Re: Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt
"Randy Presuhn" <[email protected]>
| Newsgroups | gmane.ietf.disman |
|---|---|
| Message-ID | <004801c45f9d$9843c960$7f1afea9@oemcomputer> |
Hi - > From: "Romascanu, Dan (Dan)" <[email protected]> > To: "Randy Presuhn" <[email protected]>; <[email protected]> > Cc: <[email protected]> > Sent: Thursday, July 01, 2004 8:41 AM > Subject: RE: [Disman] Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt > > I have some concerns with respect to the Security Considerations section. > It is not aligned with the latest guidelines (http://www.ops.ietf.org/mib-security.html), > probably reflecting the style or the guidelines that were in place by the time > RFC 2925 was published. (As WG chair) Clearly, this must be fixed before we ask our AD to take it to the IESG. Juergen Q.: could you re-spin this before the i-d cutoff? > However, I miss the clarity of the current text, and > especially the enumeration of the security sensitive objects in the MIB modules, > the explicit description of the risks associated with their mis-configuration or > disclosure, and the explicit recommendation to deploy SNMPv3 and to enable > cryptographic security. ... (As technical contributor) I rather like the current text. I'd like to see it retained (except perhaps the first paragraph, which would become redundant) and merged with the additional text required by the boilerplate. Randy