Re: AD Evaluation: draft-ietf-dmm-requirements
Brian Haberman <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <52E90898.6050604__3420.45681686631$1391003810$gmane$org@innovationslab.net> |
On 1/28/14 3:31 PM, h chan wrote: > REQ6: Security considerations > > > > A DMM solution MUST NOT introduce new security risks or > > amplify existing security risks against which the existing > > security mechanisms/protocols cannot offer sufficient > > protection. > > > > The intention of REQ6 is NOT that it cannot introduce new vulnerabilities at all. > > Rather the protection against such new vulnerablities can be limited to the use of existing security protocols. It is okay to provide additional means to protect against new risks as long as they do not require development of new security protocols which are needed for DMM alone but are not needed otherwise. Else a network deploying DMM versus a network not deploying DMM will need additional security protocols which are not needed otherwise. > > > > So I think the word: "existing" security mechanisms/protocols is intended to exclude protocols that are not needed otherwise. > > > > We can clarify with the following: > > > > REQ6: Security considerations > > > > A DMM solution MUST NOT introduce new security risks or > > amplify existing security risks against which security means using existing > > security mechanisms/protocols CANNOT offer sufficient > > protection. > The above seems a little clunky. Does this work for everyone? A DMM solution MUST NOT introduce new security risks, or amplify existing security risks, that cannot be mitigated by existing security mechanisms or protocols. Regards, Brian _______________________________________________ dmm mailing list [email protected] https://www.ietf.org/mailman/listinfo/dmm
signature.asc
(application/pgp-signature, 536 B)
-----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.20 (Darwin) Comment: GPGTools - https://gpgtools.org iQEcBAEBCgAGBQJS6QieAAoJEBOZRqCi7goqRTcIAM++uC5/qS8Pe+ykrn3bVKcx tmAtGzmPx9oanQJmkXp5HY4SllWHfHkM59GOTSVlmYgNwp99Rxo39yOQfVWDxL1T 4CIOGWX3R3C2pk3Tkm8w4mqegHeqG50ByZ1xlPNGghQ6mm0w4rGwi7i/6GD079Ua ++jXChoncQgGmATldmhTuNc27oR/VXmFMVhOCeRXz8dZrTIxjo+WUwR2dxfKToiI 7oB0pca1MjtKMvtW2oF4+HG3Olxm4sU4iEYTK+4cD9IuYKOxnJ9EJB2e2UkP0bi1 wEQgdJ6sA86xGW0NchlGSCQzX4Dp56RRhj7EjNU00nhNFpb7BgMwfOIvm8R+uR4= =IjcJ -----END PGP SIGNATURE-----