Re: Issue 1: should we have a security boilerplate formanagement protocols and data models?
"Randy Presuhn" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <004e01c986f5$8b8aaac0$6801a8c0@oemcomputer> |
Hi - > From: "David Harrington" <[email protected]> > To: "'ops-area (IETF)'" <[email protected]> > Sent: Wednesday, February 04, 2009 7:46 AM > Subject: [OPS-AREA] Issue 1: should we have a security boilerplate formanagement protocols and data models? ... > I think the debate aboiut whether we should have boilerplate is a > different issue than what the replacement text should be, so this > thread is for tha debate about whether a boilerplate is desirable. ... While this is an admirable goal, I think it is premature. Does *anyone* have an idea of what *standardized* access control for netconf is going to look like? Though I know folks would like to make it simpler than VACM, until folks work through how access control interacts with augmentations and vendor extensions in that environment, I'd be very wary of trying to set out meta-policies (which is what the filled-in boilerplate will be) for that environment. Randy