-
Notifications
You must be signed in to change notification settings - Fork 17
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
New importer: ncsc.nl CSAF #94
Comments
@jonite the source doesn't seem to work with the default downloader, could you have a look at it? As it is seems to be the same issue as the Microsoft one, I'm stating to suspect there is a tool used to generate CSAF repos that isn't following the specs somewhere. Logfile: downloader.log |
Looking at your
is different from Microsoft, this time you have invented an eighteenth month. ;) The |
LOL, ok, right, I didn't look particularly close. That is an interesting way to generate an isoformat indeed. |
Hi, A watcher of this project dropped me a mail. Jacco |
Thanks!
I get a bunch of files where the signature cannot be verified:
@jaccoNCSCNL can you have a look? |
That is strange, there are quite some tests involved in making sure the signing is correct. As it turns out there is an encoding issue 'somewhere' that breaks the signing. Not yet sure where. In the original signed text there is often a word with an |
Ahh, the fun with encoding... :( Good luck and thank you! |
Took longer than expected, but it should be fixed for the future and the old data is also corrected. |
thanks! I'll setup the importer tomorrow. |
@Rafiot is it working now? |
@jaccoNCSCNL yep, all good, thanks! Adding the source now. |
Thanks for looking into it, the advisory feed is probably a better option then:
https://advisories.ncsc.nl/csaf/
After publication of CSAF 2.1 advisories are created also in that standard. Further, new features will be added in the 2.1 version, likely including also a new score. As part of the change it is also planned to change the assessment method for advisories from probability/severity to urgency with three proposed levels.
Originally posted by @jonite in #84 (comment)
The text was updated successfully, but these errors were encountered: