Privileged Resource Manager comments

"Jim Pinkerton" <[email protected]>
Newsgroups gmane.ietf.rddp
Message-ID <E6564B8F86852D46A4E98C485FB33B8F059998A0@WIN-MSG-10.wingroup.windeploy.ntdev.microsoft.com>
 

In the minutes for the last IETF meeting, it states:

 

Q: Draft introduces Privileged Resource Manager as a mandatory

      functional component.  How does this affect performance?

A: The intent is that it not be involved in high-frequency

      operations, but more work is needed to define the precise

      functionality of the Privileged Resource Manager and check

      if there are problems.

 

 

In the latest draft, per feedback from the reflector, the following text
was added:

 

For example, the Privileged Resource Manager may be partially or
completely encapsulated in the Privileged Application. Regardless, it is
expected that the security analysis of the potential threats and
countermeasures still apply.

 

Thus I don't believe the draft requires a distinct entity called the
Privileged Resource Manager. It can be encapsulated in an application
that has been trusted to access privileged resources directly. For
example, a particular implementation may run exactly one application,
which has physical access to all resources. In that case the security
issues described for the non-privileged application are unnecessary to
implement (because there is not one), and there is no need to separate
the Privileged Resource Manager from the privileged application.

 

 

Jim
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.