Re: Issue 2: replacement text for secure managementprotocolboilerplate
"David Harrington" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Hi, Would the following be better? "Operators SHOULD enable cryptographic security and ensure that the protocol giving access to management information is properly configured to give access only to those principals (users/applications) that have legitimate rights to read/create/change/delete the information." i.e., s:server/agent:protocol: s:(users):(users/applications)/ or does that get so diluted as to be meaningless? dbh > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Randy Presuhn > Sent: Wednesday, February 04, 2009 1:12 PM > To: 'ops-area (IETF)' > Subject: Re: [OPS-AREA] Issue 2: replacement text for secure > managementprotocolboilerplate > > Hi - > > > From: "David Harrington" <[email protected]> > > To: "'ops-area (IETF)'" <[email protected]> > > Sent: Wednesday, February 04, 2009 7:47 AM > > Subject: [OPS-AREA] Issue 2: replacement text for secure > management protocolboilerplate > ... > > NEW: > > Any protocol used to manage a device should support authentication, > > encryption, integrity checking, and control of access to the > > management information. It is RECOMMENDED that operators deploy an > > IETF standard protocol for secure management, such as > Netconf over SSH > > [RFC4742] or SNMPv3 [RFC3410] or syslog over TLS [RFC5425]. > Operators > > SHOULD enable cryptographic security and ensure that the > server/agent > > giving access to management information is properly > configured to give > > access only to those principals (users) that have > legitimate rights to > > read/create/change/delete the information. > ... > > I think the last sentence isn't quite right for syslog and > SNMP notification > originators. It's true that that's how we handle the "giving > access" part in > VACM, but at the level of the cryptographic security happening during > the actual transfer of the information (rather than the > configuration of how > the information is to be transferred) it's a different matter. > > Randy > > _______________________________________________ > OPS-AREA mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/ops-area >