Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add draft RFC for establishing CFF as a CVE Numbering Authority #762

Open
wants to merge 2 commits into
base: main
Choose a base branch
from

Conversation

paulcwarren
Copy link
Member

@paulcwarren paulcwarren commented Jan 25, 2024

@beyhan beyhan added the toc label Jan 26, 2024
@beyhan beyhan requested review from a team, rkoster, beyhan, stephanme, ameowlia and ChrisMcGowan and removed request for a team January 26, 2024 08:14
@ameowlia
Copy link
Member

ameowlia commented Feb 6, 2024

@paulcwarren - Can you add a bit more details around implementation? How are you going to do this? What is the expected timeline?

@paulcwarren
Copy link
Member Author

paulcwarren commented Feb 6, 2024

It's a whole thing from what I can tell. The steps as far as I can tell are:

Eligibility assessment
Application
Evaluation
Training,
Signing the MOU.

At which point we could start issuing CVEs.

The interesting thing is that I am pretty sure that we used to be an authority, or we already are one (and we just flipped to using VMWare for a while, unclear to me why), and the Linux Foundation is obviously already is an authority so it's possible it might not be a big deal.

As for timing, I cant make any determination there. I think we would just need to get started.

@beyhan beyhan added the rfc CFF community RFC label Feb 7, 2024
@christopherclark
Copy link
Member

@paulcwarren I don't have context into whether the CFF was a CNA in the past, but if it was that would have been when it was a separate legal entity from the LF. So that's likely moot at this point. The LF in not a CNA, however some LF projects are, i.e. https://www.cve.org/PartnerInformation/ListofPartners/partner/zephyr

So, this is definitely possible, I just need to dig into this a bit more. OpenSSF recently published a blog post on this topic: https://openssf.org/blog/2023/11/27/openssf-introduces-guide-to-becoming-a-cve-numbering-authority-as-an-open-source-project/

I'll reach out soon.

@paulcwarren
Copy link
Member Author

@christopherclark any thoughts on how to progress this. I have not heard back from MITRE at all. I can ping them again, or jsut start applying to become a CNA. WDYT?

@christopherclark
Copy link
Member

@paulcwarren Sure, let's go ahead and apply. I'll be around Mon-Wed next week, happy to assist as needed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
rfc CFF community RFC toc
Projects
Status: Blocked
Development

Successfully merging this pull request may close these issues.

4 participants