This Internet-Draft is submitted in full conformance with the provisions of BCP 78 and BCP 79.
Internet-Drafts are working documents of the Internet Engineering Task Force (IETF). Note that other groups may also distribute working documents as Internet-Drafts. The list of current Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.
Internet-Drafts are draft documents valid for a maximum of six months and may be updated, replaced, or obsoleted by other documents at any time. It is inappropriate to use Internet-Drafts as reference material or to cite them other than as "work in progress."
-
This Internet-Draft will expire on October 10, 2019.
+
This Internet-Draft will expire on October 21, 2019.
Copyright (c) 2019 IETF Trust and the persons identified as the document authors. All rights reserved.
This document is subject to BCP 78 and the IETF Trust's Legal Provisions Relating to IETF Documents (https://trustee.ietf.org/license-info) in effect on the date of publication of this document. Please review these documents carefully, as they describe your rights and restrictions with respect to this document. Code Components extracted from this document must include Simplified BSD License text as described in Section 4.e of the Trust Legal Provisions and are provided without warranty as described in the Simplified BSD License.
The expected file format of the security.txt file is plain text (MIME type “text/plain”) as defined in section 4.1.3 of [RFC2046] and is encoded using UTF-8 [RFC3629] in Net-Unicode form [RFC5198].
The following is an ABNF definition of the security.txt format, using the conventions defined in [RFC5234].
-body = signed / unsigned
+body = signed / unsigned
-signed = sign-header unsigned sign-footer
+signed = sign-header unsigned sign-footer
-sign-header = <headers and line from section 7 of [RFC4880]>
+sign-header = <headers and line from section 7 of [RFC4880]>
-sign-footer = <OpenPGP signature from section 7 of [RFC4880]>
+sign-footer = <OpenPGP signature from section 7 of [RFC4880]>
-unsigned = *line (canonical-field eol) (lang-field eol) *line
+unsigned = *line [canonical-field eol *line] [lang-field eol] *line
+unsigned =/ *line [lang-field eol *line] [canonical-field eol] *line
-line = (field / comment) eol
+line = (field / comment) eol
-eol = *WSP [CR] LF
+eol = *WSP [CR] LF
-field = ack-field /
- contact-field /
- encryption-field /
- hiring-field /
- policy-field /
- ext-field
+field = ack-field /
+ contact-field /
+ encryption-field /
+ hiring-field /
+ policy-field /
+ ext-field
-fs = ":"
+fs = ":"
-comment = "#" *(WSP / VCHAR / %x80-FFFFF)
+comment = "#" *(WSP / VCHAR / %x80-FFFFF)
-ack-field = "Acknowledgments" fs SP uri
+ack-field = "Acknowledgments" fs SP uri
-canonical-field = "Canonical" fs SP uri
+canonical-field = "Canonical" fs SP uri
-contact-field = "Contact" fs SP uri
+contact-field = "Contact" fs SP uri
-lang-tag = <Language-Tag from section 2.1 of [RFC5646]>
+lang-tag = <Language-Tag from section 2.1 of [RFC5646]>
-uri = <URI as per [RFC3986]>
+uri = <URI as per [RFC3986]>
-encryption-field = "Encryption" fs SP uri
+encryption-field = "Encryption" fs SP uri
-hiring-field = "Hiring" fs SP uri
+hiring-field = "Hiring" fs SP uri
-policy-field = "Policy" fs SP uri
+policy-field = "Policy" fs SP uri
-lang-field = "Preferred-Languages" fs SP lang-values
+lang-field = "Preferred-Languages" fs SP lang-values
-lang-values = lang-tag *("," [WSP] lang-tag)
+lang-values = lang-tag *("," [WSP] lang-tag)
-ext-field = field-name fs SP unstructured
+ext-field = field-name fs SP unstructured
-field-name = <imported from section 3.6.8 of [RFC5322]>
+field-name = <imported from section 3.6.8 of [RFC5322]>
-unstructured = <imported from section 3.2.5 of [RFC5322]>
+unstructured = <imported from section 3.2.5 of [RFC5322]>
“ext-field” refers to extension fields, which are discussed in Section 4.4
diff --git a/draft-foudil-securitytxt.md b/draft-foudil-securitytxt.md
index ff9874b..2b3223d 100644
--- a/draft-foudil-securitytxt.md
+++ b/draft-foudil-securitytxt.md
@@ -413,56 +413,57 @@ The following is an ABNF definition of the security.txt format, using
the conventions defined in {{!RFC5234}}.
