Re: status and future of the isms working group

Wes Hardaker <[email protected]>
Newsgroups gmane.ietf.ops
Organization Sparta
Message-ID <[email protected]>
>>>>> On Mon, 20 Sep 2010 09:28:49 +0200, "t.petch" <[email protected]> said:

tp> RFC3411 was a great piece of work, but turned out to be fatally
tp> flawed.  The first time it was put to the test, introducing a new
tp> security model, it proved unusable.

Well, I'm not sure that's an entirely fair characterization.  The
problem wasn't that the model was flawed, it was that it wrapped *only*
around its own notion of the SNMP protocol.

When ISMS came along and the decision was to outsource the security to
something in a lower layer, then yes the original model had issues with
that because it didn't take that possibility into account.  5590 simply
fixed that.  Interestingly enough by providing some extra transmission
lines to the model and extra information to the data passed via the
ASIs.

However, the ISMS solutions were the first "standardized" ones.  More
documents and code have been written to provide other security models
that were either implemented or partially implemented and worked just
fine without changing the underlying 3411 model: KSM (which is now being
brought forward again) and SBSM (which is how the ISMS working group got
started but went the SSH-underneath route instead of an
in-SNMPv3-protocol integrated model).
-- 
Wes Hardaker
Cobham Analytic Solutions
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.