The IETF Administration LLC (IETF LLC) is soliciting proposals ("Proposals")
for the
Security Review and Remediation of the RFC Production Center Web Accessible
Code RFP. The RFP is located at: https://ietf.org/about/administration/rfps/
Please note the following:
Timeline:
27 Sep: RFP Issued
04 Oct: Questions and Inquiries deadline
07 Oct: Answers to questions issued, RFP Addenda and Update issued
14 Oct: Proposals due
21 Oct: Selection made, negotiations begin
01 Nov: Contract execution
08 Nov: Work begins
Overview
The RFC Production Center (RPC) currently maintains a private CVS repository
that
houses the code for the RFC Editor website and the public web services provided
there, as well as staff-only web services, command line tools, and utilities
used
by the RPC. There is an effort to move this repository to one that is open to
the
public to bring the resources of the Tools Team and volunteer developers to bear
on evolving the codebase. An important first step in this move is inspecting the
code for the web services to ensure the released code does not advertise any
obvious security vulnerabilities, such as SQL insertion attacks against the
underlying databases.
It is not known if there are any such vulnerabilities in the current codebase.
However, it is known that the source contains at least one embedded password
used for communicating with the datatracker. One possible output of this
project
is a report that the codebase is ready to move into the open with only simple
modifications to address embedded passwords.
Please reply with questions, if any, and a bid if you are interested in
pursuing this
opportunity to [email protected].
Thanks in advance.
Portia Wenze-Danley
IETF LLC Interim Executive Director
_______________________________________________
IETF-Announce mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/ietf-announce