~~~~~~~~~~
-body = signed / unsigned
+body = signed / unsigned
-signed = sign-header unsigned sign-footer
+signed = sign-header unsigned sign-footer
-sign-header =
+sign-header =
-sign-footer =
+sign-footer =
-unsigned = *line (canonical-field eol) (lang-field eol) *line
+unsigned = *line [canonical-field eol *line] [lang-field eol] *line
+unsigned =/ *line [lang-field eol *line] [canonical-field eol] *line
-line = (field / comment) eol
+line = (field / comment) eol
-eol = *WSP [CR] LF
+eol = *WSP [CR] LF
-field = ack-field /
- contact-field /
- encryption-field /
- hiring-field /
- policy-field /
- ext-field
+field = ack-field /
+ contact-field /
+ encryption-field /
+ hiring-field /
+ policy-field /
+ ext-field
-fs = ":"
+fs = ":"
-comment = "#" *(WSP / VCHAR / %x80-FFFFF)
+comment = "#" *(WSP / VCHAR / %x80-FFFFF)
-ack-field = "Acknowledgments" fs SP uri
+ack-field = "Acknowledgments" fs SP uri
-canonical-field = "Canonical" fs SP uri
+canonical-field = "Canonical" fs SP uri
-contact-field = "Contact" fs SP uri
+contact-field = "Contact" fs SP uri
-lang-tag =
+lang-tag =
-uri =
+uri =
-encryption-field = "Encryption" fs SP uri
+encryption-field = "Encryption" fs SP uri
-hiring-field = "Hiring" fs SP uri
+hiring-field = "Hiring" fs SP uri
-policy-field = "Policy" fs SP uri
+policy-field = "Policy" fs SP uri
-lang-field = "Preferred-Languages" fs SP lang-values
+lang-field = "Preferred-Languages" fs SP lang-values
-lang-values = lang-tag *("," [WSP] lang-tag)
+lang-values = lang-tag *("," [WSP] lang-tag)
-ext-field = field-name fs SP unstructured
+ext-field = field-name fs SP unstructured
-field-name =
+field-name =
-unstructured =
+unstructured =
~~~~~~~~~~
"ext-field" refers to extension fields, which are discussed in {{extensibility}}
@@ -740,5 +741,8 @@ of DNS-stored encryption keys (#28 and #94)
- Added language handling redirects (#143)
- Expanded security considerations section and fixed typos (#30, #73, #103, #112)
+## Since draft-foudil-securitytxt-06
+- Fixed ABNF grammar for non-chainable directives (#150)
+
Full list of changes can be viewed via the IETF document tracker:
https://tools.ietf.org/html/draft-foudil-securitytxt
diff --git a/draft-foudil-securitytxt.txt b/draft-foudil-securitytxt.txt
index 5fb115b..65c43ed 100644
--- a/draft-foudil-securitytxt.txt
+++ b/draft-foudil-securitytxt.txt
@@ -5,8 +5,8 @@
Network Working Group E. Foudil
Internet-Draft
Intended status: Informational Y. Shafranovich
-Expires: October 10, 2019 Nightwatch Cybersecurity
- April 08, 2019
+Expires: October 21, 2019 Nightwatch Cybersecurity
+ April 19, 2019
A Method for Web Security Policies
@@ -36,7 +36,7 @@ Status of This Memo
time. It is inappropriate to use Internet-Drafts as reference
material or to cite them other than as "work in progress."
- This Internet-Draft will expire on October 10, 2019.
+ This Internet-Draft will expire on October 21, 2019.
