can easily process and review. Since you know the
> >>>> content you are submitting I am happy to let you decide how best
> to
> >>>> split up content into batches.
> >>>
> >>> Great! I will do a quick QA to ensure that these definitions have
> not
> >>> been adversely affected somehow by further developments here at
> >> Maitreya
> >>> Security and then submit asap.
> >>>
> >>> We have been processing in lexicographical order. I see no reason
> to
> >>> change an efficient process. ;)
> >>>
> >>
> >> Sounds good to me.
> >>
> >>>>
> >>>> When we last exchanged emails you were considering hosting your
> own
> >>>> repository. Have you made any progress there? As I have said in
> the
> >>>> past, to reduce confusion in the community we would like to avoid
> >>>> having lots of duplicate content floating around. We are thrilled
> to
> >>>> have the inventory content and can host it in the OVAL Repository.
> >> We
> >>>> just would prefer not to have duplicate repositories around.
> >>>
> >>> Yes I have. As you know, the Dharma Repository contains duplicate
> >>> data
> >>> definitions in their developmental state to include particular
> >> metadata
> >>> that Mitre does not accept. So I must remove and re-declare such
> >>> resources path. In our content the schema location is altered to
> >>> point
> >>> to a path that is compliant with the Filesystem Hierarchy
> >> Standard(FHS)
> >>> and the Linux Standard Base(LSB).
> >>>
> >>> Our repository will be utilized for community development and
> review.
> >>> And will be publicly available. As of this moment, it is online.
> >>> However, some services must be worked on-----mainly mailinglist
> >>> notification of SVN changes, deletions and additions. Please feel
> >>> free
> >>> to discuss with me the specifics if you would like to move further
> to
> >>> ensure compliance.
> >>>
> >>
> >> Can you send the url to your repository to this list?
> >
> >http://developer.novell.com/wiki/index.php/Dharma
> >
> >>
> >> As I mentioned before I still have a concern about creating
> duplicate
> >> data for us all to manage. From your comments above it sounds like
> you
> >> intend your repository to be the place where the definitions are
> >> developed before they are submitted to the oval repository. Is that
> >> correct?
> >
> >To an extent yes. The content submitted to the official mitre
> >repository will be developed and available for review by novell
> >contributing members. It is my hope that some resources such as 0-day
> >vulnerabilities will be fast-tracked through the initial phases of
> >community review and quickly submitted to mitre for public
> >consumption. However, less critical resources, such as inventory
> >definitions or system configuration evaluations will undergo a
> >timeline based review process before submission to mitre.
> >
> >As we've previously discussed, there is metadata currently developed
> >inline with all content published by this service. Mitre does not
> >accept any such metadata in the official repository. In order to
> >accomodate the use of this value-added metadata and still keep
> >official content in the mitre repository there must be multiple
> >branches of development. How this will be handled is still being
> >reviewed.
> >
> >Furthermore, this resource will provide some functionality that has
> >not been implemented within the official repository. Off my head:
> >- digital signature implementation
> >- XML encryption implementation
> >- i18n functionality and implementation
> >
> >The i18n implementation is of paramount importance in my estimation.
> >As novell contributing members are diverse and hail from a great many
> >countries; the native acceptance of the oval content produced by this
> >repository must be easily consumed. To do so, there will be a great
> >many versions of each definition developed in various languages. I
> >have constructed a few po files for international translation and will
> >place them in the svn repository for your review. The content itself
> >will not be altered. But the language encoding will be altered
> >accordingly.
> >
> >I hope this quells your concerns. If not, you have my email address
> >and phone number. Feel free to contact me at any time.
> >
> >Thomas jones
> >>
> >>
> >> Thanks,
> >>
> >> Jon
> >>
> >> To unsubscribe, send an email message to LISTSERV@...
> with
> >> SIGNOFF OVAL-DISCUSSION-LIST
> >> in the BODY of the message.  If you have difficulties, write to
> OVAL-
> >DISCUSSION-LIST-request@...
> >> .
> >
> >To unsubscribe, send an email message to LISTSERV@... with
> >SIGNOFF OVAL-DISCUSSION-LIST
> >in the BODY of the message.  If you have difficulties, write to OVAL-
> >DISCUSSION-LIST-request@....
>
> To unsubscribe, send an email message to LISTSERV@... with
> SIGNOFF OVAL-DISCUSSION-LIST
> in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....
bakerj
Re: Fwd: Novell submissions
Reply Threaded More
Print post
Permalink
>-----Original Message-----
>From: Thomas R. Jones [mailto:thomas.jones@...]
>Sent: Friday, August 08, 2008 10:20 AM
>To: oval-discussion-list OVAL Discussion List/Closed Public Discussi
>Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>
>That was an unexpected request...but I understand your continued
>concern. So are vulnerability definitions also included in your
request
>or are we just referring to the on-going inventory development?
>

Thomas,

If you plan to host the vulnerability definitions in your repository
then we should probably not host them in the OVAL Repository either. I
am sorry for the unexpected response on this. I don't want to
understate the importance of the Novell content you are working on. It
is important and I think that it is very important for OVAL as a
project to do a good job of highlighting efforts like your repository.

