Microsoft Security Development Lifecycle (SDL)
A forum for discussing the Microsoft SDL Process and guidance.
Announcements
Workaround for MSF-Agile+SDL v5.0 install error
SDL Team Friday, June 24, 2011 7:05 PMAnnouncement originially posted Tuesday, August 03, 2010 9:59 PM
Hi everyone,
We've talked with some people experiencing problems when trying to install the MSF-Agile+SDL v5.0 process template. We believe these problems are a result of an incompatibility with certain configurations of Sharepoint, and we are working to correct the issue for the next release of the MSF-Agile+SDL template. In the meantime, you should be able to work around the problem by following these instructions to disable the Sharepoint features of the template:
- Uninstall the template if you've already installed it.
- Reinstall the template files, and uncheck the Additional Sharepoint Components feature during the installation process.
- Using your XML editor of choice, open the file <template install dir>\Process Template\Windows SharePoint Services\wsstasks.xml.
- Near the bottom of the file, you will see the lines:
<!--TfsDashboardSDLAgile -->
<feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" />
5. Comment out the second line, ie:
<!--TfsDashboardSDLAgile -->
<!-- <feature featureId="3F6F501A-5DFF-4359-8ED8-232784DFF47E" /> -->
6. Save the file and close
7. Open the Process Template Manager in Visual Studio
8. Delete the existing "MSF for Agile Software Development plus Security Development Lifecycle (SDL) v5.0" process template.
9. Upload the process template again, browse for <template install dir>\Process Template\process template.xml.
10. Close the Process Template Manager.
You should now be able to create MSF-A+SDL projects. If you're experiencing the install bug, please let us know if this helps workaround the problem (or if it doesn't).
Thanks,
Bryan
Announcing the templates for SDL Practices
SDL Team Friday, April 29, 2011 5:46 PMDownload the templates for SDL practices, a library of templates to help you get started with the more thought-based SDL practices or activities: Defining Security Requirements, Creating a Security Bug Bar, Performing a Security Risk Assessment, Conducting a basic threat model, Managing SDL Exception Requests, Performing a Final Security Review.
Tools updates: SDL Threat Modeling Tool, MiniFuzz File Fuzzer, SDL Regex Fuzzer
SDL Team Friday, September 16, 2011 10:37 PMThe SDL team has recently announced updated versions of three SDL tools:
SDL Threat Modeling Tool v3.1.8
Check them out and feel free to provide comments and feedback.
Follow @MSFTsdl on Twitter
SDL Team Friday, June 24, 2011 7:12 PMFollow @MSFTsdl on Twitter to stay informed about the latest news, events and releases of the Microsoft Security Development Lifecycle.
Filtering and SortingUse these options to narrow down the question and discussion list.
- 024

Get property in JavaBeans in Java
rafatjahagirdar 19 hours 30 minutes ago - 017

Get property in JavaBeans in JAva
rafatjahagirdar 19 hours 30 minutes ago - 017

Get property in JavaBeans
rafatjahagirdar 19 hours 30 minutes ago - 025

Run WIF without LoadUserProfile = True is throwing null error
Zafar.Yousafi Tuesday, May 22, 2012 6:40 AM - 053

SDL tool error: Object reference not set to an instance of an object.
helina cc Monday, May 21, 2012 7:36 AM - 1425

sha-256 multiple updates
jsvanderkin Tuesday, May 08, 2012 3:26 PM - 1221

SDL Threat modeling tool says "Visio is not installed" when start up (Both Visio Premium 2010 and Prof 2007 installed)
vinguyen Monday, May 14, 2012 5:54 PM - 2782

Remove McAfee antivirus completely
Brian456 Friday, April 20, 2012 9:57 PM - 5380

SDL Threat Modelling Tool installation issues
cboers Tuesday, April 24, 2012 11:42 AM - 1350

FIM 2010 R2 licensing
Sathiyanarayanan Gopal Friday, April 20, 2012 10:53 AM - 6537

ClaimsAuthenticationManager
MSDev23 Saturday, April 14, 2012 3:13 PM - 31648

SDL Reports
Yuzarsiv Sunday, January 15, 2012 8:29 AM - 2942

GSFunctionOptimizeCheck BinScope
Siddireddy Lakshman Wednesday, March 21, 2012 10:38 AM - 1734

Why does IIS use the IUSR_Machine account to load aspnet_isapi.dll when it should use application pool account?
stryker77 Wednesday, March 14, 2012 8:57 PM - 2793

Windows 8 Consumer Preview Windows Defender Stopped Working
splunkett1 Saturday, March 10, 2012 8:00 PM - 21198

Denial Of Service threats for External Interactors
loosiGoosi Tuesday, February 07, 2012 8:48 PM - 21260

Problem installing MSF SDL Process Template v5.0 after environment upgrade
MrWeiland Sunday, January 29, 2012 9:58 AM - 11452

HTTP Auth_User
bca2012 Monday, January 16, 2012 7:11 PM - 11263

Get started with SDL
Pure Deal Tuesday, January 24, 2012 11:49 AM - 11336

Using SDL Tools for .NET applications hosted in Linux
CrushedOnion Monday, January 23, 2012 7:49 AM

