Re: again about ietf-outcomes

Fred Baker <[email protected]>
Newsgroups gmane.ietf.ops
Message-ID <[email protected]>
Along the lines of "secure management", Cisco's Lawful Intercept  
offering is controlled using SNMPv3, so anyone that uses it has to  
deploy and use SNMPv3. There is a recent Black hat discussion  
regarding that, and US Cert is likely to come back to your working  
group with a request for a change in the access control procedure -  
the message responding to an accepted access is different than the  
response to a denied access, which reveals information to an attacker.

On Feb 10, 2010, at 8:39 AM, David Harrington wrote:

> Hi,
>
> I didn't change the adoption column that was already set for snmpv3; I
> have an obvious conflict of interest as snmpv3 wg chair. I would be
> happy to see the ops area reach consensus on what the adoption column
> should say.
>
> I have discussed snmpv3 with a number of service provider operators
> who tell me they definitely use snmpv3.
>
> Here are my impressions, with very little evidence to support those
> impressions:
> There is the distinction between deployment and usage.
> I believe snmpv3 is found in many devices.
> It had a slower adoption rate in NMS systems, but I think the major
> NMS systems now support snmpv3.
> Many of the features are not used widely, and many are not used fully.
> (I remember one case where VACM's per-user authorization was
> supported, but they only allowed one user.)
>
> Some environments are far more concerned about security than others,
> and SNMPv3 gets used in security-conscious environments.
> Some environments have strict controls over management traffic using
> techniques such as management VLANS, and operators for those networks
> may feel that they have "enough" security using those approaches to
> allow snmpv1/v2 to be used in a secure-enough manner, and they
> obviously don't have demand for the additional features of SNMPv3.)
>
> I would support "some adoption" with a target market of "environments
> that require secure management".
>
> dbh
>
>
>> -----Original Message-----
>> From: [email protected]
>> [mailto:[email protected]] On Behalf Of Wes Hardaker
>> Sent: Wednesday, February 10, 2010 10:09 AM
>> To: Romascanu, Dan (Dan)
>> Cc: [email protected]; [email protected]
>> Subject: Re: [OPS-AREA] again about ietf-outcomes
>>
>>>>>>> On Wed, 10 Feb 2010 11:49:26 +0100, "Romascanu, Dan
>> (Dan)" <[email protected]> said:
>>
>> DR> David Harrington put some work in improving the content
>> of the wiki page
>> DR> at
>> http://trac.tools.ietf.org/misc/outcomes/wiki/IetfOperations in what
>> DR> concerns SNMP and SMI. It would be good if other folks
>> have a look and
>> DR> especially if they can spare some time adding more exact
>> and detailed
>> DR> information related to the other management protocols.
>>
>> Being the project leader of a major SNMP stack, I find it odd
>> that we've
>> marked SNMPv3 as "poor adoption".  It's definitely deployed
>> and adopted
>> from the perspective of what my users ask questions about.  It's
>> definitely confusing to many (or they wouldn't ask questions) and
> it's
>> definitely not as big of a percentage as we'd like (hence the need
> for
>> ISMS), but to say that it's "poor adoption" is a bit odd.
>> "Some" would
>> be a better marking, IMHO.  Definitely not "massive".
>> Unfortunately, we
>> don't have an "ehhh" marking.
>>
>> -- 
>> Wes Hardaker
>> Cobham Analytic Solutions
>> _______________________________________________
>> OPS-AREA mailing list
>> [email protected]
>> https://www.ietf.org/mailman/listinfo/ops-area
>>
>

http://www.ipinc.net/IPv4.GIF
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.