oasis-tcs / csaf

OASIS CSAF TC: Supporting version control for Work Product artifacts developed by members of TC, including prose specifications and secondary artifacts like meeting minutes and productivity code
https://github.com/oasis-tcs/csaf
Other
151 stars 40 forks source link

Clarify csaf.data.security.domain.ltd in Requirement 10: DNS path #831

Open sonnyvanlingen opened 4 days ago

sonnyvanlingen commented 4 days ago

Suggestion to improve the usability.

Section 7.1.10 Requirement 10: DNS path documents the following:

The DNS record csaf.data.security.domain.tld SHALL resolve as a web server which serves directly the provider-metadata.json according to requirement 7.

It is not clarified to the reader that domain.tld is simply a placeholder which has to be made specific to the issuing party's own organisation and context.

Options to resolve:

  1. Add a sentence clarifying the situation such as Replace 'domain.tld' with the appropriate domain specific to your organization of use case.

  2. Simply change domain.tld to example.com