Re: configuration: writable MIB modules versus NETCONF/YANG modules
Warren Kumari <[email protected]> Mon, 24 Feb 2014 12:31:44 -0500
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <CAHw9_iJjXVJxJJPFYLau69kTd0LnX-gX=sVbhSX51JvCZxZVaA@mail.gmail.com> |
On Mon, Feb 24, 2014 at 5:02 AM, Mikael Abrahamsson <[email protected]> wrote: > On Fri, 21 Feb 2014, Randy Presuhn wrote: > >> Just to be clear... Are you saying that there are security problems with >> the RFC 3414 or RFC 3415 specifications, problems with the implementations, >> or something else? > > > I am saying that together with blind BCP38-less UDP spoofing, SNMPv1 and v2 > together with how implementations handle views, and the complexity of SNMPv3 > setup in most implementations, I wish for SNMP write to go away. +many lots. > > I'm pretty sure with SNMPv3 only implementations this can be made to be > secure, but I am not aware of anyone actually using SNMPv3 and every time > I've looked into deploying SNMPv3 I shy away after just a short while. Actually, I am -- and it has write enabled too (I'd forgotten it earlier). The IETF meeting network uses SNMPv3, but also has SNMPv2 (because lots of things don't support v3). Write access is enabled -- this is used to poke the access points and ask them to come fetch a new config from TFTP. I think that there is some element of dogfood here... > > And my primary reason for this is people getting their configurations either > stolen (uploaded) or modified by unfortunately misconfiguring or being hit > by a bug that caused the command that was in place to limit the use of SNMP > write, not working properly. > > So while the standard might be fine, in real life it's hard to do. Yes, yes it is.... W > > -- > Mikael Abrahamsson email: [email protected] > > _______________________________________________ > OPS-AREA mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/ops-area