Regards,

Jon

>On Fri, 2008-08-08 at 10:12 -0400, Baker, Jon wrote:
>> Thomas,
>>
>> I have been mulling this over for a while now. I think that the work
>> you are doing in your repository is awesome and I would be delighted
>to
>> see your repository be granted compatibility. However, I remain
>> concerned about creating large amounts of duplicate content in the
>> community. Avoiding duplicate content will reduce content
maintenance
>> efforts for both of us and also reduce confusion in the community
>about
>> where to look for Novell content. With this in mind I would like to
>> suggest that we do not include the contents of your repository in
the
>> OVAL Repository. Having the Novell content available from a Novell
url
>> is a huge win for everyone.
>>
>> I would like to advertise the availability of your repository. We
can
>> do this through the following web pages once your repository has
been

>> granted compatibility:
>>
>> http://oval.mitre.org/repository/index.html
>>
>> and this page:
>>
>> http://oval.mitre.org/repository/about/other_repositories.html
>>
>> Thanks for your continued work for get OVAL definitions for Novell
>> products.
>>
>> Regards,
>>
>> Jon
>>
>> ============================================
>> Jonathan O. Baker
>> The MITRE Corporation
>> Email: bakerj@...
>>
>>
>>
>> >-----Original Message-----
>> >From: Thomas R. Jones [mailto:thomas.jones@...]
>> >Sent: Tuesday, July 08, 2008 10:06 AM
>> >To: oval-discussion-list OVAL Discussion List/Closed Public
Discussi

>> >Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>> >
>> >Responses inline below.
>> >
>> >Sent from my iPhone
>> >
>> >On Jul 7, 2008, at 7:24 AM, "Baker, Jon" <bakerj@...> wrote:
>> >
>> >>> -----Original Message-----
>> >>> From: Thomas R. Jones [mailto:thomas.jones@...]
>> >>> Sent: Wednesday, July 02, 2008 9:36 AM
>> >>> To: oval-discussion-list OVAL Discussion List/Closed Public
>> Discussi
>> >>> Subject: Re: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>> >>>
>> >>> On Wed, 2008-07-02 at 06:49 -0400, Baker, Jon wrote:
>> >>>>> -----Original Message-----
>> >>>>> From: Thomas R. Jones
[mailto:thomas.jones@...]
>> >>>>> Sent: Friday, June 27, 2008 5:46 PM
>> >>>>> To: oval-discussion-list OVAL Discussion List/Closed Public
>> >> Discussi
>> >>>>> Subject: [OVAL-DISCUSSION-LIST] Fwd: Novell submissions
>> >>>>>
>> >>>>> Erroneously sent to ONLY mitre. Forwarding to the community
for

>> >>>> possible
>> >>>>> discussion.
>> >>>>>
>> >>>>> Begin forwarded message:
>> >>>>>
>> >>>>>
>> >>>>>
>> >>>>>    From: Thomas R. Jones <thomas.jones@...>
>> >>>>>    Date: June 27, 2008 3:45:23 PM CDT
>> >>>>>    To: Jon Baker <bakerj@...>
>> >>>>>    Subject: Novell submissions
>> >>>>>
>> >>>>>
>> >>>>>
>> >>>>>    I am currently preparing the next round of submissions for
>> >>>> Novell
>> >>>>> packages. There has been no changes to the source as of the
>> initial
>> >>>>> phase. So this lends me to believe that QA should be smooth
and
>> >>>> without
>> >>>>> much effort.
>> >>>>>
>> >>>>>    I was going to proceed with additions of the last two
>> >>>>> distributions produced by Novell; but have elected to proceed
>> with
>> >>>>> current development. And release new distribution inventory in
>> >>>>> conjunction with code additions within the affected_cpe_list
and

>> >>>>> platform elements. Personal choice for my ease of development.
>;)
>> >>>>>
>> >>>>>    Is Mitre ready to accept these for community review?
>> >>>>>
>> >>>>>
>> >>>>
>> >>>> Yes, we are ready for another batch of definitions for Novell
>> >>> products.
>> >>>> As we previously discussed it would be ideal if submissions
came
>> in
>> >>>> batches that we can easily process and review. Since you know
the
>> >>>> content you are submitting I am happy to let you decide how
best
>> to
>> >>>> split up content into batches.
>> >>>
>> >>> Great! I will do a quick QA to ensure that these definitions
have
>> not
>> >>> been adversely affected somehow by further developments here at
>> >> Maitreya
>> >>> Security and then submit asap.
>> >>>
>> >>> We have been processing in lexicographical order. I see no
reason

