Re: Issue 2: replacement text for securemanagementprotocolboilerplate

"David Harrington" <[email protected]>
Newsgroups gmane.ietf.ops
Message-ID <[email protected]>
Hi,

I think the original formulation could lead one to assume the access
control was "standardized" as part of the standard protocol. I think
it might be clearer to separate this into two separate
recommendations:

"Any protocol used to manage a device should support authentication,
encryption, integrity checking, and control of access to the
management information. It is RECOMMENDED that operators deploy an
IETF standard protocol for secure management, such as Netconf over SSH
[RFC4742] or SNMPv3 [RFC3410] or syslog over TLS [RFC5425].  

Operators SHOULD enable cryptographic security and ensure that the 
protocol giving access to management information is properly
configured 
to give access only to those principals (users/applications) that have

legitimate rights to create/change/delete/read/receive the
information."

dbh 

> -----Original Message-----
> From: [email protected] 
> [mailto:[email protected]] On Behalf Of Randy Presuhn
> Sent: Wednesday, February 04, 2009 1:28 PM
> To: 'ops-area (IETF)'
> Subject: Re: [OPS-AREA] Issue 2: replacement text for 
> securemanagementprotocolboilerplate
> 
> Hi -
> 
> > From: "David Harrington" <[email protected]>
> > To: "'Randy Presuhn'" <[email protected]>; 
> "'ops-area (IETF)'" <[email protected]>
> > Sent: Wednesday, February 04, 2009 10:24 AM
> > Subject: RE: [OPS-AREA] Issue 2: replacement text for 
> secure managementprotocolboilerplate
> ...
> > Would the following be better?
> >  
> > "Operators SHOULD enable cryptographic security and ensure that
the 
> > protocol giving access to management information is properly 
> > configured to give access only to those principals
> > (users/applications) that have legitimate rights to
> > read/create/change/delete the information." 
> > 
> > i.e., 
> > s:server/agent:protocol:
> > s:(users):(users/applications)/
> > 
> > or does that get so diluted as to be meaningless?
> 
> I think it's better.  To more explicitly address the 
> syslog/notification
> cases, perhaps one could add "/receive" after "delete"?
> 
> Randy
> 
> _______________________________________________
> OPS-AREA mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/ops-area
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.