Copyright Notice
@@ -53,7 +53,7 @@ Copyright Notice
-Foudil & Shafranovich Expires October 10, 2019 [Page 1]
+Foudil & Shafranovich Expires October 21, 2019 [Page 1]
Internet-Draft A Method for Web Security Policies April 2019
@@ -109,7 +109,7 @@ Table of Contents
-Foudil & Shafranovich Expires October 10, 2019 [Page 2]
+Foudil & Shafranovich Expires October 21, 2019 [Page 2]
Internet-Draft A Method for Web Security Policies April 2019
@@ -119,6 +119,7 @@ Internet-Draft A Method for Web Security Policies April 2019
B.4. Since draft-foudil-securitytxt-03 . . . . . . . . . . . . 21
B.5. Since draft-foudil-securitytxt-04 . . . . . . . . . . . . 21
B.6. Since draft-foudil-securitytxt-05 . . . . . . . . . . . . 22
+ B.7. Since draft-foudil-securitytxt-06 . . . . . . . . . . . . 22
Authors' Addresses . . . . . . . . . . . . . . . . . . . . . . . 22
1. Introduction
@@ -164,8 +165,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-
-Foudil & Shafranovich Expires October 10, 2019 [Page 3]
+Foudil & Shafranovich Expires October 21, 2019 [Page 3]
Internet-Draft A Method for Web Security Policies April 2019
@@ -221,7 +221,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 4]
+Foudil & Shafranovich Expires October 21, 2019 [Page 4]
Internet-Draft A Method for Web Security Policies April 2019
@@ -277,7 +277,7 @@ https://[2001:db8:8:4::2]/.well-known/security.txt
-Foudil & Shafranovich Expires October 10, 2019 [Page 5]
+Foudil & Shafranovich Expires October 21, 2019 [Page 5]
Internet-Draft A Method for Web Security Policies April 2019
@@ -333,7 +333,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 6]
+Foudil & Shafranovich Expires October 21, 2019 [Page 6]
Internet-Draft A Method for Web Security Policies April 2019
@@ -389,7 +389,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 7]
+Foudil & Shafranovich Expires October 21, 2019 [Page 7]
Internet-Draft A Method for Web Security Policies April 2019
@@ -445,7 +445,7 @@ Encryption: dns:5d2d37ab76d47d36._openpgpkey.example.com?type=OPENPGPKEY
-Foudil & Shafranovich Expires October 10, 2019 [Page 8]
+Foudil & Shafranovich Expires October 21, 2019 [Page 8]
Internet-Draft A Method for Web Security Policies April 2019
@@ -501,7 +501,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 9]
+Foudil & Shafranovich Expires October 21, 2019 [Page 9]
Internet-Draft A Method for Web Security Policies April 2019
@@ -557,7 +557,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 10]
+Foudil & Shafranovich Expires October 21, 2019 [Page 10]
Internet-Draft A Method for Web Security Policies April 2019
@@ -574,63 +574,65 @@ Internet-Draft A Method for Web Security Policies April 2019
The following is an ABNF definition of the security.txt format, using
the conventions defined in [RFC5234].
- body = signed / unsigned
+body = signed / unsigned
- signed = sign-header unsigned sign-footer
+signed = sign-header unsigned sign-footer
- sign-header =
+sign-header =
- sign-footer =
+sign-footer =
- unsigned = *line (canonical-field eol) (lang-field eol) *line
+unsigned = *line [canonical-field eol *line] [lang-field eol] *line
+unsigned =/ *line [lang-field eol *line] [canonical-field eol] *line
- line = (field / comment) eol
+line = (field / comment) eol
- eol = *WSP [CR] LF
+eol = *WSP [CR] LF
- field = ack-field /
- contact-field /
- encryption-field /
- hiring-field /
- policy-field /
- ext-field
+field = ack-field /
+ contact-field /
+ encryption-field /
+ hiring-field /
+ policy-field /
+ ext-field
- fs = ":"
+fs = ":"
- comment = "#" *(WSP / VCHAR / %x80-FFFFF)
+comment = "#" *(WSP / VCHAR / %x80-FFFFF)
- ack-field = "Acknowledgments" fs SP uri
+ack-field = "Acknowledgments" fs SP uri
- canonical-field = "Canonical" fs SP uri
+canonical-field = "Canonical" fs SP uri
- contact-field = "Contact" fs SP uri
+contact-field = "Contact" fs SP uri
- lang-tag =
+lang-tag =
- uri =
+uri =
- encryption-field = "Encryption" fs SP uri
-Foudil & Shafranovich Expires October 10, 2019 [Page 11]
+Foudil & Shafranovich Expires October 21, 2019 [Page 11]
Internet-Draft A Method for Web Security Policies April 2019
- hiring-field = "Hiring" fs SP uri
+encryption-field = "Encryption" fs SP uri
+
+hiring-field = "Hiring" fs SP uri
- policy-field = "Policy" fs SP uri
+policy-field = "Policy" fs SP uri
- lang-field = "Preferred-Languages" fs SP lang-values
+lang-field = "Preferred-Languages" fs SP lang-values
- lang-values = lang-tag *("," [WSP] lang-tag)
+lang-values = lang-tag *("," [WSP] lang-tag)
- ext-field = field-name fs SP unstructured
+ext-field = field-name fs SP unstructured
- field-name =
+field-name =
- unstructured =
+unstructured =
"ext-field" refers to extension fields, which are discussed in
Section 4.4
@@ -663,17 +665,18 @@ Internet-Draft A Method for Web Security Policies April 2019
If information and resources referenced in a "security.txt" file are
incorrect or not kept up to date, this can result in security reports
- not being received by the organization or sent to incorrect contacts,
- thus exposing possible security issues to third parties.
-Foudil & Shafranovich Expires October 10, 2019 [Page 12]
+Foudil & Shafranovich Expires October 21, 2019 [Page 12]
Internet-Draft A Method for Web Security Policies April 2019
+ not being received by the organization or sent to incorrect contacts,
+ thus exposing possible security issues to third parties.
+
Organizations SHOULD ensure that information in this file and any
referenced resources such as web pages, email addresses and telephone
numbers are kept current, are accessible, controlled by the
@@ -722,10 +725,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-
-
-
-Foudil & Shafranovich Expires October 10, 2019 [Page 13]
+Foudil & Shafranovich Expires October 21, 2019 [Page 13]
Internet-Draft A Method for Web Security Policies April 2019
@@ -781,7 +781,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 14]
+Foudil & Shafranovich Expires October 21, 2019 [Page 14]
Internet-Draft A Method for Web Security Policies April 2019
@@ -837,7 +837,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 15]
+Foudil & Shafranovich Expires October 21, 2019 [Page 15]
Internet-Draft A Method for Web Security Policies April 2019
@@ -893,7 +893,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 16]
+Foudil & Shafranovich Expires October 21, 2019 [Page 16]
Internet-Draft A Method for Web Security Policies April 2019
@@ -949,7 +949,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 17]
+Foudil & Shafranovich Expires October 21, 2019 [Page 17]
Internet-Draft A Method for Web Security Policies April 2019
@@ -1005,7 +1005,7 @@ Internet-Draft A Method for Web Security Policies April 2019
-Foudil & Shafranovich Expires October 10, 2019 [Page 18]
+Foudil & Shafranovich Expires October 21, 2019 [Page 18]
Internet-Draft A Method for Web Security Policies April 2019
@@ -1061,7 +1061,7 @@ Appendix A. Note to Readers
-Foudil & Shafranovich Expires October 10, 2019 [Page 19]
+Foudil & Shafranovich Expires October 21, 2019 [Page 19]
Internet-Draft A Method for Web Security Policies April 2019
@@ -1117,7 +1117,7 @@ B.2. Since draft-foudil-securitytxt-01
-Foudil & Shafranovich Expires October 10, 2019 [Page 20]
+Foudil & Shafranovich Expires October 21, 2019 [Page 20]
Internet-Draft A Method for Web Security Policies April 2019
@@ -1173,7 +1173,7 @@ B.5. Since draft-foudil-securitytxt-04
-Foudil & Shafranovich Expires October 10, 2019 [Page 21]
+Foudil & Shafranovich Expires October 21, 2019 [Page 21]
Internet-Draft A Method for Web Security Policies April 2019
@@ -1201,6 +1201,10 @@ B.6. Since draft-foudil-securitytxt-05
o Expanded security considerations section and fixed typos (#30,
#73, #103, #112)
+B.7. Since draft-foudil-securitytxt-06
+
+ o Fixed ABNF grammar for non-chainable directives (#150)
+
Full list of changes can be viewed via the IETF document tracker:
https://tools.ietf.org/html/draft-foudil-securitytxt
@@ -1225,8 +1229,4 @@ Authors' Addresses
-
-
-
-
-Foudil & Shafranovich Expires October 10, 2019 [Page 22]
+Foudil & Shafranovich Expires October 21, 2019 [Page 22]