Re: configuration: writable MIB modules versus NETCONF/YANG modules

Mikael Abrahamsson <[email protected]> Mon, 24 Feb 2014 11:02:38 +0100 (CET)
Newsgroups gmane.ietf.ops
Organization People's Front Against WWW
Message-ID <[email protected]>
On Fri, 21 Feb 2014, Randy Presuhn wrote:

> Just to be clear...  Are you saying that there are security problems 
> with the RFC 3414 or RFC 3415 specifications, problems with the 
> implementations, or something else?

I am saying that together with blind BCP38-less UDP spoofing, SNMPv1 and 
v2 together with how implementations handle views, and the complexity of 
SNMPv3 setup in most implementations, I wish for SNMP write to go away.

I'm pretty sure with SNMPv3 only implementations this can be made to be 
secure, but I am not aware of anyone actually using SNMPv3 and every time 
I've looked into deploying SNMPv3 I shy away after just a short while.

And my primary reason for this is people getting their configurations 
either stolen (uploaded) or modified by unfortunately misconfiguring or 
being hit by a bug that caused the command that was in place to limit the 
use of SNMP write, not working properly.

So while the standard might be fine, in real life it's hard to do.

-- 
Mikael Abrahamsson    email: [email protected]