Hi all,
Developer Days are long gone, but I would like to propose another wacky
idea. This is based on the assumption that people actually read the
descriptions which is a poor assumption but I am sticking to it. One of
the goals of SCAP is "XCCDF should be structured to foster the
generation of readable prose documents from XCCDF-format documents." We
could improve the descriptions of our rules (and some groups).
For example given:
The <SERVICE NAME> service should be enabled or disabled as
appropriate.
or
The password minimum length should be set appropriately.
Could we instead have something like
The <SERVICE NAME> service should be {some-var-id:selector}.
or
The password minimum length should be {some-other-var-id:value}.
The idea is to use either the selector or value chosen by the selected
profile. We could default to something by convention and allow just
{some-var-id} to mean something. I don't have a good story for
localized content. If this idea has merit, we can try to think of
something better. Making things complicated is usually a bad idea, but
it would make things a lot more readable. This is an issue both in
XCCDF and OVAL (and all other checking systems). Ideally, we could help
readability everywhere, but starting in XCCDF would be nice.
Besides the fact that changing anything is evil and the reality that
changing XCCDF is impossible, is this worth considering?
Thanks,
Vladimir Giszpenc
DSCI Contractor Supporting
US Army CERDEC S&TCD IAD Tactical Network Protection Branch
(732) 532-8959
---------------------------------------------------------------
To unsubscribe from this mailing list, please send an e-mail to
[hidden email] with the words "unsubscribe xccdf-dev" in the
body. You will need to send this from the email account that you
used to initially subscribe to xccdf-dev.