Issue 1: should we have a security boilerplate for management protocols and data models?

"David Harrington" <[email protected]>
Newsgroups gmane.ietf.ops
Message-ID <[email protected]>
Hi,

I plan to propose some replacement text for the current boilerplate
for secure management protocols, and for the sensitivity of data model
objects.

I think the debate aboiut whether we should have boilerplate is a
different issue than what the replacement text should be, so this
thread is for tha debate about whether a boilerplate is desirable.

Please keep the threads separate.

now, my opinion on whether to have boilerplate:

I have seen editors try to write their own recommendations for
securing management using SNMPv3 or other secure protocol, and they
typically get the text way wrong. I think it is important for us to
provide accurate text for them to use. 

I personally find the existing MIB object sensitivity boilerplate
longer than I like, and I think we should consider whether it can be
shortened, but I think it is important that the security
considerations for a data model document include a discussion of the
sensitivity, and potential problems, associated with the data model
objects.

David Harrington
[email protected]
[email protected]
[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.