Re: Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt

Juergen Quittek <[email protected]>
Newsgroups gmane.ietf.disman
Message-ID <2147483647.1088762586@[10.1.1.171]>
Rand

--On 01.07.2004 11:59 Uhr -0700 Randy Presuhn wrote:

> Hi -
>
>> From: "Romascanu, Dan (Dan)" <[email protected]>
>> To: "Randy Presuhn" <[email protected]>; <[email protected]>
>> Cc: <[email protected]>
>> Sent: Thursday, July 01, 2004 8:41 AM
>> Subject: RE: [Disman] Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt
>>
>
>> I have some concerns with respect to the Security Considerations section.
>> It is not aligned with the latest guidelines (http://www.ops.ietf.org/mib-security.html),
>> probably reflecting the style or the guidelines that were in place by the time
>> RFC 2925 was published.
>
> (As WG chair) Clearly, this must be fixed before we ask our AD to take
> it to the IESG.
>
> Juergen Q.: could you re-spin this before the i-d cutoff?
>
>> However, I miss the clarity of the current text, and
>> especially the enumeration of the security sensitive objects in the MIB modules,
>> the explicit description of the risks associated with their mis-configuration or
>> disclosure, and the explicit recommendation to deploy SNMPv3 and to enable
>> cryptographic security.
> ...
>
> (As technical contributor) I rather like the current text.  I'd like to see it retained
> (except perhaps the first paragraph, which would become redundant) and
> merged with the additional text required by the boilerplate.

I will try to satisfy both sides: including the new boilerplate text and listing
vulnerable objects as well as keeping all but the first paragraphs of the current
version.

    Juergen

> Randy
>
>
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.