Issue 1: should we have a security boilerplate for management protocols and data models?
"David Harrington" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Hi, I plan to propose some replacement text for the current boilerplate for secure management protocols, and for the sensitivity of data model objects. I think the debate aboiut whether we should have boilerplate is a different issue than what the replacement text should be, so this thread is for tha debate about whether a boilerplate is desirable. Please keep the threads separate. now, my opinion on whether to have boilerplate: I have seen editors try to write their own recommendations for securing management using SNMPv3 or other secure protocol, and they typically get the text way wrong. I think it is important for us to provide accurate text for them to use. I personally find the existing MIB object sensitivity boilerplate longer than I like, and I think we should consider whether it can be shortened, but I think it is important that the security considerations for a data model document include a discussion of the sensitivity, and potential problems, associated with the data model objects. David Harrington [email protected] [email protected] [email protected]