Sorry to be a latecomer to this group, missed SANS, releases will play
hell with a schedule.  I have been doing a very quick review of all
the info from MITRE that Steve has so graciously forwarded as well as
this summary.
I lean toward Russ's view on the scheme.  I would like to be able to
reference the CVE number in our vulnerability description but it needs
to be fairly stable.  Frequent changes require maintenance and
maintenance requires time and time....you know...
A candidate number would be important for initial reference and
tracking purposes and changing it to an actual CVE number wouldn't
require much to update.
I feel the issue of the candidate number becoming the defacto "common"
name can be overcome when the "official" CVE number is assigned.  At
least there will be a tracking mechanism in place to relate the final
CVE to the initial Candidate number.

Also, the shorter the number the better for common usage and
reference.  A long convoluted numbering scheme becomes unwieldy and
may die off on its own.  As long as it is a unique, easily referenced
number it doesn't have to be fancy, just workable.
Still catching up so look forward to more discussions

I made up a summary of the candidate numbering scheme discussion and
included it below.  Any errors are mine.  It seems to me that the
"right answer" isn't too far away.  In the next day or two, Dave and I
will probably propose something based on the discussions so far.  As
an indicator of what our proposal might look like - if you had any big
disagreements with Russ' last email, better speak up now ;-)

Candidate Numbering Schemes/Etc.
