Re: Email Web of Trust - Defining the metrics

Yakov Shafranovich <[email protected]> Thu, 18 Mar 2004 01:04:14 -0500
Newsgroups gmane.ietf.asrg.smtpverify
Organization SolidMatrix Technologies, Inc.
Message-ID <[email protected]>
Alan DeKok wrote:
> Mark Baugher <[email protected]> wrote:
> 
>>    I think we should try to capture the antispam counters as SNMP 
>>Management Information objects (SMIv2), we should define access to these 
>>counters using SNMPv3, and we should consider shortcomings and alternatives 
>>to SMIv2 and to SNMPv3.
> 
>   I agree.  Having a standard for recording such information means
> that it's easier to exchange data, and to talk about that data.
> 
> 
>>For example, can IPsec be used for providing privacy and antidos as
>>well as confidentiality and integrity to SNMP protocol operations?
> 
>   I would start off by defining what data needs to be recorded, and
> worry about publication/exchange of that data later.
> 

I agree also. Same goes for the use of SNMP as an example - this should 
not be limited to just SNMP, rather we are using the existing SNMP 
standard as an example of a possible protocol for this. It may very well 
happen that other protocols will be considered or used. The main point 
is the idea of the counters themselves.

> 
>>   This work should come after a description of one or two applications 
>>that can use the counters such as a trusted reputation service.
> 
>   I would turn that around.  Once you define the foundation of a
> service (what it's measuring), it's possible then, and only then, to
> describe how that services uses that data.
> 

I think either way for the beginning is fine, we can sort out the 
details later.

Yakov