Re: Issue 2: replacement text for secure managementprotocolboilerplate

"David Harrington" <[email protected]>
Newsgroups gmane.ietf.ops
Message-ID <[email protected]>
Hi,

Would the following be better?
 
"Operators SHOULD enable cryptographic security and ensure that the 
protocol giving access to management information is properly 
configured to give access only to those principals
(users/applications) that have legitimate rights to
read/create/change/delete the information." 

i.e., 
s:server/agent:protocol:
s:(users):(users/applications)/

or does that get so diluted as to be meaningless?

dbh

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Randy Presuhn
> Sent: Wednesday, February 04, 2009 1:12 PM
> To: 'ops-area (IETF)'
> Subject: Re: [OPS-AREA] Issue 2: replacement text for secure 
> managementprotocolboilerplate
> 
> Hi -
> 
> > From: "David Harrington" <[email protected]>
> > To: "'ops-area (IETF)'" <[email protected]>
> > Sent: Wednesday, February 04, 2009 7:47 AM
> > Subject: [OPS-AREA] Issue 2: replacement text for secure 
> management protocolboilerplate
> ...
> > NEW:
> > Any protocol used to manage a device should support
authentication,
> > encryption, integrity checking, and control of access to the
> > management information. It is RECOMMENDED that operators deploy an
> > IETF standard protocol for secure management, such as 
> Netconf over SSH
> > [RFC4742] or SNMPv3 [RFC3410] or syslog over TLS [RFC5425]. 
>  Operators
> > SHOULD enable cryptographic security and ensure that the 
> server/agent
> > giving access to management information is properly 
> configured to give
> > access only to those principals (users) that have 
> legitimate rights to
> > read/create/change/delete the information. 
> ...
> 
> I think the last sentence isn't quite right for syslog and 
> SNMP notification
> originators.  It's true that that's how we handle the "giving 
> access" part in
> VACM, but at the level of the cryptographic security happening
during
> the actual transfer of the information (rather than the 
> configuration of how
> the information is to be transferred) it's a different matter.
> 
> Randy
> 
> _______________________________________________
> OPS-AREA mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/ops-area
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.