FW: RSTP-MIB coments

"David B Harrington" <[email protected]> Thu, 31 Mar 2005 12:28:21 -0500
Newsgroups gmane.ietf.bridge
Message-ID <[email protected]>
 
Hi,

The security considerations section of the RSTP-MIB needs details.
Please review this proposed text to make sure these statements look to
be true.

> The text in dot1dStpVersion will need to change since there 
> are two 802.1D specs.
> <suggested text>
>         "The version of Spanning Tree Protocol the bridge is
>          currently running.  The value 'stpCompatible(0)'
>          indicates the Spanning Tree Protocol specified in
>          IEEE 802.1D-1998 and 'rstp(2)' indicates the Rapid Spanning
>          Tree Protocol specified in IEEE 802.1w and clause 17 of 
>          802.1D-2004.  New values may be defined as future versions 
>          of the protocol become available."
> </suggested text>
> 
> Security Considerations:
> <suggested text>
> A number of writable objects could be misused to cause 
> network delays and spanning tree instabilities, including 
> dot1dStpVersion, dot1dStpTxHoldCount, 
> dot1dStpPortProtocolMigration, dot1dStpPortAdminEdgePort, and 
> dot1dStpPortAdminPathCost. 
> 
> dot1dStpVersion could be read by an attacker to identify 
> environments containing applications or protocols which are 
> potentially sensitive to RSTP mode.
> 
> dot1dStpPortAdminPointToPoint could be used to mislead an 
> access control protocol, such as 802.1X, to believe that only 
> one other system is attached to the LAN segment and to enable 
> network access based on that assumption. This situation could 
> permit potential man-in-the-middle attacks.
> 
> </suggested text>


David Harrington
[email protected]