Re: Disman WG last call on draft-ietf-disman-remops-mib-v2-02.txt
"Randy Presuhn" <[email protected]>
| Newsgroups | gmane.ietf.disman |
|---|---|
| Message-ID | <009301c4650c$b7e88b60$7f1afea9@oemcomputer> |
Hi - > From: "Romascanu, Dan (Dan)" <[email protected]> > To: "Juergen Quittek" <[email protected]>; "Juergen Quittek" <[email protected]>; "Randy Presuhn" <[email protected]>; <[email protected]> > Sent: Thursday, July 08, 2004 6:44 AM > Subject: RE: [Disman] DismanWGlast call ondraft-ietf-disman-remops-mib-v2-02.txt > > It looks fine with one observation. The phrase: > > In insecure environments it is RECOMMENDED that the > MIBs defined within this memo not be supported. > > seems intended to apply only for the ping and traceroute MIB, not for the lookup MIB. (As technical contributor) I disagree. One could use excessive DNS lookups as a form of DoS attack. Consequently, I think the lookup MIB merits the same level of protection as the traceroute MIB. > In any case, this seems redundant with the generic recommendations > that are part of the security boilerplate which say: ... I understand the redundancy in the abstract. However, given these tools' potential for abuse, I think the redundancy is a good thing, and would like to see the recommendation retained. I think it's important that the lookup MIB be given the same level of protection as ping and traceroute. I feel much less strongly about whether the redundacy should be removed. Randy