[IDMEF] [Issue 3] additionaldata and meaning

Herve Debar <[email protected]> Thu, 08 Jan 2004 17:35:39 +0100
Newsgroups gmane.ietf.idwg
Organization France Telecom R et D
Message-ID <[email protected]>
Herve> The current tag for introducing additionaldata is the
Herve> following:
Herve> <additionaldata type=[fixed list] meaning=[free text]>

Herve> I propose to specify a non-mandatory list for meaning,
Herve> as a best-current-practice, to help convergence on the
Herve> description of additional data. I would include "packet-dump"
Herve> in the list.

DaveC> I thought this had come up before and was rejected by the
DaveC> group, although I may be misremembering things.  I don't
DaveC> have any strong feelings one way or the other.

Zaraska> Agreed. This is absolutely necessary.
[NOTE: I have splitted the issue in 2, and have included K Zaraska's 
comment in both, as I believe it adresses the two final issues. My 
mistake if it does not.]

The rationale for proposing such a list is to help interoperability. I 
see it as a BCP rather than a normative reference. However, I am 
reluctant to have yet another draft that would be a BCP on how to use 
the free text in all possible fields of the IDMEF DTD/Schema. So I was 
hoping that a statement like

"MAY use one of the keywords of the following list to represent this 
kind of information ...."

would be acceptable to everybody. Please comment so that we can reach 
a concensus.

BTW, if we moved to schemas, my understanding is that we could then 
have an (extensible) namespace there. Am I right ?

Hervé
-- 
Hervé Debar             <mailto:[email protected]>
Tel: +33 (0)2 31 75 92 61            GSM: +33 (0)6 74 09 09 66
France Télécom R&D                   Fax: +33 (0)2 31 75 93 13
42 rue des Coutures  (--)  BP 6243  (--)  F-14066 Caen Cedex 4