Re: Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt
Juergen Quittek <[email protected]>
| Newsgroups | gmane.ietf.disman |
|---|---|
| Message-ID | <2147483647.1088776734@[10.1.1.171]> |
Randy, Sorry, my last email slipped out of my mail editor while I was typing with a wrong keyboard driver. --On 01.07.2004 11:59 h -0700 Randy Presuhn wrote: > Hi - > >> From: "Romascanu, Dan (Dan)" <[email protected]> >> To: "Randy Presuhn" <[email protected]>; <[email protected]> >> Cc: <[email protected]> >> Sent: Thursday, July 01, 2004 8:41 AM >> Subject: RE: [Disman] Disman WG last call ondraft-ietf-disman-remops-mib-v2-02.txt >> > >> I have some concerns with respect to the Security Considerations section. >> It is not aligned with the latest guidelines (http://www.ops.ietf.org/mib-security.html), >> probably reflecting the style or the guidelines that were in place by the time >> RFC 2925 was published. > > (As WG chair) Clearly, this must be fixed before we ask our AD to take > it to the IESG. > > Juergen Q.: could you re-spin this before the i-d cutoff? Yes. I am currently working on the issues raised by Eduardo. Fixing the security consideration should not be a big problem. >> However, I miss the clarity of the current text, and >> especially the enumeration of the security sensitive objects in the MIB modules, >> the explicit description of the risks associated with their mis-configuration or >> disclosure, and the explicit recommendation to deploy SNMPv3 and to enable >> cryptographic security. > ... > > (As technical contributor) I rather like the current text. I'd like to see it retained > (except perhaps the first paragraph, which would become redundant) and > merged with the additional text required by the boilerplate. I will try to satisfy both sides: including the new boilerplate text and listing vulnerable objects as well as keeping all but the first paragraphs of the current version. Thanks, Juergen > Randy > > >