Vienna, 12 May 2000
Karel Vietsch - Draft 1, issued 17 May 2000
1. Welcome and Apologies
The meeting chairman, Brian Gilmore, welcomed the participants and expressed his gratitude to Wilfried Wöber and ACOnet for hosting this meeting and organising logistics in an excellent way.
Apologies had been received from John Dyer (TERENA), Klaus-Peter Kossakowski and Jacques Schuurman (CERT-NL)
2. Round of Introductions
Present:
| Name | Organisation | ||
|
1
|
Jaime Agudo | ESCERT | |
|
2
|
Preben Andersen | DK-CERT | |
|
3
|
Christos Aposkitis | GRNET-CERT | |
|
4
|
Jimmy Arvidsson | Telia CERT | |
|
5
|
Gorazd Bozic | ARNES | |
|
6
|
Roberto Cecchini | GARR-CERT | |
|
7
|
Andrew Cormack | JANET CERT | |
|
8
|
David Crochemore | Le CERT RENATER | |
|
9
|
Pascal Delmoitié | BELNET | |
|
10
|
Michel Dupuy | CERTA | |
|
11
|
Per Arne Enstad | UNINETT CERT | |
|
12
|
Tony Falenius | FUNET CERT | |
|
13
|
Brian Gilmore | TERENA | |
|
14
|
Christoph Graf | SWITCH | |
|
15
|
David Harmelin | DANTE | |
|
16
|
Denise Heagerty | CERN CERT | |
|
17
|
Peter Janitz | DFN-CERT | |
|
18
|
Xander Jansen | CERT-NL | |
|
19
|
Mark Koek | M&I/Stelvio | |
|
20
|
Flemming Laugaard | DK-CERT | |
|
21
|
Jordi Linares | ESCERT | |
|
22
|
Chelo Malagon | RedIRIS | |
|
23
|
Jan Meijer | CERT-NL | |
|
24
|
Francisco Monserrat | RedIRIS | |
|
25
|
Robert Morgan | JANET CERT | |
|
26
|
Claudia Natanson | BT-CERT | |
|
27
|
Gareth Price | BT-CERT | |
|
28
|
Don Stikvoort | M&I/Stelvio | |
|
29
|
Karel Vietsch | TERENA | |
|
30
|
Wilfried Wöber | ACOnet |
3. Minutes of Last Meeting (Amsterdam, 21 January 2000)
The minutes of the previous meeting (revised draft issued 28-1-2000)
were approved without change.
Actions List:
|
|
TERENA | Prepare an implementation plan and timeline and documentation for the TI scheme | done;
see agenda item 4 |
|
|
A. Cormack | Obtain copy of Law Enforcement Agents list of minimum requirements for taking legal action | Andrew Cormack
had circulated EU guidelines; he would continue watching developments;
see also agenda item 9 |
|
|
Cert-coord | Mail information to Y. Demchenko about incident response tools | ongoing;
see agenda item 9 |
|
|
J. Schuurman | Draft 1-page statement of requirements for security entry in RIPE database and mail to RIPE list | done ;
see agenda item 8 |
|
|
TERENA | Open new Incident Classification email distribution list | done |
|
|
TERENA | Draft TF charter, circulate to cert-coord list and submit to TTC once agreed | draft available; to be discussed under agenda item 10 |
|
|
TERENA | Organise next meeting (11-12 May 2000), cert-coord and seminar | done |
4. Status of Trusted Introducer call for proposals
TERENA staff had drafted the documents for the Call for Proposals for the provision of the TI function. The discussion of these documents on the mailing list had led to some small changes, and subsequently the call had been published by TERENA. Before the deadline of 2 May 2000, only one proposal had been received. It is a proposal from M&I/Stelvio. The key persons in this proposal are Klaus-Peter Kossakowski (TI-manager), Don Stikvoort (contract manager and back-up TI-manager) and Mark Koek (technical and information support services). They offer to provide the TI function for the first year for a fixed-price sum of EUR 30,000.
