Re: status and future of the isms working group
Wes Hardaker <[email protected]>
| Newsgroups | gmane.ietf.ops |
|---|---|
| Organization | Sparta |
| Message-ID | <[email protected]> |
>>>>> On Mon, 20 Sep 2010 09:28:49 +0200, "t.petch" <[email protected]> said: tp> RFC3411 was a great piece of work, but turned out to be fatally tp> flawed. The first time it was put to the test, introducing a new tp> security model, it proved unusable. Well, I'm not sure that's an entirely fair characterization. The problem wasn't that the model was flawed, it was that it wrapped *only* around its own notion of the SNMP protocol. When ISMS came along and the decision was to outsource the security to something in a lower layer, then yes the original model had issues with that because it didn't take that possibility into account. 5590 simply fixed that. Interestingly enough by providing some extra transmission lines to the model and extra information to the data passed via the ASIs. However, the ISMS solutions were the first "standardized" ones. More documents and code have been written to provide other security models that were either implemented or partially implemented and worked just fine without changing the underlying 3411 model: KSM (which is now being brought forward again) and SBSM (which is how the ISMS working group got started but went the SSH-underneath route instead of an in-SNMPv3-protocol integrated model). -- Wes Hardaker Cobham Analytic Solutions