Re: Disman WG last call on draft-ietf-disman-remops-mib-v2-02.txt

"Randy Presuhn" <[email protected]>
Newsgroups gmane.ietf.disman
Message-ID <009301c4650c$b7e88b60$7f1afea9@oemcomputer>
Hi -

> From: "Romascanu, Dan (Dan)" <[email protected]>
> To: "Juergen Quittek" <[email protected]>; "Juergen Quittek" <[email protected]>; "Randy Presuhn"
<[email protected]>; <[email protected]>
> Sent: Thursday, July 08, 2004 6:44 AM
> Subject: RE: [Disman] DismanWGlast call ondraft-ietf-disman-remops-mib-v2-02.txt
>

> It looks fine with one observation. The phrase:
>
>  In insecure environments it is RECOMMENDED that the
>    MIBs defined within this memo not be supported.
>
> seems intended to apply only for the ping and traceroute MIB, not for the lookup MIB.

(As technical contributor)
I disagree.  One could use excessive DNS lookups as a form of DoS attack.
Consequently, I think the lookup MIB merits the same level of protection as
the traceroute MIB.

> In any case, this seems redundant with the generic recommendations
> that are part of the security boilerplate which say:
...

I understand the redundancy in the abstract.  However, given these tools'
potential for abuse, I think the redundancy is a good thing, and would
like to see the recommendation retained.

I think it's important that the lookup MIB be given the same level of protection
as ping and traceroute.  I feel much less strongly about whether the redundacy
should be removed.

Randy
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.