You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The roles, responsibilities and processes are explained in different repos and it is fragmented and not updated. The following dialog took place via email and needs to be clarified, captured and enhanced in the Wiki (this repo)
In the authorization chaincode there is only a single role, the Authorizing Official, who is responsible for uploading ATO attestations. The system owner is an off chain user who works with the AO to create the ATO attestation, then the AO reports it to the blockchain. In the asset chaincode there is a System Owner role but only for GSA as they own the licenses and make them available. The customer agencies do not have this on-chain role. I could rename the System Owner role to License Owner or something similar to avoid confusion. Would that help? It will be easier to modify the asset chaincode since the authorization chaincode is already deployed.
The roles, responsibilities and processes are explained in different repos and it is fragmented and not updated. The following dialog took place via email and needs to be clarified, captured and enhanced in the Wiki (this repo)
In the authorization chaincode there is only a single role, the Authorizing Official, who is responsible for uploading ATO attestations. The system owner is an off chain user who works with the AO to create the ATO attestation, then the AO reports it to the blockchain. In the asset chaincode there is a System Owner role but only for GSA as they own the licenses and make them available. The customer agencies do not have this on-chain role. I could rename the System Owner role to License Owner or something similar to avoid confusion. Would that help? It will be easier to modify the asset chaincode since the authorization chaincode is already deployed.
Places where pieces of documentation exists and need aggregation and correct ions:
https://github.com/usnistgov/blossom-oscal/blob/feature-ato-process/docs/asset/README.md
https://github.com/usnistgov/blossom-nist-member/wiki/BloSS@M--%E2%80%90-Authorization-Chaincode-Functions
https://hackmd.io/YGI5dYvcTealhNFT2jSzQQ
https://github.com/usnistgov/blossom-nist-member/wiki/BloSS@M-ATO-Process
The text was updated successfully, but these errors were encountered: