Re: Issue 2: replacement text for secure managementprotocolboilerplate
"Randy Presuhn" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <007101c986f6$5ac4e620$6801a8c0@oemcomputer> |
Hi - > From: "David Harrington" <[email protected]> > To: "'Randy Presuhn'" <[email protected]>; "'ops-area (IETF)'" <[email protected]> > Sent: Wednesday, February 04, 2009 10:24 AM > Subject: RE: [OPS-AREA] Issue 2: replacement text for secure managementprotocolboilerplate ... > Would the following be better? > > "Operators SHOULD enable cryptographic security and ensure that the > protocol giving access to management information is properly > configured to give access only to those principals > (users/applications) that have legitimate rights to > read/create/change/delete the information." > > i.e., > s:server/agent:protocol: > s:(users):(users/applications)/ > > or does that get so diluted as to be meaningless? I think it's better. To more explicitly address the syslog/notification cases, perhaps one could add "/receive" after "delete"? Randy