We will try to get a list of differences out to you. A mechanical diff won t work in this case, so we will create a high level overview. Please be aware that this is coming forward as an extension object, not as an update to the specification
at this time.
Emily
From: aa tt <
atcyber1000@gmail.com>
Date: Wednesday, March 2, 2022 at 10:34 AM
To: Emily Ratliff <
Emily.Ratliff@ibm.com>
Cc: Bret Jordan <
bj@ctin.us>, "cti@lists.oasis-open.org" <
cti@lists.oasis-open.org>
Subject: [EXTERNAL] Re: [cti] STIX WG - Please review object signing proposal
I m unable to attend such a meeting (due to many conflicts) but I would also ask the team provide a delta presentation or doc and help provide insight/why a delta needs to exist. I
generally agree that coming up with 2 solutions for digital ZjQcmQRYFpfptBannerStart
This Message Is From an External Sender
This message came from outside your organization.
ZjQcmQRYFpfptBannerEnd
I m unable to attend such a meeting (due to many conflicts) but I would also ask the team provide a delta presentation or doc and help provide insight/why a delta needs to exist.
I generally agree that coming up with 2 solutions for digital signing on STIX/CACAO (fundamentally JSON) makes no sense and will likely undermine the whole objective.
Would it be possible for someone to provide a summary on the differences? Any insight on pro/con on what the delta does would also help.
I m very familiar with the CACAO (fundamentally its just JSON) signing. So it would help me understand better if such a delta existed.
Allan
On Mar 2, 2022, at 8:27 AM, Emily Ratliff <
Emily.Ratliff@ibm.com > wrote:
Hi Bret,
Are you able to join us next week to discuss your concerns and hear the rationale for the differences?
Emily
From: Bret Jordan <
bj@ctin.us >
Date: Wednesday, March 2, 2022 at 10:12 AM
To: Emily Ratliff <
Emily.Ratliff@ibm.com >
Cc: "
cti@lists.oasis-open.org " <
cti@lists.oasis-open.org >
Subject: [EXTERNAL] Re: [cti] STIX WG - Please review object signing proposal
HI Emily, I would like to see a diff of this proposal from the proposal I submitted to this TC based on what CACAO did. From what I can tell, JMG just tweaked my original
content. So a diff would be very helpful since the CACAO version is already
ZjQcmQRYFpfptBannerStart
This Message Is From an External Sender
This message came from outside your organization.
ZjQcmQRYFpfptBannerEnd
HI Emily,
I would like to see a diff of this proposal from the proposal I submitted to this TC based on what CACAO did. From what I can tell, JMG just tweaked my original content. So a diff would be very helpful since the CACAO version is already
being used in the wild. Reinventing the wheel is never a good idea and diminishes the value of OASIS as whole.
Bret
On Mar 1, 2022, at 5:21 PM, Emily Ratliff <
Emily.Ratliff@ibm.com > wrote:
Hi STIX WG,
John-Mark sent out his proposal for JSON Signing last week. I got some reports that some people did not receive his email. For next week s meeting, please review the proposal here:
https://www.oasis-open.org/committees/document.php?document_id=69653&wg_abbrev=cti and come prepared to discuss.
Thanks!
Emily