>> to
>> >>> change an efficient process. ;)
>> >>>
>> >>
>> >> Sounds good to me.
>> >>
>> >>>>
>> >>>> When we last exchanged emails you were considering hosting your
>> own
>> >>>> repository. Have you made any progress there? As I have said in
>> the
>> >>>> past, to reduce confusion in the community we would like to
avoid
>> >>>> having lots of duplicate content floating around. We are
thrilled
>> to
>> >>>> have the inventory content and can host it in the OVAL
>Repository.
>> >> We
>> >>>> just would prefer not to have duplicate repositories around.
>> >>>
>> >>> Yes I have. As you know, the Dharma Repository contains
duplicate

>> >>> data
>> >>> definitions in their developmental state to include particular
>> >> metadata
>> >>> that Mitre does not accept. So I must remove and re-declare such
>> >>> resources path. In our content the schema location is altered to
>> >>> point
>> >>> to a path that is compliant with the Filesystem Hierarchy
>> >> Standard(FHS)
>> >>> and the Linux Standard Base(LSB).
>> >>>
>> >>> Our repository will be utilized for community development and
>> review.
>> >>> And will be publicly available. As of this moment, it is online.
>> >>> However, some services must be worked on-----mainly mailinglist
>> >>> notification of SVN changes, deletions and additions. Please
feel
>> >>> free
>> >>> to discuss with me the specifics if you would like to move
further

>> to
>> >>> ensure compliance.
>> >>>
>> >>
>> >> Can you send the url to your repository to this list?
>> >
>> >http://developer.novell.com/wiki/index.php/Dharma
>> >
>> >>
>> >> As I mentioned before I still have a concern about creating
>> duplicate
>> >> data for us all to manage. From your comments above it sounds
like
>> you
>> >> intend your repository to be the place where the definitions are
>> >> developed before they are submitted to the oval repository. Is
that
>> >> correct?
>> >
>> >To an extent yes. The content submitted to the official mitre
>> >repository will be developed and available for review by novell
>> >contributing members. It is my hope that some resources such as
0-day
>> >vulnerabilities will be fast-tracked through the initial phases of
>> >community review and quickly submitted to mitre for public
>> >consumption. However, less critical resources, such as inventory
>> >definitions or system configuration evaluations will undergo a
>> >timeline based review process before submission to mitre.
>> >
>> >As we've previously discussed, there is metadata currently
developed

>> >inline with all content published by this service. Mitre does not
>> >accept any such metadata in the official repository. In order to
>> >accomodate the use of this value-added metadata and still keep
>> >official content in the mitre repository there must be multiple
>> >branches of development. How this will be handled is still being
>> >reviewed.
>> >
>> >Furthermore, this resource will provide some functionality that has
>> >not been implemented within the official repository. Off my head:
>> >- digital signature implementation
>> >- XML encryption implementation
>> >- i18n functionality and implementation
>> >
>> >The i18n implementation is of paramount importance in my
estimation.
>> >As novell contributing members are diverse and hail from a great
many
>> >countries; the native acceptance of the oval content produced by
this
>> >repository must be easily consumed. To do so, there will be a great
>> >many versions of each definition developed in various languages. I
>> >have constructed a few po files for international translation and
>will
>> >place them in the svn repository for your review. The content
itself

>> >will not be altered. But the language encoding will be altered
>> >accordingly.
>> >
>> >I hope this quells your concerns. If not, you have my email address
>> >and phone number. Feel free to contact me at any time.
>> >
>> >Thomas jones
>> >>
>> >>
>> >> Thanks,
>> >>
>> >> Jon
>> >>
>> >> To unsubscribe, send an email message to LISTSERV@...
>> with
>> >> SIGNOFF OVAL-DISCUSSION-LIST
>> >> in the BODY of the message.  If you have difficulties, write to
>> OVAL-
>> >DISCUSSION-LIST-request@...
>> >> .
>> >
>> >To unsubscribe, send an email message to LISTSERV@...
>with
>> >SIGNOFF OVAL-DISCUSSION-LIST
>> >in the BODY of the message.  If you have difficulties, write to
OVAL-
>> >DISCUSSION-LIST-request@....
>>
>> To unsubscribe, send an email message to LISTSERV@...
with
>> SIGNOFF OVAL-DISCUSSION-LIST
>> in the BODY of the message.  If you have difficulties, write to
OVAL-
>DISCUSSION-LIST-request@....
>
>To unsubscribe, send an email message to LISTSERV@... with
>SIGNOFF OVAL-DISCUSSION-LIST
>in the BODY of the message.  If you have difficulties, write to OVAL-
>DISCUSSION-LIST-request@....

To unsubscribe, send an email message to LISTSERV@... with
SIGNOFF OVAL-DISCUSSION-LIST
in the BODY of the message.  If you have difficulties, write to OVAL-DISCUSSION-LIST-request@....