Re: Issue 2: replacement text for securemanagementprotocolboilerplate
"David Harrington" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Hi, I think the original formulation could lead one to assume the access control was "standardized" as part of the standard protocol. I think it might be clearer to separate this into two separate recommendations: "Any protocol used to manage a device should support authentication, encryption, integrity checking, and control of access to the management information. It is RECOMMENDED that operators deploy an IETF standard protocol for secure management, such as Netconf over SSH [RFC4742] or SNMPv3 [RFC3410] or syslog over TLS [RFC5425]. Operators SHOULD enable cryptographic security and ensure that the protocol giving access to management information is properly configured to give access only to those principals (users/applications) that have legitimate rights to create/change/delete/read/receive the information." dbh > -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Randy Presuhn > Sent: Wednesday, February 04, 2009 1:28 PM > To: 'ops-area (IETF)' > Subject: Re: [OPS-AREA] Issue 2: replacement text for > securemanagementprotocolboilerplate > > Hi - > > > From: "David Harrington" <[email protected]> > > To: "'Randy Presuhn'" <[email protected]>; > "'ops-area (IETF)'" <[email protected]> > > Sent: Wednesday, February 04, 2009 10:24 AM > > Subject: RE: [OPS-AREA] Issue 2: replacement text for > secure managementprotocolboilerplate > ... > > Would the following be better? > > > > "Operators SHOULD enable cryptographic security and ensure that the > > protocol giving access to management information is properly > > configured to give access only to those principals > > (users/applications) that have legitimate rights to > > read/create/change/delete the information." > > > > i.e., > > s:server/agent:protocol: > > s:(users):(users/applications)/ > > > > or does that get so diluted as to be meaningless? > > I think it's better. To more explicitly address the > syslog/notification > cases, perhaps one could add "/receive" after "delete"? > > Randy > > _______________________________________________ > OPS-AREA mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/ops-area >