A small committee was appointed from among the participants in the cert-coord meetings to review the proposal. That committee, consisting of Brian Gilmore (chairman), Andrew Cormack, Christoph Graf, Wilfried Wöber and Karel Vietsch (secretary) met on 11 May 2000. They found no surprises in the proposal and recommended accepting it, subject to some administrative details that Karel Vietsch would discuss with the proposers.
The committee had discussed in some detail how the TI provision should be paid for. For the first year this was not a problem because 30 kEUR was a limited amount of money. If needed even TERENA alone could supply this sum, but also there was more than 85 kEUR left-over money from the SIRCE pilot, which after the approval of the original SIRCE Contributors might be used for funding the TI function provision. However it was important to set the funding scheme up in such a way that after an initial subsidy the system would automatically grow to a self-financing state. After comprehensive deliberations the committee proposed the following:
The TI structure also encompasses a board that will oversee the work of the subcontractor. It is envisaged that this board will consist of representatives from level-2 teams. This poses a start-up problem, since at the start of the TI function provision there are no level-2 teams yet. The meeting therefore agreed that the committee that had reviewed the proposal (composition: see above) would continue for the time being, but no longer than for one year, as the interim-board. As soon as more than just a few teams had reached level-2 status, board members would be appointed to take over from the interim-board.
5. Deploying PKI for CSIRTs and web-of-trust (incl. relation to LDAP)
Andrew Cormack and Don Stikvoort together gave a short introduction. PGP works well but only within a relatively small community; it is also mostly used for e-mail only. X.509 is widely supported but it has in practice a limited set of applications. How could X.509 be used in the context of the cert-coord group? Using it for e-mail would be a bridge too far for most participants. One useful suggestion would be to have a server certificate for the TI Web site. (A simple common password to the confidential information would not be an adequate solution, also because it is foreseen that teams might lose their level-2 status.) A third idea was to have a client certificate for TI use, but that seemed still difficult and should therefore not be tried now.
After a lively discussion the meeting concluded the following:
Don Stikvoort gave a short presentation. Since 1 April 2000, M&I/Stelvio have been contracted to provide the FIRST secretariat. FIRST has now established a funding model with funds coming in through membership fees. The annual membership fee is USD 550, and there are currently about 100 FIRST members. The main functions of the FIRST secretariat are: accounting, facilitating meetings, action item maintenance, co-ordinating membership applications, keeping the FIRST Web site up-to-date, PGP key distribution, the mail address FIRST-SEC@FIRST.ORG, committee support.
As to the relations between FIRST and the cert-coord group, the conclusion from the meeting was that time was not yet ripe to institutionalise those. The cert-coord has another remit than FIRST, among others by its geographical scope and its activities, but also by being open to teams that are not FIRST members.
The meeting concluded as follows:
The seminar sessions on the day before this meeting had been very worthwhile. Thanks were expressed to the presenters. It was felt that the format of 2-day meetings, the first day for seminar sessions and the second day for a meeting in the strict sense, was a good one. Also the joint dinner on the evening of the first day is an important element of the format, because it provides an excellent opportunity for informal discussions.
In the first seminar session, JANET CERT, CERT-NL and Telia CERT had presented their practice, organisation, structure, working methods. Conclusions from the meeting were:
Wilfried Wöber introduced the subject. In an analysis that had been performed of the value of the RIPE database for the community, also information about security contacts had been discussed. The RIPE database now has links to administrative and technical contacts at Local Internet Registries, and that could be extended with a pointer to a security contact. The initial thrust had been to attach that to different types in the RIPE database. Jacques Schuurman had drafted a proposal, which had been circulated only informally. The proposal would be on the agenda of the meeting of the RIPE database working group next week, but again it would probably be discussed there only informally. Probably the first implementation should be restricted to adding a pointer to the IP address object (and potentially the AS number object). A small subgroup of cert-coord, consisting of Jacques Schuurman, Wilfried Wöber, Jan Meijer and Denise Heagerty would continue to work on this. Thanks were due to Jacques Schuurman for the work he had done.
It was noted that a regular review process would be needed to ensure that the information is there and is up-to-date.
