< Return to Ballot details

Vote Details

Ballot: Approval of WD02 of the OpenC2 Over HTTPS Specification as a Committee Specification Draft
Company:
sFractal Consulting LLC
Vote:
Yes
Comment:
3.2.3 - I believe mutual authentication is required not optional. I opened https://github.com/oasis-tcs/openc2-impl-https/issues/5 to further document my concern.

3.2.3 - I believe we are being over prescriptive in defining how authentication is implemented. I opened https://github.com/oasis-tcs/openc2-impl-https/issues/6 to further document my concern

4. - I believe the OpenC2 command content should not be dependent on the http header information. I opened https://github.com/oasis-tcs/openc2-impl-https/issues/7 to further document my concern