Re: [IDMEF] [Issue 3] additionaldata and meaning

"David A. Curry" <[email protected]> Sun, 11 Jan 2004 20:43:47 -0500
Newsgroups gmane.ietf.idwg
Message-ID <[email protected]>
>>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote:

  Herve> The current tag for introducing additionaldata is the following:
  Herve> <additionaldata type=[fixed list] meaning=[free text]>
  Herve> I propose to specify a non-mandatory list for meaning, as a
  Herve> best-current-practice, to help convergence on the description of
  Herve> additional data. I would include "packet-dump" in the list.

  Herve> The rationale for proposing such a list is to help interoperability. I
  Herve> see it as a BCP rather than a normative reference. However, I am
  Herve> reluctant to have yet another draft that would be a BCP on how to use
  Herve> the free text in all possible fields of the IDMEF DTD/Schema. So I was
  Herve> hoping that a statement like
  Herve> "MAY use one of the keywords of the following list to represent this
  Herve> kind of information ...."

The only thing that bothers me about "MAY" is you're going to end up with
people who make wonderful decisions like "that's not bluish-green, it's
cyan, so since you say 'may' I'll change it."

I think a better way might be to provide a halfway decent list, and then
say something like "SHOULD use one of the keywords if possible, although
MAY define a new word if there are no close matches".  Or something like
that.

--Dave