Re: AD Evaluation: draft-ietf-dmm-requirements
"Dapeng Liu" <[email protected]>
| Newsgroups | gmane.ietf.nemo |
|---|---|
| Message-ID | <003c01cf1e88$654c79d0$2fe56d70$__31937.9461383962$1391182426$gmane$org@com> |
-----Original Message----- From: Brian Haberman [mailto:[email protected]] Sent: Wednesday, January 29, 2014 9:57 PM To: h chan; [email protected]; [email protected]; Peter McCann Subject: Re: [DMM] AD Evaluation: draft-ietf-dmm-requirements On 1/28/14 3:31 PM, h chan wrote: > REQ6: Security considerations > > > > A DMM solution MUST NOT introduce new security risks or > > amplify existing security risks against which the existing > > security mechanisms/protocols cannot offer sufficient > > protection. > > > > The intention of REQ6 is NOT that it cannot introduce new vulnerabilities at all. > > Rather the protection against such new vulnerablities can be limited to the use of existing security protocols. It is okay to provide additional means to protect against new risks as long as they do not require development of new security protocols which are needed for DMM alone but are not needed otherwise. Else a network deploying DMM versus a network not deploying DMM will need additional security protocols which are not needed otherwise. > > > > So I think the word: "existing" security mechanisms/protocols is intended to exclude protocols that are not needed otherwise. > > > > We can clarify with the following: > > > > REQ6: Security considerations > > > > A DMM solution MUST NOT introduce new security risks or > > amplify existing security risks against which security means > using existing > > security mechanisms/protocols CANNOT offer sufficient > > protection. > The above seems a little clunky. Does this work for everyone? A DMM solution MUST NOT introduce new security risks, or amplify existing security risks, that cannot be mitigated by existing security mechanisms or protocols. Works for me. Dapeng Regards, Brian