Re: Issue 2: replacement text for securemanagementprotocolboilerplate
"Romascanu, Dan (Dan)" <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <EDC652A26FB23C4EB6384A4584434A0401394E62@307622ANEX5.global.avaya.com> |
> -----Original Message----- > From: [email protected] > [mailto:[email protected]] On Behalf Of Randy Presuhn > Sent: Wednesday, February 04, 2009 8:28 PM > To: 'ops-area (IETF)' > Subject: Re: [OPS-AREA] Issue 2: replacement text for > securemanagementprotocolboilerplate > > Hi - > > > From: "David Harrington" <[email protected]> > > To: "'Randy Presuhn'" <[email protected]>; "'ops-area > > (IETF)'" <[email protected]> > > Sent: Wednesday, February 04, 2009 10:24 AM > > Subject: RE: [OPS-AREA] Issue 2: replacement text for secure > > managementprotocolboilerplate > ... > > Would the following be better? > > > > "Operators SHOULD enable cryptographic security and ensure that the > > protocol giving access to management information is properly > > configured to give access only to those principals > > (users/applications) that have legitimate rights to > > read/create/change/delete the information." > > > > i.e., > > s:server/agent:protocol: > > s:(users):(users/applications)/ > > > > or does that get so diluted as to be meaningless? > > I think it's better. To more explicitly address the > syslog/notification cases, perhaps one could add "/receive" > after "delete"? > > Randy > +1 Dan (speaking as contributor)