The further time schedule was as follows:
9a. Clearing House for Incident Handling Tools
A simple Web-based reference to incident handling tools had been set up at the TERENA Web site. Questions were if this was felt to be useful and if it could be extended with references to more tools and also with reviews explaining the value (or lack thereof) of specific tools.
A lively discussion produced the following conclusions and suggestions:
As mentioned under agenda item 3, Andrew Cormack had volunteered to continue watching developments. He called on the others to inform him about interesting developments or legal changes in their countries. Andrew Cormack would then make such information available to the entire group.
9c. Encouraging new CSIRTs
It had been agreed that it would be one of the tasks of cert-coord to encourage the establishment and development of new teams. It was not clear yet how this could be approached best.
Some actions were agreed as follows:
9d. Training workshops for new (staff of) CSIRTs
It had been agreed that under the auspices of cert-coord, training workshops would be organised for new (staff of) CSIRTs. It was felt that one or two such workshops should be organised in the next two years. One opportunity would be to organise such a workshop adjacent to next year's FIRST conference, which would take place in Toulouse in June 2001 (David Crochemore is on the programme committee). However there might also be disadvantages in the combination of the two events.
Whether existing CSIRTs would be interested to send their new staff to such a workshop appeared to depend very much on the content and form of the workshop. For example, a workshop should have a clear added value compared to studying information from the available literature.
It was concluded that the requirements for the programme of the training workshop needed further clarification. A separate agenda item should be devoted to those requirements in the next meeting.
10. Establishing a TERENA Task Force
It had been agreed that the cert-coord group would continue as a TERENA task force. This required the adoption of Terms of Reference, which were useful to obtain a common understanding of the groups objectives and working methods and to introduce some planning in the form of deliverables and milestones.
The TERENA secretariat had provided a first draft of the Terms of Reference, which was discussed by the meeting. Specific remarks were:
By acclamation, Gorazd Bozic was elected chair of the task force.
11. Date of next meeting
Offers to host the next meeting had been made by RENATER (in Paris), ARNES (in Ljubljana) and ESCERT (in Barcelona). It was decided to have the next meeting in Paris and take up the other offers at a later date. Because of the success of the formula of this meeting and the number of suggestions for seminar topics, the next meeting will again be a 2-day event, with seminar sessions on the first day.
The next meeting will take place in Paris on Thursday and Friday 28-29 September 2000.
12. Any other business
The meeting expressed its thanks to Wilfried Wöber for the excellent organisation of the meeting facilities and the meals.
The meeting expressed its thanks to Brian Gilmore for his chairmanship of the past three meetings, which had been instrumental in getting an important new structured activity off the ground.
SUMMARY OF ACTIONS
|
|
Karel Vietsch | Finalise negotiations with M&I/Stelvio on TI contract and have contract signed |
|
|
TI | Produce document(s) to explain benefits of TI to managers |
|
|
TERENA and TI | Discuss and arrange server certificate for TI Web site |
|
|
Secretariat | Arrange seminar session about experiences of CSIRTs with PKI, adjacent to next TF-CSIRT meeting |
|
|
Secretariat | Arrange separate agenda item for update on FIRST at all future TF-CSIRT meetings |
|
|
Secretariat | Arrange seminar session about current practice of CSIRTs, adjacent to next TF-CSIRT meeting. Via discussion on the e-mail list obtain list of topics that speakers should address |
|
|
Taxonomy subgroup | Present work on taxonomy at FIRST conference in Chicago in June 2000 |
|
|
Wilfried Wöber and others | Prepare decision at September 2000 RIPE meeting about security contact entry in RIPE database |
|
|
Secretariat | Arrange seminar session about experiences with specific incident handling tools, adjacent to a future TF-CSIRT meeting |
|
|
TI | Give a presentation at a future RIPE meeting |
|
|
Secretariat | Arrange separate agenda item at the next TF-CSIRT meeting about requirements for the programme of training workshops |
|
|
Karel Vietsch | Revise draft Terms of Reference of TF-CSIRT and send it to mailing list for further discussion |
|
|
David Crochemore and Secretariat | Organise next TF-CSIRT meeting in Paris on 28-29 September 2000 |