You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
<metaname="dct.abstract" content="When security vulnerabilities are discovered by independent security researchers, they often lack the channels to report them properly. As a result, security vulnerabilities may be left unreported. This document defines a format (“security.txt”) to help organizations describe the process for security researchers to follow in order to report security vulnerabilities." />
345
345
<metaname="description" content="When security vulnerabilities are discovered by independent security researchers, they often lack the channels to report them properly. As a result, security vulnerabilities may be left unreported. This document defines a format (“security.txt”) to help organizations describe the process for security researchers to follow in order to report security vulnerabilities." />
346
346
@@ -364,12 +364,12 @@
364
364
<tdclass="right">Y. Shafranovich</td>
365
365
</tr>
366
366
<tr>
367
-
<tdclass="left">Expires: May 15, 2020</td>
367
+
<tdclass="left">Expires: May 22, 2020</td>
368
368
<tdclass="right">Nightwatch Cybersecurity</td>
369
369
</tr>
370
370
<tr>
371
371
<tdclass="left"></td>
372
-
<tdclass="right">November 12, 2019</td>
372
+
<tdclass="right">November 19, 2019</td>
373
373
</tr>
374
374
375
375
@@ -385,7 +385,7 @@ <h1 id="rfc.status"><a href="#rfc.status">Status of This Memo</a></h1>
385
385
<p>This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.</p>
386
386
<p>Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.</p>
387
387
<p>Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."</p>
388
-
<p>This Internet-Draft will expire on May 15, 2020.</p>
388
+
<p>This Internet-Draft will expire on May 22, 2020.</p>
<p>Copyright (c) 2019 IETF Trust and the persons identified as the document authors. All rights reserved.</p>
391
391
<p>This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.</p>
@@ -510,7 +510,7 @@ <h1 id="rfc.section.1.1">
510
510
<pid="rfc.section.1.1.p.1">Many security researchers encounter situations where they are unable to report security vulnerabilities to organizations because there is no course of action laid out and no way indicated to contact the owner of a particular resource.</p>
511
511
<pid="rfc.section.1.1.p.2">As per section 4 of <ahref="#RFC2142" class="xref">[RFC2142]</a>, there is an existing convention of using the <SECURITY@domain> email address for communications regarding security vulnerabilities. That convention provides only a single, email-based channel of communication for security vulnerabilities per domain, and does not provide a way for domain owners to publish information about their security disclosure policies.</p>
512
512
<pid="rfc.section.1.1.p.3">There are also contact conventions prescribed for Internet Service Providers (ISPs) in section 2 of <ahref="#RFC3013" class="xref">[RFC3013]</a>, for Computer Security Incident Response Teams (CSIRTs) in section 3.2 of <ahref="#RFC2350" class="xref">[RFC2350]</a> and for site operators in section 5.2 of <ahref="#RFC2196" class="xref">[RFC2196]</a>. As per <ahref="#RFC7485" class="xref">[RFC7485]</a>, there is also contact information provided by Regional Internet Registries (RIRs) and domain registries for owners of IP addresses, autonomous system numbers (ASNs) and domain names. However, none of these address the issue of how security researchers can locate disclosure policies and contact information for organizations in order to report security vulnerabilities.</p>
513
-
<pid="rfc.section.1.1.p.4">In this document, we define a richer, machine-parsable and more extensible way for organizations to communicate information about their security disclosure policies, which is not limited to email and also allows for additional features such as encryption. This format is designed to help assist with the security disclosure process by making it easier for organizations to designate the preferred steps for researchers to take when trying to reach out to them with security vulnerabilities.</p>
513
+
<pid="rfc.section.1.1.p.4">In this document, we define a richer, machine-parsable and extensible way for organizations to communicate information about their security disclosure policies, which is not limited to email and also allows for additional features such as encryption. This format is designed to help assist with the security disclosure process by making it easier for organizations to designate the preferred steps for researchers to take when trying to reach out to them with security vulnerabilities.</p>
514
514
<pid="rfc.section.1.1.p.5">Other details of vulnerability disclosure are outside the scope of this document. Readers are encouraged to consult other documents such as <ahref="#ISO.29147.2018" class="xref">[ISO.29147.2018]</a> or <ahref="#CERT.CVD" class="xref">[CERT.CVD]</a>.</p>
<ahref="#rfc.section.7.2">7.2.</a><ahref="#registry" id="registry">Registry for security.txt Header Fields</a>
852
854
</h1>
853
855
<pid="rfc.section.7.2.p.1">IANA is requested to create the “security.txt Header Fields” registry in accordance with <ahref="#RFC8126" class="xref">[RFC8126]</a>. This registry will contain header fields for use in security.txt files, defined by this specification.</p>
854
-
<pid="rfc.section.7.2.p.2">New registrations or updates MUST be published in accordance with the “Expert Review” guidelines as described in section 4.5 of <ahref="#RFC8126" class="xref">[RFC8126]</a>. Any new field thus registered is considered optional by this specification unless a new version of this specification is published.</p>
855
-
<pid="rfc.section.7.2.p.3">New registrations and updates MUST contain the following information:</p>
856
+
<pid="rfc.section.7.2.p.2">New registrations or updates MUST be published in accordance with the “Expert Review” guidelines as described in sections 4.5 and 5 of <ahref="#RFC8126" class="xref">[RFC8126]</a>. Any new field thus registered is considered optional by this specification unless a new version of this specification is published.</p>
857
+
<pid="rfc.section.7.2.p.3">Designated Experts are expected to check whether a proposed registration or update makes sense in the context of this specification and provides value to the wider Internet community.</p>
858
+
<pid="rfc.section.7.2.p.4">New registrations and updates MUST contain the following information:</p>
856
859
<p></p>
857
860
858
861
<ol>
@@ -868,8 +871,8 @@ <h1 id="rfc.section.7.2">
868
871
</li>
869
872
<li>Change controller</li>
870
873
</ol>
871
-
<pid="rfc.section.7.2.p.5">An update may make a notation on an existing registration indicating that a registered field is historical or deprecated if appropriate.</p>
872
-
<pid="rfc.section.7.2.p.6">The initial registry contains these values:</p>
874
+
<pid="rfc.section.7.2.p.6">An update may make a notation on an existing registration indicating that a registered field is historical or deprecated if appropriate.</p>
875
+
<pid="rfc.section.7.2.p.7">The initial registry contains these values:</p>
873
876
<pre>
874
877
Field Name: Acknowledgments
875
878
Description: link to page where security researchers are recognized
@@ -1218,6 +1221,8 @@ <h1 id="rfc.appendix.B.8">
1218
1221
<ul>
1219
1222
<li>Addressing AD feedback (#165)</li>
1220
1223
<li>Fix for ABNF grammar in lang-values (#164)</li>
1224
+
<li>Fixing idnits warnings</li>
1225
+
<li>Adding guidance for designated experts</li>
1221
1226
</ul>
1222
1227
<pid="rfc.section.B.8.p.2">Full list of changes can be viewed via the IETF document tracker: https://tools.ietf.org/html/draft-foudil-securitytxt</p>
0 commit comments