Re: configuration: writable MIB modules versus NETCONF/YANG modules
Mikael Abrahamsson <[email protected]> Mon, 24 Feb 2014 11:02:38 +0100 (CET)
| Newsgroups | gmane.ietf.ops |
|---|---|
| Organization | People's Front Against WWW |
| Message-ID | <[email protected]> |
On Fri, 21 Feb 2014, Randy Presuhn wrote: > Just to be clear... Are you saying that there are security problems > with the RFC 3414 or RFC 3415 specifications, problems with the > implementations, or something else? I am saying that together with blind BCP38-less UDP spoofing, SNMPv1 and v2 together with how implementations handle views, and the complexity of SNMPv3 setup in most implementations, I wish for SNMP write to go away. I'm pretty sure with SNMPv3 only implementations this can be made to be secure, but I am not aware of anyone actually using SNMPv3 and every time I've looked into deploying SNMPv3 I shy away after just a short while. And my primary reason for this is people getting their configurations either stolen (uploaded) or modified by unfortunately misconfiguring or being hit by a bug that caused the command that was in place to limit the use of SNMP write, not working properly. So while the standard might be fine, in real life it's hard to do. -- Mikael Abrahamsson email: [email protected]