Re: Issue 1: should we have a security boilerplateformanagement protocols and data models?
"David Harrington" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Hi, > While this is an admirable goal, I think it is premature. > Does *anyone* > have an idea of what *standardized* access control for > netconf is going > to look like? Though I know folks would like to make it simpler than > VACM, until folks work through how access control interacts with > augmentations and vendor extensions in that environment, I'd be > very wary of trying to set out meta-policies (which is what > the filled-in > boilerplate will be) for that environment. I am not sure which goal you find admirable, but I assume you mean suggesting that protocols should support access control, and the info model access should differentiate between modify sensitivity and expose sensitivity. I tried to write the text to say that the protocol should support control of access to the information. I tried to avoid saying anything about using a particular conceptualization/model of access control. "support" could be for a proprietary access control model, or a standardized one - but some type of access control should be supported. I think that whether the access control is standardized or proprietary, it will be reasonable to expect that the access control will differentiate between operations that expose and those that modify (if there is a modify capability). dbh