Re: again about ietf-outcomes
Fred Baker <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Message-ID | <[email protected]> |
Along the lines of "secure management", Cisco's Lawful Intercept offering is controlled using SNMPv3, so anyone that uses it has to deploy and use SNMPv3. There is a recent Black hat discussion regarding that, and US Cert is likely to come back to your working group with a request for a change in the access control procedure - the message responding to an accepted access is different than the response to a denied access, which reveals information to an attacker. On Feb 10, 2010, at 8:39 AM, David Harrington wrote: > Hi, > > I didn't change the adoption column that was already set for snmpv3; I > have an obvious conflict of interest as snmpv3 wg chair. I would be > happy to see the ops area reach consensus on what the adoption column > should say. > > I have discussed snmpv3 with a number of service provider operators > who tell me they definitely use snmpv3. > > Here are my impressions, with very little evidence to support those > impressions: > There is the distinction between deployment and usage. > I believe snmpv3 is found in many devices. > It had a slower adoption rate in NMS systems, but I think the major > NMS systems now support snmpv3. > Many of the features are not used widely, and many are not used fully. > (I remember one case where VACM's per-user authorization was > supported, but they only allowed one user.) > > Some environments are far more concerned about security than others, > and SNMPv3 gets used in security-conscious environments. > Some environments have strict controls over management traffic using > techniques such as management VLANS, and operators for those networks > may feel that they have "enough" security using those approaches to > allow snmpv1/v2 to be used in a secure-enough manner, and they > obviously don't have demand for the additional features of SNMPv3.) > > I would support "some adoption" with a target market of "environments > that require secure management". > > dbh > > >> -----Original Message----- >> From: [email protected] >> [mailto:[email protected]] On Behalf Of Wes Hardaker >> Sent: Wednesday, February 10, 2010 10:09 AM >> To: Romascanu, Dan (Dan) >> Cc: [email protected]; [email protected] >> Subject: Re: [OPS-AREA] again about ietf-outcomes >> >>>>>>> On Wed, 10 Feb 2010 11:49:26 +0100, "Romascanu, Dan >> (Dan)" <[email protected]> said: >> >> DR> David Harrington put some work in improving the content >> of the wiki page >> DR> at >> http://trac.tools.ietf.org/misc/outcomes/wiki/IetfOperations in what >> DR> concerns SNMP and SMI. It would be good if other folks >> have a look and >> DR> especially if they can spare some time adding more exact >> and detailed >> DR> information related to the other management protocols. >> >> Being the project leader of a major SNMP stack, I find it odd >> that we've >> marked SNMPv3 as "poor adoption". It's definitely deployed >> and adopted >> from the perspective of what my users ask questions about. It's >> definitely confusing to many (or they wouldn't ask questions) and > it's >> definitely not as big of a percentage as we'd like (hence the need > for >> ISMS), but to say that it's "poor adoption" is a bit odd. >> "Some" would >> be a better marking, IMHO. Definitely not "massive". >> Unfortunately, we >> don't have an "ehhh" marking. >> >> -- >> Wes Hardaker >> Cobham Analytic Solutions >> _______________________________________________ >> OPS-AREA mailing list >> [email protected] >> https://www.ietf.org/mailman/listinfo/ops-area >> > http://www.ipinc.net/IPv4.GIF