Re: [IDMEF] [Issue 3] additionaldata and meaning
"David A. Curry" <[email protected]> Sun, 11 Jan 2004 20:43:47 -0500
| Newsgroups | gmane.ietf.idwg |
|---|---|
| Message-ID | <[email protected]> |
>>>>> On Thu, 8 Jan 2004, Herve Debar, identified as "Herve" below, wrote: Herve> The current tag for introducing additionaldata is the following: Herve> <additionaldata type=[fixed list] meaning=[free text]> Herve> I propose to specify a non-mandatory list for meaning, as a Herve> best-current-practice, to help convergence on the description of Herve> additional data. I would include "packet-dump" in the list. Herve> The rationale for proposing such a list is to help interoperability. I Herve> see it as a BCP rather than a normative reference. However, I am Herve> reluctant to have yet another draft that would be a BCP on how to use Herve> the free text in all possible fields of the IDMEF DTD/Schema. So I was Herve> hoping that a statement like Herve> "MAY use one of the keywords of the following list to represent this Herve> kind of information ...." The only thing that bothers me about "MAY" is you're going to end up with people who make wonderful decisions like "that's not bluish-green, it's cyan, so since you say 'may' I'll change it." I think a better way might be to provide a halfway decent list, and then say something like "SHOULD use one of the keywords if possible, although MAY define a new word if there are no close matches". Or something like that. --Dave