FW: [psg.com #76] AutoReply: Security Considerations
"Sharon Chisholm" <[email protected]>
| Newsgroups | gmane.ietf.entmib |
|---|---|
| Message-ID | <[email protected]> |
Hi Proposed Resolution ent-state-76: Add the following to the Security Considerations section: "Note that setting the entStateAdmin to disabled can cause disruption of services ranging from those running on a port or an entire device, depending on the type of entity. Access to this object should be properly protected. Access to the objects defined in this MIB allows one to figure out what the active and standby resources in a network are. This information can be used to optimize attacks on networks so even read-only access to this MIB should be properly protected." Sharon -----Original Message----- From: entity-state [mailto:[email protected]] Sent: Tuesday, July 15, 2003 4:21 AM To: Chisholm, Sharon [CAR:0S00:EXCH] Subject: [psg.com #76] AutoReply: Security Considerations <clip> ------------------------------------------------------------------------- Romascanu, Dan (Dan) [[email protected]] "The Security Considerations section should clearly articulate the operational risks of writing on entStateAdmin." Juergen Schoenwaelder [[email protected]] 'm) In the security section, you may want to explain that access to the objects defined in this MIB allows to figure out what the active and standby resources in a network are and that this information can be used to optimize attacks on networks. So even read-only access to this MIB should be properly protected.'