Issue 3: replacement boilerplate for management object sensitivity
"David Harrington" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Hi,
There is an existing boilerplate for the security consideration
section of a document defining objects of management information. This
boilerplate text discusses the read and write sensitivity of
management information in the data model. The current text is SMIv2
oriented. As the IETF moves to a strategy of supporting multiple
languages for defining management data models, the boilerplate text
should be updated to address the sensitivity of the information,
regardless of the language used to define the information.
(This discussion is about how to update the existing boilerplate, not
whether to have such a boilerplate. Please see issue 1 if you think we
should not have boilerplate.)
OLD:
-- if you have any read-write and/or read-create objects, please
-- describe their specific sensitivity or vulnerability.
-- RFC 2669 has a very good example.
There are a number of management objects defined in this MIB module
with a MAX-ACCESS clause of read-write and/or read-create. Such
objects may be considered sensitive or vulnerable in some network
environments. The support for SET operations in a non-secure
environment without proper protection can have a negative effect on
network operations. These are the tables and objects and their
sensitivity/vulnerability:
<list the tables and objects and state why they are sensitive>
-- else if there are no read-write objects in your MIB module
There are no management objects defined in this MIB module that
have
a MAX-ACCESS clause of read-write and/or read-create. So, if this
MIB module is implemented correctly, then there is no risk that an
intruder can alter or create any management objects of this MIB
module via direct SNMP SET operations.
-- for all MIB modules you must evaluate whether any readable objects
-- are sensitive or vulnerable (for instance, if they might reveal
-- customer information or violate personal privacy laws such as
-- those of the European Union if exposed to unathorized parties)
Some of the readable objects in this MIB module (i.e., objects with
a
MAX-ACCESS other than not-accessible) may be considered sensitive
or
vulnerable in some network environments. It is thus important to
control even GET and/or NOTIFY access to these objects and possibly
to even encrypt the values of these objects when sending them over
the network via SNMP. These are the tables and objects and their
sensitivity/vulnerability:
<list the tables and objects and state why they are sensitive>
NEW:
-- include this paragraph if the management information can be
created, deleted, or modified:
Some management information defined in this document can be
created, deleted, or modified by one or more management protocols.
Unauthorized or inappropriate modification could have a negative
effect on network operations or security.
-- include the following in all documents that define management
information:
The management information defined in this document can be
considered sensitive or lead to network vulnerabilities in some
environments. It is important to control access to this information
and possibly to encrypt the information when sending the information
over a network using a management protocol, to prevent unauthorized or
inappropriate exposure of this information.
Following is a list of the potentially sensitive information, and why
this information is sensitive:
<list the sensitive information elements and state why they are
sensitive to modification and exposure>
----
comments welcome
David Harrington
[email protected]
[email protected]
[email protected]